National Chengchi University
Uedu Main Site
Explore Uedu
Student Console
Register as Member/Login
Research Informed Consent Center
Survey Center
Teacher Console
Course Setup
Support & Messages
Uptime Data

UeduGPTs

--

Jupyters

6

Local AI

--

Uedu Code

--

CISOSE26 Local AI Uedu Code UG26
政治大學 AQI 56 26°C PM2.5 11
AI Reply Desktop Notifications

Show a desktop notification when the AI TA finishes replying

Chat Message Notifications

Notify me when classmates post messages in the forum

Sound notification

Play an alert sound whenever there is a new notification

Operations · Sub-processor List

次處理者清單

This document discloses the external vendors (Sub-processors) engaged by the Uedu platform, including those responsible for infrastructure, inference services, authentication, email, DNS / CDN and other specific technical functions, as well as their geographic region and compliance certifications.

Document Versionv1.0
Effective Date2026-04-10
Last Updated2026-05-11
Published Online2026-05-11
Legal Review StatusSelf-authored; partner-side review invited
LanguageTraditional Chinese (legal baseline version)

1. Disclosure principle

The disclosure scope of this list is: (i) personal data processed or capable of being processed on this platform; (ii) necessary for platform operation; or (iii) not directly processing personal data but, under the strict practice of an EU DPO, could be regarded as a sub-processor. To ensure transparency for cooperation with Europe, disclosures in this list for LLM and CDN are named disclosures rather than generic descriptions.

This list will be updated within 30 days when major changes occur (addition or replacement of key vendors, changes to region, termination of cooperation); the change record is disclosed in the version history section of the document. Registered users will be notified by email of changes that result in a jump in the main version number.

2. Infrastructure and storage

roleSupplierRegionPurpose of processing / processed data / DPA
Server room National Central University Computer Room Zhongli District, Taoyuan City (Taiwan) Primary application server (uedu.tw, 140.115.103.70); Ubuntu 24.04.3 LTS
Local storage Local SSD (2TB NVMe) Same as above MySQL database, uploaded files, application logs; no third-party vendors
NAS Educational Omics Lab NAS(borglab) Same as above Screen recording mp4 / large file uploads; not open to the public

3. LLM inference service

The platform uses a flexible LLM routing strategy: the default provider is OpenAI, and depending on the data residency requirements of the research partner, it may be switched to the European region of Microsoft Azure OpenAI Service. This strategy has been disclosed in section 6 of the 'Privacy and Data Retention Policy'; this section discloses the specific provider and the relevant DPA.

roleSupplierRegionPurpose of processing / DPA
Default LLM Provider OpenAI, L.L.C. United States (US) Inference services (generative LLM, whisper speech-to-text, image generation). OpenAI Data Processing Addendum.
Optional EU Provider Microsoft Azure OpenAI Service Switzerland North / West Europe Inference service for European collaboration. Microsoft Online Services DPA + EU Data Boundary commitment.
Optional EU-native Provider (planned) To be selected (candidates include Apertus, Mistral) Switzerland / EU Enabled as needed; per-vendor DPA.

3.1 OpenAI Zero Data Retention

Original wording — OpenAI ZDR Uedu has Zero Data Retention enabled with OpenAI. Inputs and outputs to OpenAI's API are not retained by OpenAI for any period beyond the immediate processing of each request.

Zero Data Retention (ZDR) has been enabled for Uedu's API to OpenAI. Inputs to and outputs from the OpenAI API are not retained after real-time processing; OpenAI does not use them for model training or any other secondary purpose.

3.2 LLM routing for collaboration with Europe

Original wording — EU routing For research collaborations involving European data subjects, inference may be routed through Microsoft Azure OpenAI Service deployed in the Switzerland North or West Europe region under Microsoft's EU Data Boundary commitment. The choice of region is made jointly with the partner institution to align with their data residency requirements.

For research collaboration involving data subjects in Europe, inference may be carried out via services deployed in the Switzerland North or West Europe region of Microsoft Azure OpenAI Service, processed in accordance with Microsoft's EU Data Boundary commitment. The choice of region is decided jointly with the collaborating institution to align with its data residency requirements.

4. Authentication / OAuth and wearable device integration

roleSupplierRegionPurpose of processing / processed data
OAuth ProviderGoogle LLCthe United StatesThird-party sign-in; receive user-authorised email and profile information
OAuth ProviderApple Inc.the United StatesSign in with Apple; receive the user-authorised email identifier
OAuth ProviderGitHub, Inc.the United StatesThird-party sign-in; receive the user-authorised public profile
Wearable device APIGarmin International, Inc.the United StatesRetrieve HRV, sleep, stress and other indicators from Garmin Connect API with the user's authorisation
Health integrationApple HealthKitClient-sideUse the Uedu mobile APP to read health data authorised by the user; data is retrieved on the user's device and then returned to the platform
Health integrationGoogle Health ConnectClient-sideSame as above

5. Email and communications

roleSupplierRegionPurpose of processing / DPA
Transactional email sending Mailgun(Sinch Email, Inc.) EU region System notifications, account verification, research collaboration communications. Mailgun DPA.

6. DNS / CDN / DDoS protection

roleSupplierRegionPurpose of processing / DPA
DNS / CDN / DDoS protection Cloudflare, Inc. United States (headquarters), global edge network See the explanation below
Original wording — Cloudflare Cloudflare, Inc. (US, with global edge network) provides DNS resolution, DDoS protection, and CDN services. User requests from European regions are primarily processed through Cloudflare's European edge nodes. A Data Processing Addendum is in place with Cloudflare under their standard DPA terms.

Cloudflare, Inc. (United States, global edge network) provides DNS resolution, DDoS protection and CDN services. Requests from users in Europe are primarily handled by Cloudflare's European edge nodes. This platform and Cloudflare have signed the Data Processing Addendum under its standard DPA terms.

7. Front-end asset delivery

All front-end JavaScript, CSS, font and other assets for this platform are self-hosted under the uedu.tw /static/vendor/ path. No use is made of public CDNs such as jsdelivr, cdnjs, unpkg, Google Fonts or the Tailwind Play CDN for asset delivery, and there are no related subprocessors.

7.1 Exception: Pyodide WebAssembly Runtime

roleSupplierRegionPurpose of Processing
Pyodide WASM runtime jsDelivr (Pyodide official CDN) Global edge network Python WebAssembly execution environment and package downloads for opt-in programme execution

The platform's opt-in code execution function (the runtime is located on the user's browser side and starts when triggered by the execute_code tool in ClassroomGPT and AIDA) uses the Pyodide WebAssembly Runtime. When the user actively triggers code execution, Pyodide dynamically downloads the runtime and the required Python packages from cdn.jsdelivr.net/pyodide/v0.27.5/full/. This subprocess is enabled only when actively triggered by the user; no personal data are transmitted, and only package file paths are requested.

8. Integration of secure devices for account two-factor authentication

The platform's two-factor authentication (2FA) uses the TOTP standard (RFC 6238). Users generate time-based codes through an authenticator app of their choice (such as Google Authenticator, Authy or 1Password). The platform does not transmit user-identifying information to the providers of those apps; the TOTP shared secret is stored only in the platform's database and in the user's authenticator app.

9. Change management

  • Change records for this list are retained in the version history section of this document
  • New, replacement, or region changes of major suppliers shall be announced on the Framework's homepage 30 days in advance
  • Major changes will be notified to registered users by email
  • Each vendor's DPA and sub-processor list (including any further sub-sub-processors) are governed by its official notices; this platform does not maintain them separately.

10. Items not included in this list

To maximise the readability of this list for users and partners, the following relationships are excluded from this list:

  • The user’s own device manufacturer, operating system vendor, and browser vendor (outside the platform’s control)
  • LMS or administrative systems of partner schools (clearly separated from this platform's data boundary)
  • Upstream sub-sub-processors of each sub-processor (in accordance with each sub-processor's own DPA and public notices)

11. Contact point

Privacy Contact[email protected]
Objection to changes made by the sub-processor[email protected] (please include [SUB-PROCESSOR OBJECTION] in the subject line)

This list corresponds to §6 (cross-border transfers) of the "Privacy and Data Retention Policy"; it is recommended that you read them together to understand the full picture of data flows.