TierSphere
Subprocessors and Access Controls
This page summarizes the third-party services TierSphere may use and the internal access rules applied to protected customer data.
Access Rules
- Access to customer data is limited to personnel with a documented business need.
- Access is granted according to least-privilege principles and role-based responsibilities.
- Subprocessors may receive only the data required for the specific service they provide.
- Subprocessors are expected to operate under written confidentiality, privacy, and security obligations.
- Public sharing features must use tokenized links, expiration, revocation support, and PII sanitization.
Current Subprocessors and Service Providers
| Provider | Purpose | Typical Data Involved |
|---|---|---|
| Amazon Web Services | Application hosting, database, object storage, background processing infrastructure | Application records, files, logs, backups |
| Stripe | Payments, subscriptions, checkout workflows, webhooks | Billing and transaction metadata |
| Mailgun | Transactional email delivery | Email addresses, message metadata |
| Google Analytics | Website analytics | Device and usage metadata |
| Google reCAPTCHA | Bot protection on public forms | Device, browser, IP, and anti-abuse signals |
| Google Maps | Map rendering and geocoding-related functionality | Organization or event location data |
| Sentry | Error monitoring and tracing | Error details and operational telemetry |
| Zendesk | Support widget and support workflows where enabled | Support contact details and ticket metadata |
| Dropbox Sign | Electronic signature workflows where enabled | Signer contact details and agreement metadata |
Review Expectations
- Review this list before executing a new district agreement.
- Confirm which integrations are enabled for the specific customer environment.
- Update this page whenever a new subprocessor is added or an existing provider is removed.
Related Policies
For more information, review our Student Data Privacy and Privacy Policy.