Service Provider Transparency
Subprocessors and Service Providers
Categories of third parties that may process limited personal information to support Camblish website, LMS and Xcelerate services.
1. What this page means
A subprocessor or service provider supplies infrastructure or a technical function that may involve processing personal information for Camblish or an authorised programme party. Camblish remains responsible for selecting providers appropriately and configuring Xcelerate access and data flows.
Moodle and Xcelerate are core platform technologies operated within the Camblish service environment. Other providers may support hosting, communications, push delivery, maps, storage, security or optional calling.
2. Current and conditional provider categories
| Provider or category | Purpose | Information involved | When used |
|---|---|---|---|
| Camblish contracted web, database and server hosting providers | Host the public website, Camblish LMS, Xcelerate application, databases, files, backups and security services. | Account, programme, attendance, messages, support, files, device and server-log information stored in the relevant environment. | Core service. Access is restricted to authorised administration and support. |
| Moodle and Xcelerate platform components | Learning delivery, assignments, assessment, progress, attendance, evidence, messaging, support, administration and reporting. | User identity, role, scope, course, attendance, communication, files and audit records. | Core service operated by or for Camblish. Moodle software suppliers do not automatically receive production data merely because their software is used. |
| Google Firebase Cloud Messaging | Deliver Android push notifications, including minimal incoming-call invitations where calling is enabled. | Push token, app instance or device routing data and a minimal notification payload. Passwords, Moodle tokens and permanent TURN secrets are not included. | Only after Firebase is securely configured and the app device registers for notifications. |
| Email and SMS delivery providers | Send account, support, training, attendance, security or verification communications. | Name or account reference, email address or phone number, message content and delivery status. | Only where the relevant communication channel is configured and authorised. |
| Secure file, backup and recovery providers | Protect evidence, documents, assignments, registers, support uploads and system continuity. | Encrypted or access-controlled copies of relevant platform files and records. | Where contracted for hosting, backup, disaster recovery or archive duties. |
| Maps, geocoding or location infrastructure | Display sites or zones and support authorised attendance or geofence functions. | Site or zone coordinates and, where required, a device location request. | Only where a location-enabled function uses the provider. Location is not supplied for advertising. |
| WebRTC signalling and TURN relay infrastructure | Establish secure one-to-one app voice calls and relay encrypted media where direct connectivity fails. | Temporary call UUID, participant authorisation, signalling messages, temporary ICE credentials, network addresses and transient encrypted audio packets. Audio is not intentionally recorded. | Only when Xcelerate calling is enabled after security and two-device certification. |
| Security, monitoring and technical support providers | Protect systems, detect abuse, troubleshoot faults and respond to incidents. | Limited account, device, IP, event, diagnostic and audit information relevant to the incident. | As needed under restricted access and confidentiality controls. |
| Professional advisers, auditors and authorised compliance bodies | Legal, accounting, accreditation, SETA, QCTO, funding, audit or regulatory work. | Only the records required for the authorised review or legal obligation. | Where contract, programme rules or law require or permit disclosure. |
3. Provider safeguards
Depending on the provider and risk, Camblish applies measures such as:
- Due diligence and written data-protection, confidentiality or service terms.
- Minimum-necessary data sharing and purpose restrictions.
- HTTPS or other encryption in transit and protected credentials.
- Role-based access, account separation, audit records and administrator controls.
- Short-lived push, signalling and TURN credentials where applicable.
- Retention, deletion, incident-response, backup and business-continuity requirements.
- Cross-border transfer safeguards where information is processed outside South Africa.
4. Changes to providers
Camblish may add, replace or remove providers as services change. This page will be updated when a material provider category or data-processing purpose changes. Programme contracts may identify additional named providers relevant only to that programme.
Users may contact Camblish to ask whether a particular provider category applies to their account or programme.
5. Questions and privacy requests
51 Harrison Street, Johannesburg, 2001
[email protected]
011 024 9246 or 061 035 8120
Published by Camblish Training Institute. Effective 29 July 2026. Version 1.0.