Skip to main content

TierSphere

Subprocessors and Access Controls

This page summarizes the third-party services TierSphere may use and the internal access rules applied to protected customer data.

Access Rules

  • Access to customer data is limited to personnel with a documented business need.
  • Access is granted according to least-privilege principles and role-based responsibilities.
  • Subprocessors may receive only the data required for the specific service they provide.
  • Subprocessors are expected to operate under written confidentiality, privacy, and security obligations.
  • Public sharing features must use tokenized links, expiration, revocation support, and PII sanitization.

Current Subprocessors and Service Providers

Provider Purpose Typical Data Involved
Amazon Web Services Application hosting, database, object storage, background processing infrastructure Application records, files, logs, backups
Stripe Payments, subscriptions, checkout workflows, webhooks Billing and transaction metadata
Mailgun Transactional email delivery Email addresses, message metadata
Google Analytics Website analytics Device and usage metadata
Google reCAPTCHA Bot protection on public forms Device, browser, IP, and anti-abuse signals
Google Maps Map rendering and geocoding-related functionality Organization or event location data
Sentry Error monitoring and tracing Error details and operational telemetry
Zendesk Support widget and support workflows where enabled Support contact details and ticket metadata
Dropbox Sign Electronic signature workflows where enabled Signer contact details and agreement metadata

Review Expectations

  • Review this list before executing a new district agreement.
  • Confirm which integrations are enabled for the specific customer environment.
  • Update this page whenever a new subprocessor is added or an existing provider is removed.

Related Policies

For more information, review our Student Data Privacy and Privacy Policy.