Data Processing

Last updated: August 30, 2026

Overview

This page explains how ImmiDesk processes personal data on behalf of the immigration consultants and practices who use the Service. It complements our Privacy Policy and is intended to give practices the information they need for their own GDPR records.

Controller and Processor

When you enter information about your own clients, you are the data controller and ImmiDesk is the data processor. We process client data only on your documented instructions and only to provide the Service. We do not use your client data for our own purposes.

Subprocessors

We rely on a small number of vetted subprocessors, each bound by a data processing agreement:

  • Clerk — authentication and account security.
  • Cloudflare — hosting, content delivery and DDoS protection.
  • PostHog — product analytics (usage events, IP addresses anonymized).

Security Measures

Data is encrypted at rest and in transit. Access is scoped by role and, for collaborators, limited to the specific documents shared with them. See our security page for details.

Data Location and Transfers

Client records and documents are stored in the EU. Where a subprocessor operates outside the European Economic Area, transfers are covered by Standard Contractual Clauses or an adequacy decision.

Contact

To request a signed data processing agreement or ask about our processing, email privacy@immidesk.app.