Skip to main content

For your organisation’s review

Security and privacy at TEEI

How we manage data, operate our platforms and use AI across TEEI programmes. Access technical checks, processing information and documentation for your organisation’s review.

15 checks run on every visit · raw responses · commands to reproduce

Technical checks · running22:20:47 UTC

theeducationalequalityinstitute.org · run on this visit · started 22:20:47 UTC

0of 15 checks answered

5 services · 8 web and email · 2 registers · 0 notes

22:20:47run order · ms
Cached for one minutechecks.json →
Live counterReading the public counterYour connection · TLSv1.3 · HTTP/2 · via CMH
For IT security
15 checksrunning now

System status and technical checks

Check service availability, web security headers, email authentication and organisational registration records. Each result includes a timestamp, the source response and a command to reproduce the check.

0 of 15 answered · runningcache 60 s · headers and DNS 300 s · registers 24 h
Services

Website, TEEI Language, TEEI Mentorship and CSR Cockpit.

0 of 5
Websitechecking
TEEI Languagechecking
TEEI Mentorshipchecking
CSR Cockpitchecking
Public impact counterchecking
Web and email

Security headers, email authentication records and our published security contact.

0 of 8
Website headerschecking
TEEI Language headerschecking
TEEI Mentorship headerschecking
CSR Cockpit headerschecking
DMARCchecking
SPFchecking
DKIMchecking
security.txt (RFC 9116)checking
Organisation records

Registration details from Brønnøysund and the IRS.

0 of 2
Brønnøysund registerchecking
IRS Business Master Filechecking
Machine-readable resultsare available in checks.jsonresults are cached for one minute
For legal and procurement
Policy registerowner · version · review date

Security and operational policies

The policies TEEI operates under, from software releases and incident response to data protection, AI use, whistleblowing and volunteer screening. Each entry shows its owner, version and review date, and the policies it relies on.

Security and operationsInformation securityPrivacy and AIPeople and governancePublic policies OPS-001 IRP-001 BCP-001 PRIV-001 SEC-002 SEC-003 SEC-001 SEC-004 SEC-005 SEC-006 SEC-007 SEC-008 SEC-009 SEC-010 SEC-011 SEC-012 PRIV-002 PRIV-003 PRIV-004 PRIV-005 PRIV-006 PRIV-007 AI-001 GOV-001 GOV-002 GOV-003 GOV-004 GOV-005 GOV-006 Safeguarding Privacy Cookies Accessibility How we work Disclosure
In forcePublishedNamed as related
Security and operationsIn force since 27 February 2026
OPS-001 Change Management PolicyPlatform Administrator v1.2 In force

Changes move through staging before promotion to versioned production deployments, with rollback procedures built into the release process.

Purpose, from the documentThis policy defines how changes to the CSR Cockpit platform are categorised, authorised, tested, deployed, traced, and rolled back. The goal is to keep production changes intentional, reviewable, tested, and reversible.

SectionsPurpose · Scope · Change Categories · Validation and Release Gates · Production Deployment Path · Approval Requirements by Change Type · Database Migration Process · Rollback Procedures · Rollback Drill Procedure · Traceability and Audit Trail · Roles and Responsibilities · Review Cadence · Cross-References

Owner
Platform Administrator
Applies to
CSR Cockpit
Effective
27 February 2026
Last updated
22 July 2026
Next review
27 February 2027

Request a summary

IRP-001 Incident Response PlanPlatform Administrator v1.1 In force

Our incident response plan defines how we handle security and personal-data incidents, including responsibilities, escalation and external notifications.

Purpose, from the documentThis policy defines how TEEI detects, assesses, contains, recovers from, and learns from security incidents affecting CSR Cockpit. It is a control policy, not evidence that monitoring, an on-call rotation, a tabletop, or a notification has occurred.

SectionsPurpose And Approval Boundary · Scope · Severity · Roles · Response Phases · Personal-Data Breach Assessment · Communications · Evidence And Exercises · Cross-References

Owner
Platform Administrator
Applies to
CSR Cockpit
Effective
27 February 2026
Last updated
19 July 2026
Next review
27 February 2027

Request a summary

BCP-001 Business Continuity PlanPlatform Administrator v1.2 In force

Our continuity plan sets out recovery procedures for the Cloudflare Workers services that support TEEI’s platforms.

Purpose, from the documentThis Business Continuity Plan (BCP) defines the recovery objectives, resilience architecture, backup strategy, recovery procedures, and communication protocols that keep the CSR Cockpit platform recoverable after planned maintenance, application defects, database incidents, or supporting-service outages.

SectionsPurpose · Scope · Recovery Objectives · Infrastructure Resilience · Backup Strategy · Recovery Procedures · Rollback Drill Procedure · BCP Test Schedule · Communication Plan During Outages · Roles and Responsibilities · Review Cadence · Cross-References

Owner
Platform Administrator
Applies to
CSR Cockpit
Effective
27 February 2026
Last updated
22 July 2026
Next review
27 February 2027

Request a summary

PRIV-001 Data Retention PolicyPlatform Administrator v1.1 In force

Our retention policy defines how long CSR Cockpit records are kept, with requirements for different record types, consent events and partnership deliverables.

SectionsStatus And Authority · Scope · Current Executable Schedule · HRIS-synchronised employee records · Open Decisions And Reconciliation Gaps · Execution And Verification · Data Subject Requests · Backups And Providers · Evidence · Cross-References

Owner
Platform Administrator
Applies to
CSR Cockpit
Effective
27 February 2026
Last updated
19 July 2026
Next review
27 February 2027

Request a summary

SEC-002 Penetration Testing CadencePlatform Administrator v1.1 In force

Our testing policy specifies annual independent web and API penetration testing, annual threat-model reviews and additional reviews following material architecture changes.

Purpose, from the documentThis policy defines when CSR Cockpit requires independent penetration testing, how scope is derived, and how findings are evidenced and remediated. Historical internal reports are not substitutes for a current external test of the Router Cloudflare Worker runtime.

SectionsPurpose · Current Scope Baseline · Cadence And Triggers · Engagement Controls · Required Coverage · Remediation · Evidence And Retention · Cross-References

Owner
Platform Administrator
Applies to
CSR Cockpit
Effective
27 February 2026
Last updated
19 July 2026
Next review
27 February 2027

Request a summary

SEC-003 Security Awareness Training ProgrammePlatform Administrator v1.1 In force

Our security awareness programme defines training for the people who operate TEEI’s systems.

Purpose, from the documentThis document defines the security awareness training programme for all team members who develop, operate, or have administrative access to the CSR Cockpit platform. The programme ensures that personnel understand their security responsibilities, recognise common attack vectors, and follow secure practices when handling personal data and operating the platform.

SectionsPurpose · Scope · Training Structure · Annual Assessment and Certification · Training Records · Roles and Responsibilities · Review Cadence · Cross-References

Owner
Platform Administrator
Applies to
CSR Cockpit
Effective
27 February 2026
Last updated
19 July 2026
Next review
27 February 2027

Request a summary

Information securityIn force since 1 December 2025
SEC-001 Information Security PolicyExecutive Director v1.0 In force

Purpose, from the documentThe Educational Equality Institute, TEEI, protects the confidentiality, integrity and availability of information entrusted to it. This policy establishes the organisation-wide requirements for managing information-security risk across TEEI programmes, the public website, the shared platform and CSR Cockpit. It is the umbrella policy for the information-security policy family.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Executive Director
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
OPS-001IRP-001BCP-001PRIV-001SEC-002SEC-003SEC-004SEC-005SEC-006SEC-007SEC-008SEC-009SEC-010SEC-011SEC-012

Request a summary

SEC-004 Access Control and Identity PolicyPlatform Administrator v1.0 In force

Purpose, from the documentThis policy ensures that only authorised people and approved services can access TEEI information and systems. Identity and access controls protect participants, volunteers, partners, staff and TEEI operations from unauthorised access, accidental disclosure and avoidable privilege.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Platform Administrator
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-005SEC-007SEC-008SEC-011IRP-001PRIV-001

Request a summary

SEC-005 Acceptable Use PolicyExecutive Director v1.0 In force

Purpose, from the documentThis policy sets the conditions for using TEEI systems, accounts, information and communications. It supports a safe and reliable remote working environment while respecting the responsibilities TEEI has to participants, volunteers, partners and colleagues.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Executive Director
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-004SEC-007SEC-008SEC-012IRP-001PRIV-001Safeguarding Policy

Request a summary

SEC-006 Secure Development PolicyPlatform Administrator v1.0 In force

Purpose, from the documentThis policy establishes security requirements for software, infrastructure configuration, scripts and integrations developed or changed for TEEI. Secure development reduces the likelihood that a change exposes information, weakens safeguards or disrupts a service used by participants, volunteers, partners or colleagues.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Platform Administrator
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-004SEC-007SEC-008SEC-009SEC-011OPS-001IRP-001

Request a summary

SEC-007 Logging and Monitoring PolicyPlatform Administrator v1.0 In force

Purpose, from the documentThis policy establishes requirements for recording and reviewing security-relevant activity. Appropriate logging and monitoring helps TEEI detect failures, investigate suspected incidents, protect the availability of services and account for administrative activity without collecting more information than is necessary.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Platform Administrator
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-004SEC-005SEC-006SEC-008SEC-009IRP-001PRIV-001

Request a summary

SEC-008 Encryption and Key Management PolicyPlatform Administrator v1.0 In force

Purpose, from the documentThis policy protects TEEI information, credentials and cryptographic material against unauthorised disclosure, modification and use. Encryption and sound key management are required controls for the remote, cloud-based systems that TEEI uses to deliver its programmes and administrative services.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Platform Administrator
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-004SEC-006SEC-007SEC-009SEC-011IRP-001PRIV-001

Request a summary

SEC-009 Vulnerability and Patch Management PolicyPlatform Administrator v1.0 In force

Purpose, from the documentThis policy requires TEEI to identify, assess, prioritise and remediate security vulnerabilities in its systems, dependencies, configurations and approved services. Prompt and proportionate patch management reduces the likelihood that known weaknesses harm participants, volunteers, partners, information or service availability.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Platform Administrator
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-006SEC-007SEC-008SEC-011SEC-002IRP-001Vulnerability Disclosure Policy

Request a summary

SEC-010 Backup and Recovery PolicyPlatform Administrator v1.0 In force

Purpose, from the documentThis policy requires TEEI to maintain recoverable copies of information and system components needed to restore services after accidental deletion, corruption, service failure, security incident or other disruption. Backups support continuity of the public website, programme platforms, CSR Cockpit and administrative services, but they do not replace the continuity arrangements in BCP-001 or incident handling in IRP-001.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Platform Administrator
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-004SEC-007SEC-008SEC-011BCP-001IRP-001PRIV-001

Request a summary

SEC-011 Third-Party and Vendor Risk PolicyData Protection Lead v1.0 In force

Purpose, from the documentThis policy requires TEEI to assess and manage security, privacy, continuity and transfer risks arising from third-party services. Suppliers are important to TEEI's remote, cloud-based operations, but their use does not transfer TEEI's responsibility to protect information and make proportionate decisions.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Data Protection Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-004SEC-006SEC-007SEC-008SEC-009SEC-010PRIV-001IRP-001

Request a summary

SEC-012 Endpoint and Device PolicyPlatform Administrator v1.0 In force

Purpose, from the documentThis policy sets minimum security requirements for devices used to access TEEI systems or information. TEEI works through a fully remote and asynchronous team. Endpoints therefore form an important boundary between TEEI accounts, participant information, programme operations and the environments in which people work.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Platform Administrator
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
SEC-001SEC-004SEC-005SEC-007SEC-008SEC-009IRP-001Safeguarding Policy

Request a summary

Privacy and AIIn force since 1 December 2025
PRIV-002 Data Protection PolicyData Protection Lead v1.0 In force

Purpose, from the documentThis policy sets the organisation-wide requirements for personal-data processing by The Educational Equality Institute (TEEI). It supports lawful, fair and transparent treatment of people whose data TEEI handles, including participants, volunteers, donors, team members and partner employees. It applies alongside the GDPR, the Norwegian Personal Data Act, applicable US charity obligations, and the public Privacy Policy.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Data Protection Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
PRIV-001PRIV-003PRIV-004PRIV-005PRIV-006PRIV-007AI-001IRP-001

Request a summary

PRIV-003 Data Classification and Handling PolicyData Protection Lead v1.0 In force

Purpose, from the documentThis policy defines how TEEI classifies information and how each class must be handled. Its purpose is to make the protection needed by a record clear before it is collected, stored, shared or disposed of. Classification is based on the sensitivity of the information, the people it concerns and the harm that could result from misuse, loss or inappropriate disclosure.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Data Protection Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
PRIV-001PRIV-002PRIV-005PRIV-007Safeguarding Policy

Request a summary

PRIV-004 Data Protection Impact Assessment ProcedureData Protection Lead v1.0 In force

Purpose, from the documentThis procedure ensures that TEEI identifies and addresses high risks to people before starting or materially changing processing that is likely to affect their rights and freedoms. A data protection impact assessment, or DPIA, is a documented assessment of necessity, proportionality, risks and safeguards. It supports informed decisions; it does not replace the ordinary requirements in PRIV-002.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Data Protection Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
PRIV-002PRIV-003AI-001OPS-001

Request a summary

PRIV-005 Personal Data Breach ProcedureData Protection Lead v1.0 In force

Purpose, from the documentThis procedure defines how TEEI identifies, contains, assesses, records and notifies personal-data breaches. It is designed to protect people and to support TEEI's legal duties. It supplements IRP-001, which governs the technical incident response. It does not replace safeguarding escalation requirements where a breach also creates a safeguarding concern.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Data Protection Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
IRP-001PRIV-002PRIV-003PRIV-006Safeguarding Policy

Request a summary

PRIV-006 Data Subject Rights ProcedureData Protection Lead v1.0 In force

Purpose, from the documentThis procedure sets out how TEEI receives, verifies, assesses, fulfils and records requests from people exercising rights over their personal data. It supports the rights of access, rectification, erasure, restriction, portability and objection under applicable data-protection law. It also supports fair, secure and consistent handling when TEEI must limit or refuse a request under a lawful exemption.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Data Protection Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
PRIV-002PRIV-003PRIV-005PRIV-007Privacy Policy

Request a summary

PRIV-007 Organisation-wide Records Retention PolicyData Protection Lead v1.0 In force

Purpose, from the documentThis policy sets the organisation-wide retention requirements for TEEI records. It extends PRIV-001, which applies to CSR Cockpit, to the other TEEI programmes, public website and internal functions. TEEI retains records only for defined purposes and then deletes or anonymises them unless a lawful retention duty, legal hold, safeguarding need or active investigation requires continued retention.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Data Protection Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
PRIV-001PRIV-002PRIV-003PRIV-005PRIV-006Safeguarding Policy

Request a summary

AI-001 Responsible AI Use PolicyExecutive Director v1.0 In force

Purpose, from the documentThis policy sets the requirements for responsible use of artificial intelligence by The Educational Equality Institute (TEEI). TEEI uses AI only for defined support tasks, with human responsibility for decisions and appropriate protection for people and their data. This policy applies to AI features used in programmes, public services, CSR Cockpit, administration and software development.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Executive Director
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
PRIV-002PRIV-003PRIV-004PRIV-005OPS-001Safeguarding Policy

Request a summary

People and governanceIn force since 1 December 2025
GOV-001 Code of ConductExecutive Director v1.0 In force

Purpose, from the documentThis policy sets the conduct requirements for people acting for The Educational Equality Institute (TEEI). It protects participants, colleagues and organisational resources by making expectations and accountability explicit. It must be read with the policies identified above; it does not replace their specialist reporting or decision procedures.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Executive Director
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
GOV-002GOV-003GOV-004GOV-005GOV-006SEC-003PRIV-007Safeguarding Policy

Request a summary

GOV-002 Whistleblowing PolicyBoard of Directors v1.0 In force

Purpose, from the documentThis policy enables people to report suspected wrongdoing connected with The Educational Equality Institute (TEEI) and requires protection from retaliation. It establishes independent handling and accountable records. It also supports accurate answers to governance questions in IRS Form 990. This draft must not be represented as an adopted policy or evidence that its requirements already operate.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Board of Directors
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
GOV-001GOV-003GOV-004GOV-005PRIV-007Safeguarding Policy

Request a summary

GOV-003 Conflict of Interest PolicyBoard of Directors v1.0 In force

Purpose, from the documentThis policy requires decisions for The Educational Equality Institute (TEEI) to serve its charitable purposes rather than private interests. It provides practical requirements for the duty of loyalty in the Norwegian association and the conflict policy required by Article VIII of the US bylaws. It supports accurate reporting of policy adoption, disclosure and monitoring in IRS Form 990 Part VI without treating a written draft as evidence of implementation.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Board of Directors
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
GOV-001GOV-002GOV-004PRIV-007

Request a summary

GOV-004 Document Retention and Destruction PolicyExecutive Director v1.0 In force

Purpose, from the documentThis policy governs the retention and authorised destruction of organisational records of The Educational Equality Institute (TEEI). It requires records to support governance, financial accountability, legal obligations and defensible decisions. It addresses the organisational policy considered in IRS Form 990. Personal-data retention requirements are governed by PRIV-007; PRIV-001 retains its specific CSR Cockpit scope.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Executive Director
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
GOV-002GOV-003PRIV-001PRIV-007

Request a summary

GOV-005 Anti-Harassment and Equal Opportunity PolicyExecutive Director v1.0 In force

Purpose, from the documentThis policy requires fair access to opportunities and prohibits harassment, discrimination and retaliation in The Educational Equality Institute (TEEI). It sets requirements for prevention, reporting, investigation and outcomes. It supports the non-discrimination commitment in Article XII of the US bylaws without claiming that one jurisdiction's employment rules apply identically to every contributor.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Executive Director
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
GOV-001GOV-002GOV-003GOV-004GOV-006PRIV-007Safeguarding Policy

Request a summary

GOV-006 Volunteer Screening and Vetting PolicyProgramme Lead v1.0 In force

Purpose, from the documentThis policy sets requirements for selecting, approving and supervising volunteers for The Educational Equality Institute (TEEI). Screening must support safe and appropriate role assignments while respecting applicants' rights. It must not be represented as a guarantee of future conduct or complete knowledge of an applicant's history.

SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review

Owner
Programme Lead
Applies to
TEEI-wide
Effective
1 December 2025
Last updated
16 September 2026
Next review
1 December 2026
Related
GOV-001GOV-002GOV-003GOV-004GOV-005SEC-003PRIV-007AI-001Safeguarding Policy

Request a summary

Public policiesPublished on this site
Public Safeguarding PolicyOn this site Public

Safe environments. No exceptions. Applies to all TEEI activities regardless of location, including in-person events, online interactions, and communications through any channel.

Applies to
Everyone TEEI works with
Effective
December 2025

Read the policy

Public Privacy PolicyOn this site Public

Minimal data. Never sold. What personal data we collect, why we collect it, and how we protect it.

Applies to
Everyone TEEI works with
Effective
December 2025

Read the policy

Public Cookie PolicyOn this site Public

Few cookies. Off by default. Which cookies the site sets, what they do, and how to change your choice.

Applies to
Everyone TEEI works with
Effective
7 July 2026

Read the policy

Public Accessibility StatementOn this site Public

Accessible by design. The platforms TEEI uses to deliver its programmes, and how we keep them usable for everyone.

Applies to
Everyone TEEI works with
Effective
December 2025

Read the policy

Public How We WorkOn this site Public

Fully remote. Async-first. Contributors across 50+ countries. No office, no fixed hours - just meaningful work in education, mentoring, and language access.

Applies to
Everyone TEEI works with

Read the policy

Public Vulnerability Disclosure PolicyOn this site Public

Scope, what we ask of researchers, what we do with a report, and how to send one.

Applies to
Everyone TEEI works with

Read the policy

Request policy summaries

For your data protection officer
21 processorsEU · global edge · United States

Data storage and processing

Records live in Ireland. AI, video and captions for TEEI Language and Mentorship run in AWS EU regions. Email, analytics, report drafting and transcription run in the United States. Every provider is in the register below.

ServiceLocation
Account, session and reporting recordsIreland, AWS eu-west-1
AI screening and chat safeguarding for TEEI Language and MentorshipIreland, Amazon Bedrock EU profile
Video sessions and live captionsAmazon Chime and Transcribe: media in Ireland, meeting control in Frankfurt
Error monitoringGermany, Sentry EU region
WBP chat translationGermany, DeepL
Transactional emailUnited States, Resend
CSR Cockpit report drafting and voice transcriptionUnited States, Google Gemini and OpenAI
Product analyticsUnited States, PostHog
Web request processingCloudflare’s global edge
Meetings, errors, translationGermany Records, AI, videoIreland, AWS eu-west-1 Email, analytics, reports, transcriptionUnited States Oslo · office New York · office 1 2 3 4 5
Processing locationRegistered office
  1. 1Meeting control, errors, translation · Germany
  2. 2Records, AI, video · Ireland, AWS eu-west-1
  3. 3Email, analytics, reports, transcription · United States
  4. 4Registered office · Oslo
  5. 5Registered office · New York

The sub-processor register lists every provider that processes personal data for TEEI: purpose, processing location and transfer basis, reconciled against the code on 2026-09-16.

View the sub-processor register
Sub-processor register · version 1.021 processors · reconciled 2026-09-16
ProcessorPurposeProcessing locationTransfer mechanism
EUIreland and Germany
Turso (libSQL)Primary application databaseEU, Ireland (AWS eu-west-1); backups in the United StatesTurso data processing agreement
Amazon BedrockClaude models for volunteer application screening and group-chat safeguarding (TEEI Language and Mentorship)EU, Ireland; EU inference profileAWS DPA, standard contractual clauses; no training, no retention
Amazon Chime SDKLive video sessionsMedia in Ireland, meeting control in FrankfurtAWS DPA, standard contractual clauses
Amazon TranscribeLive captions in video sessionsEUAWS DPA, standard contractual clauses
AWS Lambda and S3Platform API, uploads and testimonials, contribution-report PDF renderingEU, Ireland (eu-west-1)AWS DPA, standard contractual clauses
SentryError monitoring, scrubbed before sendingEU region, GermanySentry DPA, standard contractual clauses; Data Privacy Framework
DeepLTranslation of WBP chat messagesEEA, GermanyEU processor
Global edge
CloudflareHosting, edge network, object storage, bot protection, video hostingGlobal edgeCloudflare DPA, standard contractual clauses; Data Privacy Framework
United States
ResendTransactional emailUnited StatesResend DPA, standard contractual clauses; Data Privacy Framework
Sinch (Mailjet)Email fallback when Resend fails (TEEI Language and Mentorship)Sinch cloudSinch DPA v8, standard contractual clauses; Data Privacy Framework
Google Gemini APICSR Cockpit report drafting, disclosure extraction and transcription fallback; WBP translation fallback; website video searchUnited StatesGoogle Cloud DPA, standard contractual clauses
Google Workspace APIsSheets as a second store for website forms, Calendar for partner bookings, Gmail for the support inboxGoogle WorkspaceGoogle Cloud DPA, standard contractual clauses
Google Analytics 4 and AdsWeb analytics and ad attribution after consentEU collection serversGoogle Ads data processing terms, standard contractual clauses
PostHogProduct analytics and masked session replayUnited StatesPostHog DPA, Data Privacy Framework; standard contractual clauses
HotjarSession recordings and heatmaps on the website and WBP portalHotjar, EuropeHotjar DPA
WorkOSEnterprise single sign-on and directory sync for Cockpit managersUnited StatesWorkOS DPA, standard contractual clauses
LinkedInSign in with LinkedIn for managers, volunteers and buddy applicantsLinkedIn IrelandLinkedIn DPA, standard contractual clauses
MicrosoftMicrosoft sign-in and Outlook calendar for Skills Academy volunteersMicrosoft cloudMicrosoft DPA (22 May 2026)
FundraiseUpDonation checkoutUnited StatesFundraiseUp DPA, standard contractual clauses
OpenAI WhisperTranscription of uploaded voice and interview recordings (CSR Cockpit)United StatesOpenAI DPA, standard contractual clauses; no training on API data
CourseraEnrolment receipts for Mentorship-hosted Coursera accessUnited StatesCoursera DPA; Data Privacy Framework, standard contractual clauses
SourceTEEI’s sub-processor registerversion 1.0 · reconciled 2026-09-16

Turso (libSQL)

PurposePrimary application databaseLocationEU, Ireland (AWS eu-west-1); backups in the United StatesTransferTurso data processing agreement

Amazon Bedrock

PurposeClaude models for volunteer application screening and group-chat safeguarding (TEEI Language and Mentorship)LocationEU, Ireland; EU inference profileTransferAWS DPA, standard contractual clauses; no training, no retention

Amazon Chime SDK

PurposeLive video sessionsLocationMedia in Ireland, meeting control in FrankfurtTransferAWS DPA, standard contractual clauses

Amazon Transcribe

PurposeLive captions in video sessionsLocationEUTransferAWS DPA, standard contractual clauses

AWS Lambda and S3

PurposePlatform API, uploads and testimonials, contribution-report PDF renderingLocationEU, Ireland (eu-west-1)TransferAWS DPA, standard contractual clauses

Sentry

PurposeError monitoring, scrubbed before sendingLocationEU region, GermanyTransferSentry DPA, standard contractual clauses; Data Privacy Framework

DeepL

PurposeTranslation of WBP chat messagesLocationEEA, GermanyTransferEU processor

Cloudflare

PurposeHosting, edge network, object storage, bot protection, video hostingLocationGlobal edgeTransferCloudflare DPA, standard contractual clauses; Data Privacy Framework

Resend

PurposeTransactional emailLocationUnited StatesTransferResend DPA, standard contractual clauses; Data Privacy Framework

Sinch (Mailjet)

PurposeEmail fallback when Resend fails (TEEI Language and Mentorship)LocationSinch cloudTransferSinch DPA v8, standard contractual clauses; Data Privacy Framework

Google Gemini API

PurposeCSR Cockpit report drafting, disclosure extraction and transcription fallback; WBP translation fallback; website video searchLocationUnited StatesTransferGoogle Cloud DPA, standard contractual clauses

Google Workspace APIs

PurposeSheets as a second store for website forms, Calendar for partner bookings, Gmail for the support inboxLocationGoogle WorkspaceTransferGoogle Cloud DPA, standard contractual clauses

Google Analytics 4 and Ads

PurposeWeb analytics and ad attribution after consentLocationEU collection serversTransferGoogle Ads data processing terms, standard contractual clauses

PostHog

PurposeProduct analytics and masked session replayLocationUnited StatesTransferPostHog DPA, Data Privacy Framework; standard contractual clauses

Hotjar

PurposeSession recordings and heatmaps on the website and WBP portalLocationHotjar, EuropeTransferHotjar DPA

WorkOS

PurposeEnterprise single sign-on and directory sync for Cockpit managersLocationUnited StatesTransferWorkOS DPA, standard contractual clauses

LinkedIn

PurposeSign in with LinkedIn for managers, volunteers and buddy applicantsLocationLinkedIn IrelandTransferLinkedIn DPA, standard contractual clauses

Microsoft

PurposeMicrosoft sign-in and Outlook calendar for Skills Academy volunteersLocationMicrosoft cloudTransferMicrosoft DPA (22 May 2026)

FundraiseUp

PurposeDonation checkoutLocationUnited StatesTransferFundraiseUp DPA, standard contractual clauses

OpenAI Whisper

PurposeTranscription of uploaded voice and interview recordings (CSR Cockpit)LocationUnited StatesTransferOpenAI DPA, standard contractual clauses; no training on API data

Coursera

PurposeEnrolment receipts for Mentorship-hosted Coursera accessLocationUnited StatesTransferCoursera DPA; Data Privacy Framework, standard contractual clauses
For your AI policy
EU and United Statesa person decides where a decision is made

AI use and human review

TEEI uses AI for application review, chat safeguarding, live captions, translation, report drafting and transcription. Each use, its provider and where it runs is listed here.

Volunteer application review

Amazon Bedrock · EU

volunteer applicationsAmazon Bedrock, EUstructured first assessmenta person reviews and approves

TEEI Language and Mentorship use Amazon Bedrock to produce a structured first assessment of volunteer applications. A person reviews the assessment and makes the approval decision.

Learner admissions follow programme eligibility rules.

Group-chat safeguarding

Amazon Bedrock · EU

group-chat messagesAmazon Bedrock, EUsafeguarding flaga person reviews flagged messages

Messages in programme group chats are screened for safeguarding concerns. Flagged messages go to a person; nothing is removed or acted on by the model alone.

Live captions

Amazon Transcribe · EU

spoken audio in a sessionAmazon Transcribe, EUcaptions on screen

Shared video sessions can show live captions. The transcript is produced in the EU and shown to the participants in the session.

Chat translation

DeepL · Germany

WBP chat messageDeepL, Germanytranslated message

WBP translates buddy and participant chat messages with DeepL. Google Gemini is the fallback when DeepL does not answer.

Report drafting

Google Gemini · United States

recorded programme dataGoogle Gemini, United Statesimpact reports and case studiesdedicated review and approval step

CSR Cockpit uses Google Gemini to draft impact reports and case studies from recorded programme data. The reporting workflow includes a dedicated review and approval step.

Audio transcription

OpenAI Whisper · United States

uploaded voice and interview recordingsOpenAI Whisper, United Statestranscript

CSR Cockpit uses OpenAI Whisper to transcribe uploaded voice and interview recordings.

For your questionnaire
Public or on requestfor legal, data protection and security teams

Documentation for your review

Access our published privacy information or request documentation for your legal, data protection and security teams.

Security and operational policy summariesOn request
Data Processing AgreementOn request
Sub-processor registerView the register

For vendor questionnaires and document requests, contact partnerships@theeducationalequalityinstitute.org.

Request documentation
Who to ask

Contacts

Security
Report a security issue to security@theeducationalequalityinstitute.org. Our published security.txt provides the security contact details.
  • Scope

    theeducationalequalityinstitute.org and its subdomains, including language., mentorship. and cockpit.

  • We ask

    Test only with accounts you own. Do not access, change or keep other people’s data. No denial of service and no social engineering.

  • We do

    We confirm receipt by email, keep you informed while we fix the issue, and take no legal action against research that stays within this scope and these rules.

  • Report

    Send the affected URL, the steps to reproduce and any proof to the address above.

Partnership reviews
Contact partnerships@theeducationalequalityinstitute.org for contracts, data processing documentation and questionnaires.
Personal data requests
Use our data request form to contact TEEI about your personal data.

Submit a data request

security.txt · RFC 9116 · valid until 2027-05-09 · policy: /trust/#vulnerability-disclosure

Who you contract with

Norway

The Educational Equality Institute

Organisation number 928 776 719

Registered, checked on this visit

United States

The Educational Equality Institute Inc.

501(c)(3) public charity · EIN 33-2331817

In the IRS Business Master File, checked on this visit

View registration records