Subprocessors
Last updated 2026-06-08
At a glance
- Who uses it: District IT and DPO reviewers maintaining their subprocessor inventory.
- Purpose: Current list of subprocessors AmplifyED uses to deliver the service.
How we use subprocessors
A subprocessor is any third party that processes customer data on our behalf. We use subprocessors to host infrastructure, send transactional email, process payments, and deliver optional AI features. Each subprocessor is contracted under a data processing agreement that limits use of customer data to providing the contracted service.
Current subprocessors
| Vendor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase (managed Postgres) | Primary database & auth | All customer data | US |
| Cloudflare | CDN, edge compute, DDoS protection | TLS-terminated traffic | Global edge; US origin |
| Resend (or equivalent) | Transactional email delivery | Recipient address + email content | US |
| Stripe | Payment processing for subscriptions | Billing email, payer name, card metadata (no card numbers handled by AmplifyED) | US |
| Lovable AI Gateway → Google Gemini | Optional AI drafts and summaries | Case text submitted to AI features | US |
A signed copy of the current subprocessor list is available under NDA via security@amplifyed.app.
Changes
We announce subprocessor additions or replacements at least 30 days in advance by email to the billing contact on file. Existing customers may object before the change takes effect.
Related articles
FAQ
Can we restrict which subprocessors process our data? The infrastructure subprocessors (Supabase, Cloudflare, email, payments) are required to operate the service. The AI subprocessor is optional and can be disabled per organization.
Where can I find your current signed subprocessor list? Email security@amplifyed.app to request the current PDF under NDA.
Related
Security overview
Who uses it: District IT and security reviewers. Purpose: One page summary of AmplifyED's security posture for procurement. US based managed cloud hosting. Single tenant database…
FERPA overview (procurement)
Who uses it: District IT, legal, and DPO reviewers vetting AmplifyED. Purpose: Procurement ready summary of how AmplifyED supports FERPA obligations. AmplifyED is a FERPA…
AI & student data
Who uses it: District IT, legal, and DPO reviewers evaluating AmplifyED's AI features for student data exposure. Purpose: Plain language procurement summary of how AI handles…
