1. Disclosure principle
The disclosure scope of this list is: (i) personal data processed or capable of being processed on this platform; (ii) necessary for platform operation; or (iii) not directly processing personal data but, under the strict practice of an EU DPO, could be regarded as a sub-processor. To ensure transparency for cooperation with Europe, disclosures in this list for LLM and CDN are named disclosures rather than generic descriptions.
This list will be updated within 30 days when major changes occur (addition or replacement of key vendors, changes to region, termination of cooperation); the change record is disclosed in the version history section of the document. Registered users will be notified by email of changes that result in a jump in the main version number.
2. Infrastructure and storage
| role | Supplier | Region | Purpose of processing / processed data / DPA |
|---|---|---|---|
| Server room | National Central University Computer Room | Zhongli District, Taoyuan City (Taiwan) | Primary application server (uedu.tw, 140.115.103.70); Ubuntu 24.04.3 LTS |
| Local storage | Local SSD (2TB NVMe) | Same as above | MySQL database, uploaded files, application logs; no third-party vendors |
| NAS | Educational Omics Lab NAS(borglab) | Same as above | Screen recording mp4 / large file uploads; not open to the public |
3. LLM inference service
The platform uses a flexible LLM routing strategy: the default provider is OpenAI, and depending on the data residency requirements of the research partner, it may be switched to the European region of Microsoft Azure OpenAI Service. This strategy has been disclosed in section 6 of the 'Privacy and Data Retention Policy'; this section discloses the specific provider and the relevant DPA.
| role | Supplier | Region | Purpose of processing / DPA |
|---|---|---|---|
| Default LLM Provider | OpenAI, L.L.C. | United States (US) | Inference services (generative LLM, whisper speech-to-text, image generation). OpenAI Data Processing Addendum. |
| Optional EU Provider | Microsoft Azure OpenAI Service | Switzerland North / West Europe | Inference service for European collaboration. Microsoft Online Services DPA + EU Data Boundary commitment. |
| Optional EU-native Provider (planned) | To be selected (candidates include Apertus, Mistral) | Switzerland / EU | Enabled as needed; per-vendor DPA. |
3.1 OpenAI Zero Data Retention
Zero Data Retention (ZDR) has been enabled for Uedu's API to OpenAI. Inputs to and outputs from the OpenAI API are not retained after real-time processing; OpenAI does not use them for model training or any other secondary purpose.
3.2 LLM routing for collaboration with Europe
For research collaboration involving data subjects in Europe, inference may be carried out via services deployed in the Switzerland North or West Europe region of Microsoft Azure OpenAI Service, processed in accordance with Microsoft's EU Data Boundary commitment. The choice of region is decided jointly with the collaborating institution to align with its data residency requirements.
4. Authentication / OAuth and wearable device integration
| role | Supplier | Region | Purpose of processing / processed data |
|---|---|---|---|
| OAuth Provider | Google LLC | the United States | Third-party sign-in; receive user-authorised email and profile information |
| OAuth Provider | Apple Inc. | the United States | Sign in with Apple; receive the user-authorised email identifier |
| OAuth Provider | GitHub, Inc. | the United States | Third-party sign-in; receive the user-authorised public profile |
| Wearable device API | Garmin International, Inc. | the United States | Retrieve HRV, sleep, stress and other indicators from Garmin Connect API with the user's authorisation |
| Health integration | Apple HealthKit | Client-side | Use the Uedu mobile APP to read health data authorised by the user; data is retrieved on the user's device and then returned to the platform |
| Health integration | Google Health Connect | Client-side | Same as above |
5. Email and communications
| role | Supplier | Region | Purpose of processing / DPA |
|---|---|---|---|
| Transactional email sending | Mailgun(Sinch Email, Inc.) | EU region | System notifications, account verification, research collaboration communications. Mailgun DPA. |
6. DNS / CDN / DDoS protection
| role | Supplier | Region | Purpose of processing / DPA |
|---|---|---|---|
| DNS / CDN / DDoS protection | Cloudflare, Inc. | United States (headquarters), global edge network | See the explanation below |
Cloudflare, Inc. (United States, global edge network) provides DNS resolution, DDoS protection and CDN services. Requests from users in Europe are primarily handled by Cloudflare's European edge nodes. This platform and Cloudflare have signed the Data Processing Addendum under its standard DPA terms.
7. Front-end asset delivery
All front-end JavaScript, CSS, font and other assets for this platform are self-hosted under the uedu.tw /static/vendor/ path. No use is made of public CDNs such as jsdelivr, cdnjs, unpkg, Google Fonts or the Tailwind Play CDN for asset delivery, and there are no related subprocessors.
7.1 Exception: Pyodide WebAssembly Runtime
| role | Supplier | Region | Purpose of Processing |
|---|---|---|---|
| Pyodide WASM runtime | jsDelivr (Pyodide official CDN) | Global edge network | Python WebAssembly execution environment and package downloads for opt-in programme execution |
The platform's opt-in code execution function (the runtime is located on the user's browser side and starts when triggered by the execute_code tool in ClassroomGPT and AIDA) uses the Pyodide WebAssembly Runtime. When the user actively triggers code execution, Pyodide dynamically downloads the runtime and the required Python packages from cdn.jsdelivr.net/pyodide/v0.27.5/full/. This subprocess is enabled only when actively triggered by the user; no personal data are transmitted, and only package file paths are requested.
8. Integration of secure devices for account two-factor authentication
The platform's two-factor authentication (2FA) uses the TOTP standard (RFC 6238). Users generate time-based codes through an authenticator app of their choice (such as Google Authenticator, Authy or 1Password). The platform does not transmit user-identifying information to the providers of those apps; the TOTP shared secret is stored only in the platform's database and in the user's authenticator app.
9. Change management
- Change records for this list are retained in the version history section of this document
- New, replacement, or region changes of major suppliers shall be announced on the Framework's homepage 30 days in advance
- Major changes will be notified to registered users by email
- Each vendor's DPA and sub-processor list (including any further sub-sub-processors) are governed by its official notices; this platform does not maintain them separately.
10. Items not included in this list
To maximise the readability of this list for users and partners, the following relationships are excluded from this list:
- The user’s own device manufacturer, operating system vendor, and browser vendor (outside the platform’s control)
- LMS or administrative systems of partner schools (clearly separated from this platform's data boundary)
- Upstream sub-sub-processors of each sub-processor (in accordance with each sub-processor's own DPA and public notices)
11. Contact point
| Privacy Contact | [email protected] |
|---|---|
| Objection to changes made by the sub-processor | [email protected] (please include [SUB-PROCESSOR OBJECTION] in the subject line) |
This list corresponds to §6 (cross-border transfers) of the "Privacy and Data Retention Policy"; it is recommended that you read them together to understand the full picture of data flows.