Subprocessors

Last updated 2026-06-08

View raw markdown

At a glance

  • Who uses it: District IT and DPO reviewers maintaining their subprocessor inventory.
  • Purpose: Current list of subprocessors AmplifyED uses to deliver the service.

How we use subprocessors

A subprocessor is any third party that processes customer data on our behalf. We use subprocessors to host infrastructure, send transactional email, process payments, and deliver optional AI features. Each subprocessor is contracted under a data processing agreement that limits use of customer data to providing the contracted service.

Current subprocessors

VendorPurposeData processedLocation
Supabase (managed Postgres)Primary database & authAll customer dataUS
CloudflareCDN, edge compute, DDoS protectionTLS-terminated trafficGlobal edge; US origin
Resend (or equivalent)Transactional email deliveryRecipient address + email contentUS
StripePayment processing for subscriptionsBilling email, payer name, card metadata (no card numbers handled by AmplifyED)US
Lovable AI Gateway → Google GeminiOptional AI drafts and summariesCase text submitted to AI featuresUS

A signed copy of the current subprocessor list is available under NDA via security@amplifyed.app.

Changes

We announce subprocessor additions or replacements at least 30 days in advance by email to the billing contact on file. Existing customers may object before the change takes effect.

Related articles

FAQ

Can we restrict which subprocessors process our data? The infrastructure subprocessors (Supabase, Cloudflare, email, payments) are required to operate the service. The AI subprocessor is optional and can be disabled per organization.

Where can I find your current signed subprocessor list? Email security@amplifyed.app to request the current PDF under NDA.

Related