Provider
Google Firebase Authentication
Used for
Login, anonymous sign-in, Feide/OIDC handoff and account identity.
Data that may be processed
Technical user ID, provider identifiers, email where available, authentication metadata and password hashes for email/password accounts.
Processing / storage location
Firebase Authentication is run only from US data centers according to Firebase documentation. Transfers are covered by Google's Firebase data processing terms and SCCs where applicable.
Provider
Google Cloud Firestore
Used for
Database for profiles, Spaces, assignments, student work, usage records and app data.
Data that may be processed
Profile data, Spaces data, student work, submissions, teacher content, school administration data and technical timestamps.
Processing / storage location
europe-west1 (Belgium). Core Firestore data is stored at rest in this European region.
Provider
Firebase Storage / Google Cloud Storage
Used for
File and image storage where upload features are used.
Data that may be processed
Uploaded files/images and related technical metadata.
Processing / storage location
Active 321school bucket: 321skole-storage, EU multi-region.
Status
Active if file/image upload is used
Used for
Feide login and school-owner controlled identity access when enabled.
Data that may be processed
Login identity data such as technical identifiers, name, email where available, organization affiliation and authentication metadata handled through Feide.
Processing / storage location
Norway / EEA-oriented Feide service operated by Sikt.
Status
Active when Feide login is used
Used for
Hosting, web application delivery and server functions.
Data that may be processed
Technical request data such as IP address, browser/device data, logs and page requests.
Processing / storage location
Vercel infrastructure. Region/processing location to be confirmed in the final DPA.
Used for
Aggregate product analytics where enabled.
Data that may be processed
Page/event data, device/browser data and approximate location derived by Google Analytics. IP addresses are used at collection time and then discarded before logging in GA4 according to Google documentation.
Processing / storage location
Google Analytics uses regional data collection and global Google infrastructure for processing.
Status
Active when analytics is enabled
Used for
AI features such as content generation, feedback, image generation, text tools and speech where enabled.
Data that may be processed
Prompts, submitted text, generated content and context needed to provide the selected AI function.
Processing / storage location
OpenAI API processing location depends on the active OpenAI data processing terms and settings. To be documented in the final DPA.
Status
Active when AI features are used
Used for
Payments, subscriptions, invoices and billing portal.
Data that may be processed
Name, email, customer ID, subscription/payment metadata and billing information.
Processing / storage location
Stripe infrastructure. Only relevant for paid plans/orders.
Status
Active for paid plans/orders
Used for
Transactional email, such as welcome messages and system emails.
Data that may be processed
Email address, message content and delivery metadata.
Processing / storage location
Resend/email infrastructure. To be confirmed in the final sub-processor overview.
Status
Active when email is sent
Used for
Live/video sessions in course features, if enabled.
Data that may be processed
Participant identifiers, meeting/session metadata and technical connection data.
Processing / storage location
Daily infrastructure, only if live/video sessions are enabled.
Used for
Instructional videos linked or embedded from the service.
Data that may be processed
Technical data handled by YouTube/Google when videos are opened or played.
Processing / storage location
Google/YouTube infrastructure, only when external videos are opened.
Status
Optional / if opened