Subprocessor & Data Flow Document

Confidential
OrganizationAdvanced Learning Academy LLC
Document ClassificationConfidential — Internal & Authorized Recipients
Effective DateMay 9, 2026
Version1.0
OwnerChief Technology Officer, Advanced Learning Academy LLC

1. Purpose

This document identifies all third-party subprocessors engaged by Advanced Learning Academy LLC ("ALA") in the delivery of its cognitive assessment, biological age, relationship intelligence, and career alignment products. It describes the nature of data processed by each subprocessor, applicable certifications, and the end-to-end data flow architecture.

This document is provided to enterprise clients, procurement teams, and compliance officers to support due diligence, vendor risk assessments, and data protection impact analyses.

2. Data Processing Principles

3. Subprocessor Registry

Subprocessor Purpose Data Processed Location Certifications
Cloudflare, Inc. Infrastructure, CDN, serverless compute (Workers), database (D1), key-value storage (KV), object storage (R2) All application data, encrypted in transit and at rest Global (300+ PoPs) SOC 2 Type II, ISO 27001; Cloudflare maintains FedRAMP authorization for select products
Stripe, Inc. Payment processing, subscription management, checkout Payment card data, email address, billing address United States PCI DSS Level 1, SOC 2 Type II
Mailgun (Sinch) Transactional and notification email delivery Email addresses, notification content United States SOC 2 Type II
Bunny.net CDN for static media assets (images, documents) Public images and documents only (no PII) Global GDPR compliant
IBM Quantum Bias validation (one-time statistical validation) Assessment statistical data only (no PII) United States IBM Cloud certifications
Important: No assessment PII is shared with any subprocessor. Stripe receives only payment data necessary to process transactions. Mailgun receives only notification email addresses. IBM Quantum received only aggregate statistical data for one-time bias validation — no individual assessment records or personally identifiable information were transmitted.

4. Data Flow Architecture

The following diagram illustrates the end-to-end data flow for ALA's assessment platform:

┌──────────────────────────┐ │ USER BROWSER │ │ (HTTPS / TLS 1.3) │ └────────────┬───────────────┘ │ ▼ ┌──────────────────────────┐ │ CLOUDFLARE EDGE │ │ CDN + WAF + DDoS │ │ (300+ Global PoPs) │ └────────────┬───────────────┘ │ ┌────────────┴───────────────┐ │ │ ▼ ▼ ┌─────────────────┐ ┌─────────────────┐ │ CLOUDFLARE │ │ STATIC ASSETS │ │ WORKERS │ │ (Pages / R2) │ │ (Compute) │ │ │ └────┬───┬───┬────┘ └─────────────────┘ │ │ │ ┌──────────┘ │ └──────────┐ ▼ ▼ ▼ ┌────────────┐ ┌────────────┐ ┌────────────┐ │ D1 │ │ KV │ │ R2 │ │ (Database) │ │ (Key-Value)│ │ (Objects) │ │ Assessment │ │ Sessions │ │ Reports │ │ Results │ │ Config │ │ Media │ └────────────┘ └────────────┘ └────────────┘ Side Flows: ┌──────────────────────────────────────────────┐ │ │ │ ┌──────────┐ Payment Flow │ │ │ STRIPE │◄── Checkout redirect ──────┐ │ │ │ │ (card data never │ │ │ │ │ touches ALA servers) │ │ │ └──────────┘ │ │ │ │ │ │ ┌──────────┐ Email Flow │ │ │ │ MAILGUN │◄── Worker API call ─────┐ │ │ │ │ (Sinch) │ (email + content │ │ │ │ │ │ only) │ │ │ │ └──────────┘ │ │ │ │ │ │ │ │ Workers ─────────────────────────────┘───┘ │ └──────────────────────────────────────────────┘ One-Time Validation: ┌──────────────┐ │ IBM QUANTUM │◄── Aggregate statistics only │ │ (no PII, completed) └──────────────┘

5. Data Categories & Handling

5.1 Assessment Data

Cognitive assessment responses, scores, timing data, and generated reports are processed exclusively within the Cloudflare infrastructure stack (Workers + D1 + R2). This data never leaves the Cloudflare environment except when delivered to the authenticated end user via encrypted HTTPS connection.

5.2 Payment Data

Payment card information is collected directly by Stripe via their embedded checkout interface. ALA servers never receive, process, or store raw payment card numbers. Stripe returns only a transaction confirmation, customer email, and payment status to ALA's webhook endpoint.

5.3 Email Data

Mailgun receives recipient email addresses and notification content (e.g., assessment completion notices, report delivery links) via authenticated API calls from Cloudflare Workers. No assessment results or scores are included in email content — emails contain only secure links to the platform.

5.4 Static Assets

Public-facing images, branding assets, and downloadable documents are served via Bunny.net CDN and Cloudflare R2. These assets contain no personally identifiable information.

6. Security Controls Summary

Control Implementation
Encryption in TransitTLS 1.3 enforced on all endpoints; HSTS enabled
Encryption at RestAES-256 via Cloudflare D1, KV, and R2 native encryption
Access ControlRole-based access; API key authentication; per-worker secret bindings
DDoS ProtectionCloudflare DDoS mitigation at edge
WAFCloudflare Web Application Firewall with managed rulesets
Breach Notification72-hour notification commitment per data processing agreements
Data RetentionAssessment data retained per client agreement; configurable purge policies
BackupAutomated 15-minute backups across all D1 databases and KV namespaces to R2 with 4-quarter rotation

7. Subprocessor Change Notification

ALA will provide enterprise clients with 30 days' prior written notice before engaging any new subprocessor or materially changing the data processing activities of an existing subprocessor. Clients may object to a new subprocessor within 15 days of notification, in which case ALA will work to address concerns or provide an alternative arrangement.

8. Contact

For questions regarding this document, data processing practices, or subprocessor due diligence: