Sub-Processor Disclosure

Version 2.0.0 · Last updated 2026-06-02

DRAFT — Not yet legally reviewed. The text below names the canonical operator (Inspiration Dance LLC) but has not yet been counsel- reviewed. Use for orientation only; districts evaluating procurement should request a counsel-vetted copy.

Last updated: June 2026

[DRAFT — Not yet legally reviewed.] This disclosure was reconciled against the codebase by the AA-291 External Services + DPA Collection Audit. It lists every external service currently called by the platform, grouped by category, with each vendor's legal entity, DPA URL, DPA status, PII classification, certifications, and any deal-breaker flag raised during research. Five vendors are flagged as deal-breaker-for-districts and appear in their own section near the end. The draft: true flag will be removed only after operator + legal review.

The following third-party services process data on behalf of Avatar Animator. This page is maintained as part of our commitment to transparency under FERPA, COPPA, CCPA/CPRA, GDPR, and US state student-privacy laws.

For questions or to request a Data Processing Agreement, contact darryl@inspirationdancecompany.ai.


1. Cloud Infrastructure

Amazon Web Services (AWS)

Vercel

Neon (Serverless Postgres) — conditional, pending AA-308


2. Auth / Identity (SSO + Rostering)

Google (OAuth + Classroom + Cloud Storage)

Clever

ClassLink


3. Email

Resend

AWS SES (failover; see AWS entry in §1)

AWS SES is the failover transactional email path, wired in server/lib/ses.ts. Covered by the same AWS DPA, same certifications, same legal entity as the rest of the AWS footprint.


4. AI — Text / NLP

OpenAI

Perplexity


5. AI — Image / Video Generation

RunwayML


6. AI — Music

MusicGPT (Mureka) — deal-breaker; replacement recommended


7. AI — Motion Capture / Video Understanding

DeepMotion — deal-breaker (conditional on payload reality)

QuickMagic — deal-breaker; replacement recommended

TwelveLabs


8. Media (Stock Assets)

Pexels

Unsplash


9. Billing

Stripe


10. CRM / Sales

HubSpot


11. Error Tracking / Telemetry

Sentry


12. Aggregator (API Marketplace Routing)

RapidAPI (now Rapid, a Nokia Corporation subsidiary since Nov 2024)


13. External Content Source (deal-breakers — replacement recommended)

tiktok-api23 (RapidAPI marketplace listing) — deal-breaker

TikTok-direct (oembed + embed.js + player iframe) — deal-breaker


Appendix A — Frontend Asset Loaders (pii_sent: none)

Per AA-291 orchestrator decision 2026-05-30 §4: listed for transparency; the platform never sends student data to these — they serve static assets to the user's browser. The browser's IP / UA reaches these origins when the asset is fetched.

cdn.jsdelivr.net (jsDelivr)

storage.googleapis.com (Google Cloud Storage — MediaPipe model hosting)

fonts.googleapis.com + fonts.gstatic.com (Google Fonts)

cdnjs.cloudflare.com (Cloudflare CDN — Font Awesome) and cdn.tailwindcss.com (Tailwind Play CDN)


Appendix B — Build / CI Infrastructure (not for district-facing disclosure)

Per AA-291 orchestrator decision 2026-05-30 §5: these vendors process our source code and deployment artifacts, not student data. Listed for full auditability; segregated from the main disclosure block because they are materially different from runtime sub-processors.

npm Registry (npmjs.com / GitHub-owned)

GitHub / GitHub Actions


Appendix C — Internal Infrastructure (not a third-party sub-processor)

Per AA-291 orchestrator decision 2026-05-30 §1: listed in our security model / threat surface, but not a contractually-relevant sub-processor for district DPA purposes.

iLumaCap


Questions

For questions about our data processing practices or to request a Data Privacy Agreement, contact us at darryl@inspirationdancecompany.ai.