Compliance
Sub-processors.
Last updated: 20 June 2026
The third parties listed below help us deliver Class Prayer. We name each one, what they do for us, what data they handle, and where the data sits. The list is kept in line with UK GDPR Article 28(2) and forms Schedule 2 of our school-facing Data Processing Agreement.
Current list
| Sub-processor | Purpose | Data processed | Region |
|---|---|---|---|
| Lovable Cloud (Supabase: Postgres, Auth, Storage) | Primary database, authentication and file storage. | All Class Prayer application data. | Republic of Ireland (AWS eu-west-1) |
| Lovable AI Gateway → Google (Gemini family models) | AI-assisted generation of prayer, theme and homily content. Google is the sole upstream LLM provider; no OpenAI or Anthropic models are used. | Scrubbed prompts - no pupil identifiers are sent. Inputs are not used to train models and are not retained by the model provider beyond the response. | EU (Lovable-managed routing; written confirmation available to school DPOs on request) |
| ESV API (Crossway) api.esv.org | Scripture text lookup. | Scripture reference strings only. No personal data. | United States (UK IDTA) |
| Lovable Emails (Mailgun upstream) | Account, magic-link and notification email delivery. | Recipient email address and template variables. | European Union (Mailgun EU region, Frankfurt) |
Effective date
This sub-processor list is effective from 20 June 2026 and forms Schedule 2 of the Class Prayer Data Processing Agreement.
Change notice
We give schools' nominated contacts at least 30 days' written notice before adding or replacing a sub-processor. Schools may object on reasonable data-protection grounds; if the objection cannot be resolved, the school may terminate the affected service without penalty.
Questions
Email info@classprayer.app.