How this list works
A subprocessor is a company CampusLayer engages to process customer data on its behalf. Each subprocessor below is bound by a written data processing agreement. Under the Data Processing Addendum, CampusLayer gives institutions at least 30 days’ notice before adding or replacing a subprocessor that processes student data, and remains responsible for each subprocessor’s performance.
Supabase
- Entity: Supabase, Inc.
- Purpose: Database, authentication, and file storage for the CampusLayer application.
- Data processed: All Institution Data that CampusLayer stores: accounts, people, roles, memberships, invitations, encrypted connection credentials, Assistant conversations and files, the encrypted placeholder vault, usage records, and audit logs.
- Location: United States (Amazon Web Services, us-east-1). Supabase runs on Amazon Web Services.
- Terms: Supabase DPA · Supabase subprocessors
Vercel
- Entity: Vercel Inc.
- Purpose: Hosting and running the CampusLayer websites and application (Vercel Pro).
- Data processed: Requests passing through the application while they are processed, and runtime logs. CampusLayer writes error codes, not personal information or school data, to its logs.
- Location: Application functions run in the United States (Washington, D.C., iad1). Static content is served from Vercel's global network.
- Terms: Vercel DPA · Vercel subprocessors
OpenAI
- Entity: OpenAI OpCo, LLC
- Purpose: AI model inference for CampusLayer Assistant, through the OpenAI API.
- Data processed: What a staff member types into Assistant, files they attach, and results from connected systems after the Institution's data policy has been applied. Student identifiers, addresses, guardian contacts, and credentials are never sent; names and email addresses are replaced with placeholders.
- Location: United States.
- Terms: OpenAI Data Processing Addendum · OpenAI API data controls
Requests are sent with response storage turned off, and OpenAI does not use API data to train its models. Zero data retention is not yet in place, so OpenAI may keep requests for up to 30 days for abuse monitoring. CampusLayer is working with OpenAI to put zero data retention in place and will update this page when it is in effect.
Resend
- Entity: Resend, Inc.
- Purpose: Sending account emails, such as invitations and sign-in links.
- Data processed: The recipient's name, email address, organization name, and role, and the content of the account email. Never school records or Assistant content.
- Location: United States.
- Terms: Resend DPA · Resend subprocessors
Systems you connect (not subprocessors)
When an institution or its staff connect Microsoft 365, Canvas, or another school system to CampusLayer, CampusLayer reads from that system on the user’s behalf, with that user’s own permissions, when a request needs it. These providers are not CampusLayer subprocessors. They already hold the institution’s data under the institution’s own agreements, and those agreements govern it.
CampusLayer does not sync or mirror these systems. What Assistant receives from them during a conversation, after the privacy screen and the institution’s data policy, is saved with that conversation so it can be shown again, and the names and email addresses replaced with placeholders in it are kept encrypted so they can be restored for the user. Both are deleted when the user deletes the conversation.
Files are kept separately. A document the user brings in from OneDrive or SharePoint, and any file Assistant creates, is saved to the user’s Assistant workspace files. Deleting a conversation does not delete those files; they stay until the user deletes them from their workspace files.
Roster records the institution provides to CampusLayer, such as people, courses, sections, and enrollments, are not read from these systems. CampusLayer stores them as the institution’s processor under the Data Processing Addendum and uses them to run the institution’s CampusLayer workspace and to find the names of the institution’s people before text reaches an AI model.
Domain name service (not a subprocessor)
DNS for campuslayer.app is hosted by Cloudflare in DNS-only mode. Cloudflare answers lookups for CampusLayer’s domain names, which point directly to Vercel. Cloudflare does not proxy, receive, or store any requests, pages, or customer data. If that ever changes, Cloudflare will be added to this list with notice under the Data Processing Addendum.
Public reference data
When CampusLayer staff set up a new district, CampusLayer looks up the district’s public name and identifiers in the National Center for Education Statistics directory and the Urban Institute Education Data API. Only public institution names and identifiers are sent; no personal information is involved.
Questions and notices
To ask about a subprocessor or receive notice of changes, contact us through the CampusLayer contact page.