CommonGage Subprocessor List
Last updated: 2026-09-06
CommonGage uses the following third-party subprocessors to deliver its service. All subprocessors are bound by data processing agreements consistent with CommonGage's obligations to districts.
Infrastructure
| Subprocessor | Role | Data Processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | API hosting (Workers), static asset delivery (Pages), DDoS protection, rate limiting | Request/response traffic; Worker secrets at rest; inbound email (BCC-to-log for the Communications module, via Cloudflare Email Routing) | Global edge (data processed in transit; no persistent storage in Workers) |
| Neon, Inc. | Managed PostgreSQL database | All application data (staff accounts, events, deliverables, school/zone structure) | AWS us-east-1 (United States) |
On web fonts. Until 31 July 2026 the application, marketing, and documentation sites each loaded their fonts from Google's CDN, which meant a staff member's browser disclosed its IP address and User-Agent to Google on every page load. No customer data was involved — it was a browser-to-Google request, not a transfer by us — but it placed a third party in the page load of every site we run.
Those fonts are now self-hosted. All three sites serve their own font files and contact no third-party origin during normal page use. We record the change here rather than quietly deleting the row, because a subprocessor list that only ever grows is easier to trust than one that silently changes.
Google does still appear above, under Authentication, for a different and narrower reason: organizations that enable Google Workspace SSO authenticate through Google by their own choice. That is an inbound assertion of identity at sign-in, not a transfer of organizational data, and it applies only where an organization has asked for it.
Authentication
| Subprocessor | Role | Data Processed | Location |
|---|---|---|---|
| ClassLink, Inc. | Single sign-on (SSO) for district staff | Staff name, email, ClassLink UserId, district TenantId at login time | United States |
| Google LLC (Google Workspace SSO) | Single sign-on for organizations that authenticate with Google Workspace | At sign-in, Google asserts the staff member's name, email address, account identifier, and Workspace domain to CommonGage in a signed token. The flow is inbound only — CommonGage sends Google no organizational data, no event or programme data, and nothing about what the person does after signing in. Applies only to organizations that choose to enable it. | United States |
AI / Machine Learning
| Subprocessor | Role | Data Processed | Location |
|---|---|---|---|
| Anthropic, PBC | Event classification against the Dual Capacity-Building Framework; ordering a Find question into a structured search; and, for organizations licensing Communications, media monitoring via Anthropic's server-side web search tool — all via model claude-haiku-4-5-20251001 over the Anthropic Messages API | CommonGage sends event title, description, hub name, and engagement type to Anthropic for classification. No staff name, email address, site identifier, or participant data field is included in the prompt; because titles and descriptions are free text authored by the customer's own staff or drawn from the customer's calendar feeds, they may incidentally contain names or other identifying details the customer chose to write into an event's title or description. For Find, CommonGage sends the user's question as typed plus the names of the collections and fields their role and licensed modules reach; no database record is sent on that path, and the model returns a search to run rather than an answer, which is re-checked against the caller's permissions before it runs. For Communications media monitoring, CommonGage sends the organization's name, its location where supplied, and the watch topic an administrator typed; these are run as public web searches through Anthropic's search tool, so they reach that search infrastructure as well. No record from the organization's database is sent on that path either. Not retained by Anthropic for training under the API terms; each request is stateless. | United States |
Development & Operations
| Subprocessor | Role | Data Processed | Location |
|---|---|---|---|
| GitHub, Inc. (Microsoft) | Source code hosting | Source code only; no customer data | United States |
Data Not Shared with Subprocessors
- Staff passwords (hashed locally; hash stored in Neon only)
- JWT session tokens (generated and verified within Cloudflare Workers; not logged or forwarded)
- Database credentials (stored as Cloudflare Worker secrets; not accessible to any third party)
Subprocessor Change Notification
CommonGage will notify districts of any material changes to this subprocessor list (additions of new subprocessors who will process district data) with at least 30 days' notice, providing districts with the opportunity to object. Removal of a subprocessor or changes that reduce data sharing do not require advance notice but will be reflected in an updated version of this document.
Applicable Agreements
| Subprocessor | Relevant Agreement |
|---|---|
| Cloudflare | Cloudflare Data Processing Addendum |
| Neon | Neon Data Processing Agreement |
| Anthropic | Anthropic API Data Processing Agreement |
| ClassLink | ClassLink Privacy Policy / Data Sharing Agreement |