Skip to content

Legal & policies

Sub-processors

The complete list of third parties that may process data held in Pallara. Several are optional and only apply if your institution turns the feature on.

Last updated 7 September 2026

We give at least 30 days' notice before adding or replacing a sub-processor that processes personal information, and you may object on data protection grounds. See clause 6 of the data processing terms. To be notified, email [email protected] and ask to be added to the list.

Core infrastructure — always in use

ProviderPurposeDataLocation
DigitalOceanThe primary PostgreSQL databaseAll tenant dataSydney, Australia
Application serversThe staff and student portals and all application logicAll tenant data in transit and in memorySydney, Australia (DigitalOcean)
CloudflareDNS, CDN, TLS termination, DDoS protection, and R2 object storage for uploaded filesAll traffic; uploaded documents and mediaGlobal edge; R2 storage region as configured
Postmark (Wildbit / ActiveCampaign)Transactional email delivery and inbound email ingestionRecipient name and email address, message contentUnited States

AI providers — where AI features are enabled

Requests are routed to the model provider configured for the feature. Inputs may include questions, course content, attachments or selected records, including personal information. Redaction is applied in supported workflows. Our data processing terms prohibit our sub-processors from using your personal information for model training; institutions connecting their own providers should review their terms and settings. See the AI section of the privacy policy.

ProviderPurposeDataLocation
OpenRouterPrimary model routingFeature inputs and selected recordsUnited States
AnthropicLanguage modelsFeature inputs and selected recordsUnited States
OpenAILanguage and embedding modelsFeature inputs and selected records; course content for search indexingUnited States
GoogleLanguage modelsFeature inputs and selected recordsUnited States

Optional — only if your institution enables the feature

ProviderEnabled byPurposeLocation
StripeOnline paymentsCard payment processing. Card details go directly to Stripe and are never held by Pallara.United States and Australia
TwilioTwo-way SMS moduleSending and receiving text messagesUnited States
ExpoMobile app push notificationsDevice push tokens and notification contentUnited States
UpstashDistributed rate limitingRequest counters keyed by tenant and user identifier. No record content.As configured
Google Maps PlatformAddress finder modulePartial address strings typed into an address fieldUnited States
GammaAI presentation generationGenerated study material contentUnited States
XeroAccounting integrationInvoice, payment and contact records, at your instructionAustralia and New Zealand
MicrosoftDynamics 365 Business Central integration, Microsoft 365 sign-inFinance records or authentication identity, at your instructionAs configured by your tenant
Google WorkspaceCalendar sync, Google sign-inCalendar events or authentication identity, at your instructionUnited States

Government agencies are not sub-processors

TEC, NZQA, the Ministry of Education and StudyLink receive data because your institution is legally required to report it. They are separate agencies acting under their own statutory authority, not our sub-processors, and we transmit to them only on your institution's instruction.

Other data-handling information

  • Error monitoring is self-hosted. We run our own GlitchTip instance rather than sending diagnostics to a third-party vendor.
  • No analytics or advertising vendors. The platform carries no third-party analytics, no advertising pixels and no cross-site trackers.
  • No data broker or enrichment service is used at any point.