Sub-processors
The complete list of third parties that may process data held in Pallara. Several are optional and only apply if your institution turns the feature on.
Last updated 7 September 2026
We give at least 30 days' notice before adding or replacing a sub-processor that processes personal information, and you may object on data protection grounds. See clause 6 of the data processing terms. To be notified, email [email protected] and ask to be added to the list.
Core infrastructure — always in use
| Provider | Purpose | Data | Location |
|---|---|---|---|
| DigitalOcean | The primary PostgreSQL database | All tenant data | Sydney, Australia |
| Application servers | The staff and student portals and all application logic | All tenant data in transit and in memory | Sydney, Australia (DigitalOcean) |
| Cloudflare | DNS, CDN, TLS termination, DDoS protection, and R2 object storage for uploaded files | All traffic; uploaded documents and media | Global edge; R2 storage region as configured |
| Postmark (Wildbit / ActiveCampaign) | Transactional email delivery and inbound email ingestion | Recipient name and email address, message content | United States |
AI providers — where AI features are enabled
Requests are routed to the model provider configured for the feature. Inputs may include questions, course content, attachments or selected records, including personal information. Redaction is applied in supported workflows. Our data processing terms prohibit our sub-processors from using your personal information for model training; institutions connecting their own providers should review their terms and settings. See the AI section of the privacy policy.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| OpenRouter | Primary model routing | Feature inputs and selected records | United States |
| Anthropic | Language models | Feature inputs and selected records | United States |
| OpenAI | Language and embedding models | Feature inputs and selected records; course content for search indexing | United States |
| Language models | Feature inputs and selected records | United States |
Optional — only if your institution enables the feature
| Provider | Enabled by | Purpose | Location |
|---|---|---|---|
| Stripe | Online payments | Card payment processing. Card details go directly to Stripe and are never held by Pallara. | United States and Australia |
| Twilio | Two-way SMS module | Sending and receiving text messages | United States |
| Expo | Mobile app push notifications | Device push tokens and notification content | United States |
| Upstash | Distributed rate limiting | Request counters keyed by tenant and user identifier. No record content. | As configured |
| Google Maps Platform | Address finder module | Partial address strings typed into an address field | United States |
| Gamma | AI presentation generation | Generated study material content | United States |
| Xero | Accounting integration | Invoice, payment and contact records, at your instruction | Australia and New Zealand |
| Microsoft | Dynamics 365 Business Central integration, Microsoft 365 sign-in | Finance records or authentication identity, at your instruction | As configured by your tenant |
| Google Workspace | Calendar sync, Google sign-in | Calendar events or authentication identity, at your instruction | United States |
Government agencies are not sub-processors
TEC, NZQA, the Ministry of Education and StudyLink receive data because your institution is legally required to report it. They are separate agencies acting under their own statutory authority, not our sub-processors, and we transmit to them only on your institution's instruction.
Other data-handling information
- Error monitoring is self-hosted. We run our own GlitchTip instance rather than sending diagnostics to a third-party vendor.
- No analytics or advertising vendors. The platform carries no third-party analytics, no advertising pixels and no cross-site trackers.
- No data broker or enrichment service is used at any point.