Sub-processors
Last updated: July 1, 2026
Draft for review
This document is provided for transparency and is under review by legal counsel. It is not legal advice. For questions, contact our Privacy Officer at privacy@embaylms.com.
EmbayLMS is a multi-tenant SaaS platform. For personal information in a customer’s workspace, the customer (tenant) is the controller and Embay is the processor. We engage the sub-processors below to help deliver the service. Core learning records and the user directory stay at rest in Canada; some limited or transient processing occurs abroad under data processing agreements, encryption in transit, and data minimization.
Current sub-processors
| Processor | Purpose | Data | Location | Safeguards |
|---|---|---|---|---|
| AWS | Storage (S3), email (SES), KMS key management, malware scanning | Uploaded files, exports, encrypted content | ca-central-1 (Canada) | DPA, SOC 2, KMS encryption |
| Supabase | Managed PostgreSQL (all tenant data) | Learning records, user directory, account data | Canadian region | DPA, SOC 2, encryption |
| Vercel | Web hosting / CDN (request metadata, transient SSR) | Request metadata; no PII at rest | Global edge; compute primarily US | DPA, SOC 2, no PII at rest |
| Railway | Background worker + Redis (transient job payloads) | IDs, notification email addresses (transit-only, minimized) | US (no Canadian region) | DPA, TLS |
| Zoom | VILT meetings and recordings | Participant name/email, voice/video | US / global | DPA |
| Stripe | Payments and platform billing | Billing contact; payment method held by Stripe only | US / global | PCI DSS Level 1, DPA (card data never touches EmbayLMS servers) |
| HubSpot | CRM (one-way mirror of deal / MRR) | Business-contact data only; no cardholder data | US | DPA |
| Google / Microsoft | SSO identity providers when a tenant configures them | SSO subject ID, email, name | Per the tenant’s own IdP | Tenant-controlled, standard OIDC/SAML |
Governance
Our Privacy Officer maintains this list. When we add or replace a sub-processor, we notify affected tenants in accordance with the Data Processing Addendum, and we review the full list at least annually. Each sub-processor is bound by contractual data-protection obligations that flow down our commitments.
How to get notified
To be notified of changes to this list, contact privacy@embaylms.com. Enterprise customers receive notice through the mechanism set out in their Data Processing Addendum.
Effective date
This list is effective as of the “last updated” date shown above.
Privacy Officer
Mathieu Brillon, acting Privacy Officer, Embay Consulting Inc. — privacy@embaylms.com