Skip to content
  • Secure by design
  • Data protection
  • Security measures
  • Sub-processors

‍At EasyPeasy, every line of code is crafted with your security in mind. We adopt the latest framework releases, leverage proven modules, and integrate core security principles into every phase of our software development process. Our commitment to security is demonstrated through continuous reviews and external testing to stay ahead of emerging threats.

We are dedicated to constantly enhancing our internal processes and security measures to provide complete platform assurance. EasyPeasy is proud to be Cyber Essentials certified. Every team member undergoes security training and is subject to strict access controls to safeguard our users’ and customers’ data.

Security Certificates

We ensure the protection of your data by focusing on three key dimensions:

  • Data Minimisation: We only store necessary information, as provided by you.
  • Secure Storage: Your data is encrypted both at rest and in transit. Our storage processes are designed for maximum security, as detailed in our security measures.
  • Access Control: We have robust internal access controls. Our team members can access data only under specific conditions and after thorough security checks. You can also set account roles within our software to restrict access to sensitive information​.

We comply with the General Data Protection Regulation (GDPR) and have a designated Data Protection Officer to ensure accountability and privacy are embedded in our software and policies. Our compliance measures include:

  • Full awareness of data locations, ensuring compliance even outside the EU.
  • Restricting data access to necessary personnel and protecting against unauthorised access.
  • Enabling you to edit, update, delete and export any information we hold.
  • Obtaining consent during sign-up and allowing its withdrawal at any time.

You can review the exact standards we hold ourselves to via our Privacy Policy.

For any concerns, you can contact our Data Protection Officer.

Frequently asked questions
Are you compliant with GDPR?
Based on our current ICO audit and that of our Data Protection Officer, we are currently compliant.
Who is the EasyPeasy DPO?
Our Data Protection Officer (DPO) is Founder & CEO, Jen Lexmond. They can be contacted at dpo@easypeasyapp.com
Do you market other services to registered users of EasyPeasy?
No, we do not market other services to registered users of EasyPeasy.
How long do you retain our data?
Our retention periods are defined by you. You have complete control of what data is held on our system and are free to remove or amend it at any time.
Where is our Personally Identifiable Information (PII) data held?
Personally Identifiable Information (PII) data is held within the EU.
Do you have a training programme in place for all staff who have access to user data?
Yes, all EasyPeasy staff receive data protection training. 
If I were to ask you to remove all data I have provided to you, would you be able to do that in a timely fashion?
Of course. Our Data Subject Access Request (DSAR) procedure outlines the process for handling and responding to DSARs received from data subjects in a timely fashion.
Do you have a process in place for reporting personal data breaches?
Yes, we do. Our data breach reporting policy and procedure outlines the steps for identifying, reporting, and responding to data breaches to minimise the impact on affected individuals and mitigate risks to the organisation.
Do you have an information security policy?
Yes, we do. Our information security policy outlines our commitment to implementing robust security measures and controls to protect against various risks and threats.
Do you have a Data Protection Impact Assessment?
Yes, we do – you can view it here.

EasyPeasy is committed to maintaining the highest security standards through several measures:

  • Encryption: All traffic between users and our systems is encrypted in transit.
  • Access Control: We implement multiple layers of access controls, and only authorised personnel can access sensitive data.
  • Regular Audits and Testing: Our software undergoes frequent security audits and testing to ensure resilience against threats.
  • Certifications: We adhere to national and global best practice security standards and hold certifications including Cyber Essentials Plus.
  • Employee Training: Our team members receive regular security training and are thoroughly vetted before accessing any customer data​.
  • Code review: We draw on industry experience, both internal and external, to ensure our code is readable and maintainable. This helps us develop secure systems with ease and confidence.
  • Secure software development life cycle: We prioritise security in all feature designs and builds to ensure we always maintain our standards.
  • HTTP strict transport security: Our application forces all requests over HTTPS, ensuring all traffic is secured in transit and protecting against protocol downgrade attacks.
  • Encryption at rest: Our database has automatic encryption at rest, cloaking your data in another layer of protection.
  • High availability: We've designed EasyPeasy to ensure high availability throughout the platform.
  • Regular vulnerability scans: We test our product regularly by running vulnerability scans to ensure the safety of your data.

By integrating these measures, EasyPeasy ensures that your data is protected with the utmost care and security. For more detailed information, please refer to our privacy policy or contact our support team.

EasyPeasy Sub-Processors Page

Last Updated: July 2026

Overview

This page is for our Local Authority partners, commissioners and Family Hub teams. It sets out the sub-processors EasyPeasy engages to help deliver our app and data platform, what each one does, what categories of personal data they may touch, and how any international transfers are safeguarded. It is intended to sit alongside our Data Processing Agreement (DPA) and Privacy Policy, and to give you a clear, transparent way to review how your data — and the data of the families and practitioners you refer into EasyPeasy — is processed.

  1. What is a sub-processor

  2. Howe we assess Sub-processors

  3. Core Infrastructure & Hosting

  4. Authentication & Payments

  5. Product & Personalisation Features

  6. Communication & Collaboration Tools

  7. Analytics & Insight

  8. Marketing

  9. AI Services

  10. LA Partner Support Tools

  11. Keeping this page up to date

  12. Questions & contact


What is a sub-processor?

A sub-processor is a third-party service provider that EasyPeasy engages to process personal data on our behalf, in support of delivering the EasyPeasy app and platform to families, practitioners and our Local Authority partners. Each sub-processor below is subject to a written agreement requiring them to protect personal data to a standard consistent with UK GDPR, to only process data on our documented instructions, and to implement appropriate technical and organisational security measures.

Where a sub-processor is based outside the UK/EEA, or transfers data to a country without adopted standards, we rely on an approved transfer mechanism — in nearly all cases the UK Addendum to the EU Standard Contractual Clauses (SCCs) — to safeguard that transfer.

 

How we assess Sub-Processors

Before engaging a sub-processor, EasyPeasy reviews:

  • Security certifications and controls
  • Privacy and data protection practices
  • Data processing agreements
  • International transfer arrangements (where applicable)
  • Data retention practices
  • Incident response procedures
  • Compliance with UK GDPR requirements

Where personal data is transferred outside the UK, appropriate safeguards such as the UK International Data Transfer Addendum and Standard Contractual Clauses (SCCs) are implemented. Sub-processors are reviewed on an ongoing basis, including as part of our annual compliance checks (see Keeping this page up to date).

 

Core infrastructure & hosting

These sub-processors host the EasyPeasy app, database and core service, and are fundamental to delivering the platform. All EasyPeasy customer and user data passes through at least one of these providers.

Sub-processor Purpose Personal data categories Contracting entity International transfer
Amazon Web Services (AWS) Core application hosting and database infrastructure PII, email addresses, usage data Amazon Web Services EMEA SARL Yes — United States (UK Addendum to SCCs)
Google Cloud Hosting and processing for service delivery and analytics PII, email addresses, usage data Google Cloud EMEA Ltd Yes — United States (UK Addendum to SCCs)
Google Workspace Hosting and processing customer data for service delivery PII, name, email, work address, phone, job title Google Cloud EMEA Limited Yes — United States (UK Addendum to SCCs)
Microsoft 365 (Mail) Hosting and processing customer data for service delivery PII, name, email, work address, phone, job title Microsoft Ireland Operations Limited Yes — United States (UK Addendum to SCCs)
Dropbox Document storage and sharing Media / documents Dropbox International Unlimited Company Yes — United States (UK Addendum to SCCs)
Cloudinary Media storage and delivery for app performance Media (images, video) Cloudinary UK Ltd Yes — United States (UK Addendum to SCCs)
Amazon QuickSight Internal website hosting and management support Email address, user activity data Amazon Web Services EMEA SARL No restricted transfer identified

 

Authentication & Payments

These sub-processors support user sign-in and the processing of subscription payments.

Sub-processor Purpose Personal data categories Contracting entity International transfer
Apple App subscription processing and billing; Sign in with Apple Payment information, subscription details, user identifiers Apple Distribution International Limited No restricted transfer identified
Google Payments App subscription processing and billing Payment information, subscription details, user identifiers Google Ireland Limited Yes — United States (UK Addendum to SCCs)
Google (Sign-in) Account registration and sign-in Email address, name, profile image, username Google Ireland Limited Yes — United States (UK Addendum to SCCs)
Stripe Payment processing for subscriptions Payment information, email address Stripe Payments Europe, Limited Yes — United States (UK Addendum to SCCs)

 

Product & Personalisation Features

These sub-processors power specific features inside the app, such as personalised content, app stability monitoring and feature rollout.

Sub-processor Purpose Personal data categories Contracting entity International transfer
Recombee Content personalisation User activity data, device information, name, child's date of birth Recombee s.r.o. No restricted transfer identified
Metis Personalisation and app performance User activity data Metis Limited No restricted transfer identified
Firebase Analytics and app performance monitoring User activity data, device information Google Ireland Limited No restricted transfer identified
Sentry Error monitoring and app performance User activity data, device information Functional Software, Inc. No restricted transfer identified*
LaunchDarkly Feature flag management and phased rollout Email addresses, feature usage data LaunchDarkly, Inc. No restricted transfer identified
Iubenda Consent and privacy-policy version tracking User ID, date of consent/agreement iubenda s.r.l. No restricted transfer identified

 

Communication & Collaboration Tools

These sub-processors support training sessions, meetings and messaging between EasyPeasy, practitioners and families, and secure document sharing with LA partners.

Sub-processor Purpose Personal data categories Contracting entity International transfer
Microsoft Teams Meetings and training sessions Email, name, user image, video Microsoft Ireland Operations Limited Yes — United States (UK Addendum to SCCs)
Zoom Meetings and training sessions PII, name, email, work address, phone, job title Zoom Video Communications Ireland Ltd Yes — United States (UK Addendum to SCCs)
Otter.ai Meeting transcription PII, name, email, work address, phone, job title Otter.ai, Inc. No restricted transfer identified*
Loom Recorded product demos and process walkthroughs PII, name, email, work address, phone, job title Loom, Inc. Yes — United States (UK Addendum to SCCs)
Sakari SMS SMS notifications to service users Name, email, mobile number Sakari SMS Ltd Yes — United States (UK Addendum to SCCs)
Microsoft SharePoint Secure sharing of sensitive documents with LA partners Email address, name, job title Microsoft Ireland Operations Limited

Yes — United States (UK Addendum to SCCs)

WhatsApp Communicate with users who are taking part in our parent meet-up's   Name, mobile number Meta Platforms Ireland Limited

Yes — United States (UK Addendum to SCCs)

 

Analytics & Insight

These sub-processors help us understand app usage and performance, so we can improve the service. They generally process device and activity data rather than direct identifiers.

Sub-processor Purpose Personal data categories Contracting entity International transfer
Amplitude Analytics and app performance monitoring User activity data, device information Amplitude, Inc. No restricted transfer identified
Hotjar (Contentsquare) Analytics and app performance monitoring User activity data, device information Contentsquare UK Limited No restricted transfer identified
App Radar App store analytics and performance monitoring User activity data, device information SplitMetrics GmbH No restricted transfer identified
AppsFlyer Analytics and app performance monitoring User activity data, device information AppsFlyer Ltd. Yes — United States (UK Addendum to SCCs)
Google Tag Manager Analytics and app performance monitoring User activity data, device information Google Ireland Limited Yes — United States (UK Addendum to SCCs)
Airship Analytics and app performance monitoring PII, email addresses, usage data Airship UK Ltd No restricted transfer identified
Microsoft Power BI Data-driven insights and reporting User activity data, device information Microsoft Ireland Operations Limited Yes — United States (UK Addendum to SCCs)
Microsoft Fabric Data-driven insights and reporting User activity data, device information Microsoft Ireland Operations Limited Yes — United States (UK Addendum to SCCs)

 

Marketing

These sub-processors support EasyPeasy's marketing and communications activity, including with LA partners and prospective services.

Sub-processor Purpose Personal data categories Contracting entity International transfer
HubSpot Marketing and CRM Name, email, work address, phone, job title HubSpot Ireland Limited Yes — United States (UK Addendum to SCCs)
Google Ad Manager Marketing Contact information Google Ireland Limited Yes — United States (UK Addendum to SCCs)
Meta Targeted advertising and service personalisation Contact information Meta Platforms Ireland Limited Yes — United States (UK Addendum to SCCs)
Got Legs Digital Marketing Email address, name, postcode Got Legs Digital Limited No restricted transfer identified

 

AI Services

EasyPeasy uses AI tools to support internal document creation and analysis of meeting recordings involving employees and clients. AI providers do not have access to app user (family/child) data.

Sub-processor Purpose Personal data categories Contracting entity International transfer
OpenAI Document creation and analysis of meeting recordings Name, email, work address, phone, job title OpenAI, L.L.C. Yes — United States (UK Addendum to SCCs)

 

LA Partner Support Tools

This sub-processor is engaged specifically to support our Local Authority partners.

Sub-processor Purpose Personal data categories Contracting entity International transfer
Risk Ledger Cyber security assurance platform for LA partners Name, email, work address, phone Risk Ledger Ltd No restricted transfer identified


* Marked in our internal register as no restricted transfer despite a US-based contracting entity — this is flagged for DPO re-verification before publication.

Keeping this page up to date

EasyPeasy reviews its sub-processors on an ongoing basis as part of our annual compliance checks and whenever we onboard a new supplier. We will update this page when we add, remove or materially change a sub-processor. If you would like advance notice of changes, please contact us using the details below and we will add you to our sub-processor update list.

International data transfers

Some EasyPeasy Sub-Processors operate outside the United Kingdom or may transfer data internationally.

Where this occurs, EasyPeasy implements appropriate safeguards, including:

  • UK International Data Transfer Addendum (IDTA)
  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions where available
  • Supplier-specific security and privacy assessments

Countries currently involved in restricted transfers include the United States, where additional safeguards have been implemented.

Questions & contact

If you have questions about this page, would like a copy of our Data Processing Agreement, or need more detail on any of the sub-processors listed above to support your own data protection impact assessment, please contact EasyPeasy's Data Protection Officer at dpo@easypeasyapp.com.

Requesting advance notification of new Sub-Processors

Local Authority partners may request to be notified of material changes to EasyPeasy’s Sub-Processor list. Requests should be sent to dpo@easypeasyapp.com and will be recorded against the relevant contract or Data Sharing Agreement.