Secure by Design at EasyPeasy
- Secure by design
- Data protection
- Security measures
- Sub-processors
At EasyPeasy, every line of code is crafted with your security in mind. We adopt the latest framework releases, leverage proven modules, and integrate core security principles into every phase of our software development process. Our commitment to security is demonstrated through continuous reviews and external testing to stay ahead of emerging threats.
We are dedicated to constantly enhancing our internal processes and security measures to provide complete platform assurance. EasyPeasy is proud to be Cyber Essentials certified. Every team member undergoes security training and is subject to strict access controls to safeguard our users’ and customers’ data.
Security Certificates
We ensure the protection of your data by focusing on three key dimensions:
- Data Minimisation: We only store necessary information, as provided by you.
- Secure Storage: Your data is encrypted both at rest and in transit. Our storage processes are designed for maximum security, as detailed in our security measures.
- Access Control: We have robust internal access controls. Our team members can access data only under specific conditions and after thorough security checks. You can also set account roles within our software to restrict access to sensitive information.
We comply with the General Data Protection Regulation (GDPR) and have a designated Data Protection Officer to ensure accountability and privacy are embedded in our software and policies. Our compliance measures include:
- Full awareness of data locations, ensuring compliance even outside the EU.
- Restricting data access to necessary personnel and protecting against unauthorised access.
- Enabling you to edit, update, delete and export any information we hold.
- Obtaining consent during sign-up and allowing its withdrawal at any time.
You can review the exact standards we hold ourselves to via our Privacy Policy.
For any concerns, you can contact our Data Protection Officer.
Frequently asked questions
Are you compliant with GDPR?
Who is the EasyPeasy DPO?
Do you market other services to registered users of EasyPeasy?
How long do you retain our data?
Where is our Personally Identifiable Information (PII) data held?
Do you have a training programme in place for all staff who have access to user data?
If I were to ask you to remove all data I have provided to you, would you be able to do that in a timely fashion?
Do you have a process in place for reporting personal data breaches?
Do you have an information security policy?
Do you have a Data Protection Impact Assessment?
EasyPeasy is committed to maintaining the highest security standards through several measures:
- Encryption: All traffic between users and our systems is encrypted in transit.
- Access Control: We implement multiple layers of access controls, and only authorised personnel can access sensitive data.
- Regular Audits and Testing: Our software undergoes frequent security audits and testing to ensure resilience against threats.
- Certifications: We adhere to national and global best practice security standards and hold certifications including Cyber Essentials Plus.
- Employee Training: Our team members receive regular security training and are thoroughly vetted before accessing any customer data.
- Code review: We draw on industry experience, both internal and external, to ensure our code is readable and maintainable. This helps us develop secure systems with ease and confidence.
- Secure software development life cycle: We prioritise security in all feature designs and builds to ensure we always maintain our standards.
- HTTP strict transport security: Our application forces all requests over HTTPS, ensuring all traffic is secured in transit and protecting against protocol downgrade attacks.
- Encryption at rest: Our database has automatic encryption at rest, cloaking your data in another layer of protection.
- High availability: We've designed EasyPeasy to ensure high availability throughout the platform.
- Regular vulnerability scans: We test our product regularly by running vulnerability scans to ensure the safety of your data.
By integrating these measures, EasyPeasy ensures that your data is protected with the utmost care and security. For more detailed information, please refer to our privacy policy or contact our support team.
EasyPeasy Sub-Processors Page
Last Updated: July 2026
Overview
This page is for our Local Authority partners, commissioners and Family Hub teams. It sets out the sub-processors EasyPeasy engages to help deliver our app and data platform, what each one does, what categories of personal data they may touch, and how any international transfers are safeguarded. It is intended to sit alongside our Data Processing Agreement (DPA) and Privacy Policy, and to give you a clear, transparent way to review how your data — and the data of the families and practitioners you refer into EasyPeasy — is processed.
What is a sub-processor?
A sub-processor is a third-party service provider that EasyPeasy engages to process personal data on our behalf, in support of delivering the EasyPeasy app and platform to families, practitioners and our Local Authority partners. Each sub-processor below is subject to a written agreement requiring them to protect personal data to a standard consistent with UK GDPR, to only process data on our documented instructions, and to implement appropriate technical and organisational security measures.
Where a sub-processor is based outside the UK/EEA, or transfers data to a country without adopted standards, we rely on an approved transfer mechanism — in nearly all cases the UK Addendum to the EU Standard Contractual Clauses (SCCs) — to safeguard that transfer.
How we assess Sub-Processors
Before engaging a sub-processor, EasyPeasy reviews:
- Security certifications and controls
- Privacy and data protection practices
- Data processing agreements
- International transfer arrangements (where applicable)
- Data retention practices
- Incident response procedures
- Compliance with UK GDPR requirements
Where personal data is transferred outside the UK, appropriate safeguards such as the UK International Data Transfer Addendum and Standard Contractual Clauses (SCCs) are implemented. Sub-processors are reviewed on an ongoing basis, including as part of our annual compliance checks (see Keeping this page up to date).
Core infrastructure & hosting
These sub-processors host the EasyPeasy app, database and core service, and are fundamental to delivering the platform. All EasyPeasy customer and user data passes through at least one of these providers.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Core application hosting and database infrastructure | PII, email addresses, usage data | Amazon Web Services EMEA SARL | Yes — United States (UK Addendum to SCCs) |
| Google Cloud | Hosting and processing for service delivery and analytics | PII, email addresses, usage data | Google Cloud EMEA Ltd | Yes — United States (UK Addendum to SCCs) |
| Google Workspace | Hosting and processing customer data for service delivery | PII, name, email, work address, phone, job title | Google Cloud EMEA Limited | Yes — United States (UK Addendum to SCCs) |
| Microsoft 365 (Mail) | Hosting and processing customer data for service delivery | PII, name, email, work address, phone, job title | Microsoft Ireland Operations Limited | Yes — United States (UK Addendum to SCCs) |
| Dropbox | Document storage and sharing | Media / documents | Dropbox International Unlimited Company | Yes — United States (UK Addendum to SCCs) |
| Cloudinary | Media storage and delivery for app performance | Media (images, video) | Cloudinary UK Ltd | Yes — United States (UK Addendum to SCCs) |
| Amazon QuickSight | Internal website hosting and management support | Email address, user activity data | Amazon Web Services EMEA SARL | No restricted transfer identified |
Authentication & Payments
These sub-processors support user sign-in and the processing of subscription payments.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| Apple | App subscription processing and billing; Sign in with Apple | Payment information, subscription details, user identifiers | Apple Distribution International Limited | No restricted transfer identified |
| Google Payments | App subscription processing and billing | Payment information, subscription details, user identifiers | Google Ireland Limited | Yes — United States (UK Addendum to SCCs) |
| Google (Sign-in) | Account registration and sign-in | Email address, name, profile image, username | Google Ireland Limited | Yes — United States (UK Addendum to SCCs) |
| Stripe | Payment processing for subscriptions | Payment information, email address | Stripe Payments Europe, Limited | Yes — United States (UK Addendum to SCCs) |
Product & Personalisation Features
These sub-processors power specific features inside the app, such as personalised content, app stability monitoring and feature rollout.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| Recombee | Content personalisation | User activity data, device information, name, child's date of birth | Recombee s.r.o. | No restricted transfer identified |
| Metis | Personalisation and app performance | User activity data | Metis Limited | No restricted transfer identified |
| Firebase | Analytics and app performance monitoring | User activity data, device information | Google Ireland Limited | No restricted transfer identified |
| Sentry | Error monitoring and app performance | User activity data, device information | Functional Software, Inc. | No restricted transfer identified* |
| LaunchDarkly | Feature flag management and phased rollout | Email addresses, feature usage data | LaunchDarkly, Inc. | No restricted transfer identified |
| Iubenda | Consent and privacy-policy version tracking | User ID, date of consent/agreement | iubenda s.r.l. | No restricted transfer identified |
Communication & Collaboration Tools
These sub-processors support training sessions, meetings and messaging between EasyPeasy, practitioners and families, and secure document sharing with LA partners.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| Microsoft Teams | Meetings and training sessions | Email, name, user image, video | Microsoft Ireland Operations Limited | Yes — United States (UK Addendum to SCCs) |
| Zoom | Meetings and training sessions | PII, name, email, work address, phone, job title | Zoom Video Communications Ireland Ltd | Yes — United States (UK Addendum to SCCs) |
| Otter.ai | Meeting transcription | PII, name, email, work address, phone, job title | Otter.ai, Inc. | No restricted transfer identified* |
| Loom | Recorded product demos and process walkthroughs | PII, name, email, work address, phone, job title | Loom, Inc. | Yes — United States (UK Addendum to SCCs) |
| Sakari SMS | SMS notifications to service users | Name, email, mobile number | Sakari SMS Ltd | Yes — United States (UK Addendum to SCCs) |
| Microsoft SharePoint | Secure sharing of sensitive documents with LA partners | Email address, name, job title | Microsoft Ireland Operations Limited |
Yes — United States (UK Addendum to SCCs) |
| Communicate with users who are taking part in our parent meet-up's | Name, mobile number | Meta Platforms Ireland Limited |
Yes — United States (UK Addendum to SCCs) |
Analytics & Insight
These sub-processors help us understand app usage and performance, so we can improve the service. They generally process device and activity data rather than direct identifiers.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| Amplitude | Analytics and app performance monitoring | User activity data, device information | Amplitude, Inc. | No restricted transfer identified |
| Hotjar (Contentsquare) | Analytics and app performance monitoring | User activity data, device information | Contentsquare UK Limited | No restricted transfer identified |
| App Radar | App store analytics and performance monitoring | User activity data, device information | SplitMetrics GmbH | No restricted transfer identified |
| AppsFlyer | Analytics and app performance monitoring | User activity data, device information | AppsFlyer Ltd. | Yes — United States (UK Addendum to SCCs) |
| Google Tag Manager | Analytics and app performance monitoring | User activity data, device information | Google Ireland Limited | Yes — United States (UK Addendum to SCCs) |
| Airship | Analytics and app performance monitoring | PII, email addresses, usage data | Airship UK Ltd | No restricted transfer identified |
| Microsoft Power BI | Data-driven insights and reporting | User activity data, device information | Microsoft Ireland Operations Limited | Yes — United States (UK Addendum to SCCs) |
| Microsoft Fabric | Data-driven insights and reporting | User activity data, device information | Microsoft Ireland Operations Limited | Yes — United States (UK Addendum to SCCs) |
Marketing
These sub-processors support EasyPeasy's marketing and communications activity, including with LA partners and prospective services.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| HubSpot | Marketing and CRM | Name, email, work address, phone, job title | HubSpot Ireland Limited | Yes — United States (UK Addendum to SCCs) |
| Google Ad Manager | Marketing | Contact information | Google Ireland Limited | Yes — United States (UK Addendum to SCCs) |
| Meta | Targeted advertising and service personalisation | Contact information | Meta Platforms Ireland Limited | Yes — United States (UK Addendum to SCCs) |
| Got Legs Digital | Marketing | Email address, name, postcode | Got Legs Digital Limited | No restricted transfer identified |
AI Services
EasyPeasy uses AI tools to support internal document creation and analysis of meeting recordings involving employees and clients. AI providers do not have access to app user (family/child) data.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| OpenAI | Document creation and analysis of meeting recordings | Name, email, work address, phone, job title | OpenAI, L.L.C. | Yes — United States (UK Addendum to SCCs) |
LA Partner Support Tools
This sub-processor is engaged specifically to support our Local Authority partners.
| Sub-processor | Purpose | Personal data categories | Contracting entity | International transfer |
|---|---|---|---|---|
| Risk Ledger | Cyber security assurance platform for LA partners | Name, email, work address, phone | Risk Ledger Ltd | No restricted transfer identified |
* Marked in our internal register as no restricted transfer despite a US-based contracting entity — this is flagged for DPO re-verification before publication.
Keeping this page up to date
EasyPeasy reviews its sub-processors on an ongoing basis as part of our annual compliance checks and whenever we onboard a new supplier. We will update this page when we add, remove or materially change a sub-processor. If you would like advance notice of changes, please contact us using the details below and we will add you to our sub-processor update list.
International data transfers
Some EasyPeasy Sub-Processors operate outside the United Kingdom or may transfer data internationally.
Where this occurs, EasyPeasy implements appropriate safeguards, including:
- UK International Data Transfer Addendum (IDTA)
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where available
- Supplier-specific security and privacy assessments
Countries currently involved in restricted transfers include the United States, where additional safeguards have been implemented.
Questions & contact
If you have questions about this page, would like a copy of our Data Processing Agreement, or need more detail on any of the sub-processors listed above to support your own data protection impact assessment, please contact EasyPeasy's Data Protection Officer at dpo@easypeasyapp.com.
Requesting advance notification of new Sub-Processors
Local Authority partners may request to be notified of material changes to EasyPeasy’s Sub-Processor list. Requests should be sent to dpo@easypeasyapp.com and will be recorded against the relevant contract or Data Sharing Agreement.