Data Processing
Last updated: August 30, 2026
Overview
This page explains how ImmiDesk processes personal data on behalf of the immigration consultants and practices who use the Service. It complements our Privacy Policy and is intended to give practices the information they need for their own GDPR records.
Controller and Processor
When you enter information about your own clients, you are the data controller and ImmiDesk is the data processor. We process client data only on your documented instructions and only to provide the Service. We do not use your client data for our own purposes.
Subprocessors
We rely on a small number of vetted subprocessors, each bound by a data processing agreement:
- Clerk — authentication and account security.
- Cloudflare — hosting, content delivery and DDoS protection.
- PostHog — product analytics (usage events, IP addresses anonymized).
Security Measures
Data is encrypted at rest and in transit. Access is scoped by role and, for collaborators, limited to the specific documents shared with them. See our security page for details.
Data Location and Transfers
Client records and documents are stored in the EU. Where a subprocessor operates outside the European Economic Area, transfers are covered by Standard Contractual Clauses or an adequacy decision.
Contact
To request a signed data processing agreement or ask about our processing, email privacy@immidesk.app.