Legal

Subprocessors

Third parties that help us deliver the Services. We notify Customers 30 days in advance of any addition.

Last updated: 1 May 2026

The list below covers every subprocessor that may receive personal data (including PHI when the Customer has explicitly enabled the relevant integration and attested a BAA).

VendorPurposeRegionPHI?
AWS (us-east-1, eu-west-1, ap-southeast-2)Hosting, Postgres RDS, S3 storage, KMSRegion of Customer's choiceYes
StripePayment processingUSNo
SentryError tracking — PHI scrubbed before sendUSNo
DatadogMetrics + structured logs (no PHI fields)US / EUNo
Plausible AnalyticsAggregate website analytics — marketing site onlyEUNo
PostmarkTransactional email (account / billing / verification)USNo
CloudflareCDN, DDoS protection, WAFGlobalNo
OpenAIAI skills — only when Customer enables and attests BAAUS (Zero Data Retention)Yes
AnthropicAI skills — only when Customer enables and attests BAAUSYes
Daily.coTelehealth video — only when Customer enables and attests BAAUSYes
TwilioSMS reminders — only when Customer enables and attests BAAUSYes

Onboarding new subprocessors

We give Customers at least 30 days' written notice before adding a new subprocessor that processes PHI. To object, email [email protected]. We work with you to find a mutually acceptable solution; if none is reached, you may terminate the affected Service.

Subscribe to changes

Customer admins can subscribe to subprocessor change notices in the tenant settings. Email subscribers receive notification 30 days before any new subprocessor processes PHI on their behalf.

Customer-controlled subprocessors

Several subprocessors above are activated only by an explicit Customer action (enabling the integration AND attesting a BAA). Until both happen, no data flows to that vendor:

  • OpenAI / Anthropic — AI skill execution
  • Daily.co — telehealth video
  • Twilio — SMS reminders
  • SendGrid / SES — transactional email if not Postmark

Contact

Privacy Officer: [email protected].