Subprocessors
Last updated: 2026-08-11
Achieve IT uses the third-party providers listed below to help deliver the Ultimate Email Management System. We maintain this page so our customers can see exactly who we rely on and what they do with customer data.
Changes to this list: we will notify customers at least 30 days before engaging a new subprocessor, and you can object per our Data Processing Addendum §6.3.
Core infrastructure
| Subprocessor | What they do for us | Where processing happens | Their security/privacy page |
|---|---|---|---|
| Railway Corp. | Application hosting (web app, API, workers), managed Postgres database, managed Redis | United States | railway.com/security |
| Cloudflare, Inc. | Object storage (R2) for knowledge-base documents; DNS and edge networking | Global, primarily United States | cloudflare.com/trust-hub · SOC 2 Type II, ISO 27001 |
A note on encryption keys: your stored mailbox credentials are protected by envelope encryption — each credential has its own data key, and those keys are wrapped by a master key. That master key is currently held in our hosting platform's encrypted configuration store, which is why no separate key-management provider appears above. We plan to move it to a dedicated key-management service (AWS KMS) before our first non-pilot client, and we will add that provider to this list when we do.
Identity and authentication
| Subprocessor | What they do for us | Where processing happens | Their security/privacy page |
|---|---|---|---|
| Clerk, Inc. | User authentication and session management for the client and admin portals | United States | clerk.com/legal/privacy · SOC 2 Type II |
Multi-factor authentication is not handled by Clerk — Achieve IT runs its own TOTP second factor, and the TOTP secrets never leave our database.
AI model provider
| Subprocessor | What they do for us | Where processing happens | Training policy | Their terms |
|---|---|---|---|---|
| MiniMax (standard tier, default) | Large language model inference for draft generation, classification, and safety review | United States and global edge | May use submitted content as training data per provider terms | minimaxi.com |
On the standard service tiers (Solo, Team, Business, Managed — and the retired Starter, Growth, and Scale plans), customer content sent to MiniMax for inference may be used by MiniMax to train its own models per the provider's published terms. Achieve IT does not control that policy.
If a contractual no-training guarantee is required, Achieve IT offers a no-training AI tier that routes inference to an alternate provider (e.g., a self-hosted or zero-retention API endpoint) under a written addendum. Pricing is custom; contact [email protected].
Embeddings and search
| Subprocessor | What they do for us | Where processing happens | Their terms |
|---|---|---|---|
| Voyage AI | Generates vector embeddings of knowledge-base documents and of email text used for reply-pattern clustering, so the assistant can retrieve the right context when drafting | United States | voyageai.com |
Embeddings are numeric representations of text, not the text itself, but the source text is transmitted to Voyage in order to produce them. Voyage does not receive your stored credentials.
Outbound service email
| Subprocessor | What they do for us | Where processing happens | Their terms |
|---|---|---|---|
| Resend | Delivers Achieve IT's own transactional and notification email to your users — welcome messages, daily digests, and alerts | United States | resend.com/legal/privacy-policy |
Your customers' replies are sent through your mail provider (Gmail, Microsoft 365, or your own SMTP server), never through Resend. Resend only carries mail that Achieve IT itself sends to you.
Payments and financial
| Subprocessor | What they do for us | Where processing happens | Their security/privacy page |
|---|---|---|---|
| Stripe, Inc. | Payment processing (cards, invoices) | United States and Canada | stripe.com/privacy · PCI-DSS Level 1, SOC 2 Type II |
Other operational
| Subprocessor | What they do for us | Where processing happens | Their security/privacy page |
|---|---|---|---|
| Calendly, LLC | Meeting scheduling (call bookings on our marketing page and from the client portal) | United States | calendly.com/privacy |
| Google LLC (Google Analytics 4) | Website and portal usage analytics: page views and navigation paths on achieveit.ca and email.achieveit.ca | United States | policies.google.com/privacy |
Google Analytics runs with ad personalization and Google Signals switched off. It receives page addresses stripped of record identifiers and query strings, plus the standard device and approximate-location signals any web analytics tool collects. It is not loaded on the admin console, and it never receives email content or knowledge-base content. The client portal reports to a separate Analytics property that is not linked to Google Ads; the marketing-site property is linked, so browsing achieveit.ca also sends a non-personalized remarketing ping. See the Privacy Policy §9.
Data each subprocessor can access
For transparency, here is what each subprocessor can see. No subprocessor has access to the full picture; each sees only what it needs for its function.
| Subprocessor | Email content | Customer credentials | Knowledge base | Account metadata | Payment details |
|---|---|---|---|---|---|
| Railway | Yes (encrypted at rest in database) | Yes (encrypted at rest) | Yes (encrypted at rest) | Yes | No |
| Cloudflare R2 | No (knowledge-base files only) | No | Yes (raw files) | No | No |
| Clerk | No | No | No | Sign-in details | No |
| MiniMax (standard tier) | Yes (email bodies sent for inference; may be used by MiniMax for training) | No | Yes (retrieved KB excerpts included in the prompt) | No | No |
| Voyage AI | Yes (email text sent to generate embeddings) | No | Yes (KB text sent to generate embeddings) | No | No |
| Resend | No (only Achieve IT's own notification emails) | No | No | Name and email address of your users | No |
| Stripe | No | No | No | Billing contact | Card details (Stripe holds these; we don't) |
| Calendly | No | No | No | Name and email when booking a call | No |
| Google (Analytics) | No | No | No | Pages visited, device type, approximate location | No |
Not subprocessors (for clarity)
Some services are NOT subprocessors under this framework because they don't process personal data on our behalf:
- GitHub: where we host our code. Customer data does not live in GitHub.
- Google Workspace: our own internal email and docs. Our business operations, not customer data processing.
- Linear: our own internal project management.
These are vendors to Achieve IT and are not listed as subprocessors because they do not process customer personal information.
Historical subprocessor changes
We log every addition, removal, or material change to this list so customers have an auditable history.
| Date | Change | Notes |
|---|---|---|
| 2026-05-01 | Initial publication | Launch version |
| 2026-07-29 | Added Google LLC (Google Analytics 4) | Usage analytics on achieveit.ca and the client portal. Advertising features disabled; no email or knowledge-base content sent; not loaded on the admin console. |
| 2026-08-11 | Added Voyage AI | Generates the vector embeddings that power knowledge-base retrieval. Identified during an internal review as already in use and not yet listed here; added as soon as we found it rather than waiting for the usual 30-day notice window. |
| 2026-08-11 | Added Resend | Delivers Achieve IT's own notification email. Same as above: already in use, added on discovery. |
| 2026-08-11 | Removed Amazon Web Services (AWS KMS) | Listed since launch, but the migration to a dedicated key-management service has not happened yet — the master encryption key is still held in our hosting platform's encrypted configuration. Removed rather than leave a provider listed that we do not currently use. It will be re-added when the migration completes. |
(This table will grow over time as we add or swap subprocessors.)
Questions
- General privacy questions: [email protected]
- Data-processing / DPA questions: [email protected]
- Security researcher disclosures: [email protected]