Sub-processors
Last updated: July 1, 2026
EmbayLMS is a multi-tenant SaaS platform. For personal information in a customer’s workspace, the customer (tenant) is the controller and Embay is the processor. We engage the sub-processors below to help deliver the service. Core learning records and the user directory stay at rest in Canada; some limited or transient processing occurs abroad under data processing agreements, encryption in transit, and data minimization.
Current sub-processors
| Processor | Purpose | Data | Location | Safeguards |
|---|---|---|---|---|
| AWS | Storage (S3), KMS key management, content delivery (CloudFront) | Uploaded files, exports, encrypted content | ca-central-1 (Canada) | DPA, vendor SOC 2, KMS encryption |
| Resend | Transactional email delivery (sign-in, password reset, notifications, reminders) | Recipient email address; recipient first name in some templates. No learning records, course content, assessment responses or certificates. | US (us-east-1), no Canadian region available | DPA, TLS in transit, DKIM/SPF authenticated |
| Supabase | Managed PostgreSQL (all tenant data) | Learning records, user directory, account data | Canadian region | DPA, vendor SOC 2, encryption |
| Vercel | Web hosting / CDN (request metadata, transient SSR) | Request metadata; no PII at rest | Global edge; serverless functions pinned to yul1 (Montréal, Canada) | DPA, vendor SOC 2, no PII at rest |
| Railway | Background worker + Redis (transient job payloads) | IDs, notification email addresses (transit-only, minimized) | US West (California, us-west2); no Canadian region available | DPA, TLS |
| Zoom | VILT meetings and recordings | Participant name/email, voice/video | US / global | DPA |
| Stripe | Payments and platform billing | Billing contact; payment method held by Stripe only | US / global | PCI DSS Level 1, DPA (card data never touches EmbayLMS servers, PCI DSS SAQ A / A-EP, QSA determination pending) |
| HubSpot | CRM (one-way mirror of deal / MRR); marketing-site visitor analytics on embaylms.com, only with consent | Business-contact data only; no cardholder data. For consenting website visitors: page views, campaign source, and visitor token | US | DPA |
| Google (Analytics) | Aggregate marketing-site traffic analytics on embaylms.com, only with consent. Not used in the LMS application | Page views, approximate location, device/browser, referring campaign. IP anonymized; Google Signals and ad personalization disabled | US / global | DPA (Google Ads Data Processing Terms), consent-gated, no advertising use |
| Google / Microsoft | SSO identity providers when a tenant configures them | SSO subject ID, email, name | Per the tenant’s own IdP | Tenant-controlled, standard OIDC/SAML |
Governance
Our Privacy Officer maintains this list. When we add or replace a sub-processor, we notify affected tenants in accordance with the Data Processing Addendum, and we review the full list at least annually. Each sub-processor is bound by contractual data-protection obligations that flow down our commitments.
How to get notified
To be notified of changes to this list, contact privacy@embaylms.com. Enterprise customers receive notice through the mechanism set out in their Data Processing Addendum.
Effective date
This list is effective as of the “last updated” date shown above.
Privacy Officer
Mathieu Brillon, acting Privacy Officer, Embay Consulting Inc., privacy@embaylms.com