Immigr8.net

Sub-Processors

Last updated: July 2026

Immigr8 engages the following third-party service providers (“sub-processors”) to support delivery of our platform. Each sub-processor is contractually bound to handle personal information consistent with the protections we describe in our Privacy Policy.

Districts receive at least 30 days’ notice before any new sub-processor is added that will handle personal information. To request notification of changes, email privacy@immigr8.net.

Active sub-processors

Vendor Purpose Data Handled Region Privacy / DPA
Render Application hosting + PostgreSQL database (production data at rest) All platform data — accounts, evaluations, audit logs United States (Oregon) Privacy · DPA
Cloudflare R2 Transcript file storage (uploaded PDFs and images) Transcript documents containing student PII United States (private bucket, fetched by internal binding — not CDN edge-cached) Privacy · DPA
Cloudflare (Containers) Optical character recognition — reading uploaded transcript images into text. Ephemeral processing; the image is processed in-memory and not retained. Transcript images containing the student PII printed on the document (no additional records or SIS data are transmitted) North America (Cloudflare ENAM/WNAM placement — never routed outside North America) Privacy · DPA
Anthropic (optional / off by default) Optional AI evaluation provider. Immigr8’s primary evaluator is now an in-house engine (no external LLM); the Anthropic provider is off by default and, when used, operates under zero-retention (see note below). Transcript content (text + image), country, AI-generated mappings — only when explicitly enabled United States Privacy · DPA
Stripe Payment processing for district subscriptions and credit purchases Billing email, district name, last-4 of card (Stripe-hosted Checkout — Immigr8 servers never see full card data) United States Privacy · DPA
SendGrid (Twilio) Transactional email — verification, password reset, evaluation status notifications Educator email addresses, names, message content United States Privacy · DPA
Google (OAuth + Workspace) Google Sign-In for educators with Google Workspace accounts; Google Workspace email for Immigr8 staff Authentication tokens, email + name on sign-in United States (Google Workspace tenant: immigr8.net) Privacy · DPA
Microsoft (Azure AD OAuth) Microsoft Sign-In for educators with Microsoft 365 accounts Authentication tokens, email + name on sign-in United States (default tenant) Privacy · DPA
Anthropic zero-retention: Immigr8 has requested a zero-data-retention configuration on its Anthropic API workspace (written confirmation pending). Until confirmed in writing, Anthropic’s standard API retention applies to that traffic — which is one reason the Anthropic provider is off by default: Immigr8’s primary evaluator is an in-house engine and no transcript content is sent to any external LLM in the default path.

Per-district SAML Identity Providers (variable)

Districts that enable SAML SSO designate their own Identity Provider (Okta, Azure AD, Google Workspace SAML, ADFS, etc.). The IdP is not an Immigr8 sub-processor — it is the district’s own infrastructure. Immigr8 stores only the per-district IdP metadata (entry point URL, signing certificate) needed to validate SAML responses.

Future / on request

The following sub-processors are not currently active but may be added with 30 days’ notice:

Contact

For sub-processor questions, DPA requests, or to subscribe to change notifications, email privacy@immigr8.net.