
Sub-Processor List
Last Updated: 23 August 2026
The Compliance Classroom uses carefully selected third-party service providers to help us deliver, secure and support our online training platform.
Where these providers process personal data in connection with our services, we take appropriate steps to ensure that personal data is handled securely and in accordance with applicable UK data protection law.
This page provides information about the key third-party providers involved in delivering The Compliance Classroom service and is intended to support education settings and organisations with their own data protection and supplier due-diligence requirements.
Our Current Service Providers
StellarSites / Nexcess (Liquid Web)
Purpose: Website hosting, infrastructure, database storage and associated backup services.
The Compliance Classroom website and its primary WordPress database are hosted through StellarSites/Nexcess. This includes the infrastructure used to store and deliver website accounts, learner information, training records, contact-form submissions and other information held within our website.
Primary Hosting Location: EU West – Amsterdam, Netherlands.
Provider: Liquid Web, LLC / Nexcess.
Automattic / Jetpack
Purpose: Website backup, security, threat protection, downtime monitoring and website statistics.
We use selected Jetpack services to help protect, monitor and maintain The Compliance Classroom website. This includes VaultPress Backup, Jetpack Protect and related security and monitoring functionality.
Depending on the service being provided, information relating to the website, its configuration, visitors and backups may be processed through Automattic’s infrastructure.
Processing Location: Automattic operates internationally and personal data may be processed outside the UK/EEA. Appropriate safeguards are used where required for international transfers.
Provider: Automattic Inc.
Stripe
Purpose: Secure online payment processing, transaction management and fraud prevention.
We use Stripe to process payments made through The Compliance Classroom. Stripe may process information necessary to complete and manage a transaction, including customer contact details, billing information, payment information and transaction details.
Where a customer is presented with an optional marketing preference during checkout, the customer’s selection may be recorded with information relating to the order so that we can maintain an appropriate record of that preference.
The Compliance Classroom does not need to store customers’ full payment card details within its WordPress database in order to process card payments through Stripe.
Processing Location: Stripe operates internationally. Personal data may be processed in the UK, EEA and other countries. Appropriate safeguards are used where required for international transfers.
Provider: Stripe Payments Europe Limited / Stripe Payments UK Limited and relevant Stripe group companies.
Titan Email
Purpose: Business email and service-related communications.
We use Titan Email to provide our business email service. Personal data may therefore be processed when we send or receive communications relating to accounts, training, purchases, support enquiries, website contact-form enquiries or administration.
Information processed may include names, email addresses, organisation information where provided, and the content of relevant email communications.
Processing Location: Titan uses international infrastructure and service providers, and personal data may therefore be processed outside the UK/EEA. Appropriate safeguards are used where required.
Provider: Titan Solution Ltd SEZC.
Purpose: Website analytics, learner feedback, reflective practice and service improvement.
We use selected Google services to support the operation and improvement of The Compliance Classroom.
Google Analytics is used to help us understand how visitors use our website and to improve the performance, usability and effectiveness of our service. Information processed may include website usage information, device and browser information, interactions with the website and approximate geographic information. Our use of analytics technologies is subject to the choices available through our website cookie consent controls.
Google Forms is used to collect voluntary learner course evaluations and optional reflective practice responses. Information processed may include course feedback, reflections on learning, course details and any optional personal or contact information that a learner chooses to provide.
Learners are encouraged not to include unnecessary or sensitive personal information within free-text responses.
Information collected through learner evaluations and reflective practice may be used to monitor course quality, identify opportunities for improvement and support our wider quality assurance processes.
Processing Location: Google operates internationally and personal data may be processed outside the UK/EEA. Appropriate safeguards are used where required for international transfers.
Provider: Google LLC and relevant Google group companies.
Contact Form Processing
Our website contact form is used to receive and manage enquiries.
Information submitted through the form may include a person’s name, organisation, email address, the content of their enquiry and any other information they choose to provide.
Contact-form submissions may be stored within our WordPress website administration system and sent to our Titan business email account.
We do not intentionally record a user’s IP address or device information as part of the contact-form submission itself.
The contact form requires users to acknowledge our Privacy Notice before submitting an enquiry. This acknowledgement is not consent to receive optional marketing communications.
Submitting a contact-form enquiry does not automatically add an individual to a marketing mailing list.
International Data Transfers
Some of the service providers we use operate internationally.
Where personal data is transferred outside the United Kingdom, we take appropriate steps to ensure that the transfer is made in accordance with UK data protection law.
Depending on the provider and destination, safeguards may include adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or other legally recognised transfer mechanisms.
Changes To Our Sub-Processors
We may update the providers we use as The Compliance Classroom develops.
Where appropriate, this page will be updated to reflect material changes to the third-party providers involved in delivering our service.
Education settings and organisations using The Compliance Classroom should refer to the current version of this page when carrying out supplier or data protection reviews.
Where required under our contractual or data protection obligations, organisations will be informed of relevant material changes to sub-processors and provided with an appropriate opportunity to raise reasonable data protection concerns.
Questions About Our Sub-Processors
If you have a question about one of our service providers, how personal data is processed, or require further information for your organisation’s data protection due diligence, please contact:
The Compliance Classroom
Email: [email protected]
Further information about how we process personal data is available in our:
