Skip to main content

CommonGage Subprocessor List

Last updated: 2026-09-06

CommonGage uses the following third-party subprocessors to deliver its service. All subprocessors are bound by data processing agreements consistent with CommonGage's obligations to districts.


Infrastructure

SubprocessorRoleData ProcessedLocation
Cloudflare, Inc.API hosting (Workers), static asset delivery (Pages), DDoS protection, rate limitingRequest/response traffic; Worker secrets at rest; inbound email (BCC-to-log for the Communications module, via Cloudflare Email Routing)Global edge (data processed in transit; no persistent storage in Workers)
Neon, Inc.Managed PostgreSQL databaseAll application data (staff accounts, events, deliverables, school/zone structure)AWS us-east-1 (United States)

On web fonts. Until 31 July 2026 the application, marketing, and documentation sites each loaded their fonts from Google's CDN, which meant a staff member's browser disclosed its IP address and User-Agent to Google on every page load. No customer data was involved — it was a browser-to-Google request, not a transfer by us — but it placed a third party in the page load of every site we run.

Those fonts are now self-hosted. All three sites serve their own font files and contact no third-party origin during normal page use. We record the change here rather than quietly deleting the row, because a subprocessor list that only ever grows is easier to trust than one that silently changes.

Google does still appear above, under Authentication, for a different and narrower reason: organizations that enable Google Workspace SSO authenticate through Google by their own choice. That is an inbound assertion of identity at sign-in, not a transfer of organizational data, and it applies only where an organization has asked for it.

Authentication

SubprocessorRoleData ProcessedLocation
ClassLink, Inc.Single sign-on (SSO) for district staffStaff name, email, ClassLink UserId, district TenantId at login timeUnited States
Google LLC (Google Workspace SSO)Single sign-on for organizations that authenticate with Google WorkspaceAt sign-in, Google asserts the staff member's name, email address, account identifier, and Workspace domain to CommonGage in a signed token. The flow is inbound only — CommonGage sends Google no organizational data, no event or programme data, and nothing about what the person does after signing in. Applies only to organizations that choose to enable it.United States

AI / Machine Learning

SubprocessorRoleData ProcessedLocation
Anthropic, PBCEvent classification against the Dual Capacity-Building Framework; ordering a Find question into a structured search; and, for organizations licensing Communications, media monitoring via Anthropic's server-side web search tool — all via model claude-haiku-4-5-20251001 over the Anthropic Messages APICommonGage sends event title, description, hub name, and engagement type to Anthropic for classification. No staff name, email address, site identifier, or participant data field is included in the prompt; because titles and descriptions are free text authored by the customer's own staff or drawn from the customer's calendar feeds, they may incidentally contain names or other identifying details the customer chose to write into an event's title or description. For Find, CommonGage sends the user's question as typed plus the names of the collections and fields their role and licensed modules reach; no database record is sent on that path, and the model returns a search to run rather than an answer, which is re-checked against the caller's permissions before it runs. For Communications media monitoring, CommonGage sends the organization's name, its location where supplied, and the watch topic an administrator typed; these are run as public web searches through Anthropic's search tool, so they reach that search infrastructure as well. No record from the organization's database is sent on that path either. Not retained by Anthropic for training under the API terms; each request is stateless.United States

Development & Operations

SubprocessorRoleData ProcessedLocation
GitHub, Inc. (Microsoft)Source code hostingSource code only; no customer dataUnited States

Data Not Shared with Subprocessors

  • Staff passwords (hashed locally; hash stored in Neon only)
  • JWT session tokens (generated and verified within Cloudflare Workers; not logged or forwarded)
  • Database credentials (stored as Cloudflare Worker secrets; not accessible to any third party)

Subprocessor Change Notification

CommonGage will notify districts of any material changes to this subprocessor list (additions of new subprocessors who will process district data) with at least 30 days' notice, providing districts with the opportunity to object. Removal of a subprocessor or changes that reduce data sharing do not require advance notice but will be reflected in an updated version of this document.


Applicable Agreements

SubprocessorRelevant Agreement
CloudflareCloudflare Data Processing Addendum
NeonNeon Data Processing Agreement
AnthropicAnthropic API Data Processing Agreement
ClassLinkClassLink Privacy Policy / Data Sharing Agreement