| Organization | Advanced Learning Academy LLC |
| Document Classification | Confidential — Internal & Authorized Recipients |
| Effective Date | May 9, 2026 |
| Version | 1.0 |
| Owner | Chief Technology Officer, Advanced Learning Academy LLC |
This document identifies all third-party subprocessors engaged by Advanced Learning Academy LLC ("ALA") in the delivery of its cognitive assessment, biological age, relationship intelligence, and career alignment products. It describes the nature of data processed by each subprocessor, applicable certifications, and the end-to-end data flow architecture.
This document is provided to enterprise clients, procurement teams, and compliance officers to support due diligence, vendor risk assessments, and data protection impact analyses.
| Subprocessor | Purpose | Data Processed | Location | Certifications |
|---|---|---|---|---|
| Cloudflare, Inc. | Infrastructure, CDN, serverless compute (Workers), database (D1), key-value storage (KV), object storage (R2) | All application data, encrypted in transit and at rest | Global (300+ PoPs) | SOC 2 Type II, ISO 27001; Cloudflare maintains FedRAMP authorization for select products |
| Stripe, Inc. | Payment processing, subscription management, checkout | Payment card data, email address, billing address | United States | PCI DSS Level 1, SOC 2 Type II |
| Mailgun (Sinch) | Transactional and notification email delivery | Email addresses, notification content | United States | SOC 2 Type II |
| Bunny.net | CDN for static media assets (images, documents) | Public images and documents only (no PII) | Global | GDPR compliant |
| IBM Quantum | Bias validation (one-time statistical validation) | Assessment statistical data only (no PII) | United States | IBM Cloud certifications |
The following diagram illustrates the end-to-end data flow for ALA's assessment platform:
Cognitive assessment responses, scores, timing data, and generated reports are processed exclusively within the Cloudflare infrastructure stack (Workers + D1 + R2). This data never leaves the Cloudflare environment except when delivered to the authenticated end user via encrypted HTTPS connection.
Payment card information is collected directly by Stripe via their embedded checkout interface. ALA servers never receive, process, or store raw payment card numbers. Stripe returns only a transaction confirmation, customer email, and payment status to ALA's webhook endpoint.
Mailgun receives recipient email addresses and notification content (e.g., assessment completion notices, report delivery links) via authenticated API calls from Cloudflare Workers. No assessment results or scores are included in email content — emails contain only secure links to the platform.
Public-facing images, branding assets, and downloadable documents are served via Bunny.net CDN and Cloudflare R2. These assets contain no personally identifiable information.
| Control | Implementation |
|---|---|
| Encryption in Transit | TLS 1.3 enforced on all endpoints; HSTS enabled |
| Encryption at Rest | AES-256 via Cloudflare D1, KV, and R2 native encryption |
| Access Control | Role-based access; API key authentication; per-worker secret bindings |
| DDoS Protection | Cloudflare DDoS mitigation at edge |
| WAF | Cloudflare Web Application Firewall with managed rulesets |
| Breach Notification | 72-hour notification commitment per data processing agreements |
| Data Retention | Assessment data retained per client agreement; configurable purge policies |
| Backup | Automated 15-minute backups across all D1 databases and KV namespaces to R2 with 4-quarter rotation |
ALA will provide enterprise clients with 30 days' prior written notice before engaging any new subprocessor or materially changing the data processing activities of an existing subprocessor. Clients may object to a new subprocessor within 15 days of notification, in which case ALA will work to address concerns or provide an alternative arrangement.
For questions regarding this document, data processing practices, or subprocessor due diligence: