Vendors & subprocessors
Who processes what, and where.
Five subprocessors can touch customer data. Three of them can see record content in full-data mode; two cannot see it at all. This page says which is which, in a table, without you reading a contract first.
Subprocessors
Every vendor that can touch customer data
A subprocessor within the meaning of GDPR Article 28 and the HIPAA Rules. Region is where the workload runs, not where the company is incorporated.
| Vendor | What it does | Region | Customer records? |
|---|---|---|---|
| Cloudflare | Workers compute (API + dashboard), KV (parsed uploads at a 24h TTL, rate-limit counters, statistics cache), R2 (asset storage), Analytics Engine, DNS, DDoS protection, edge cacheBAA available on Cloudflare Enterprisecommitment | Global PoPs (per-customer region selectable on Cloudflare Enterprise) | Record content can reach it |
| Supabase | Postgres (authentication, sessions, rate-limit ledger, audit log, upload metadata) + Auth. parsed_sample is clamped to ≤3 rows × ≤80 chars per cell; parsed_rows is null in schema-only mode.HIPAA add-on on Supabase Teams / Enterprisecommitment | US or EU per project — Ireland for EU workloads (DPA Art. 8) | Record content can reach it |
| phi-cloud | Layer-5 LLM provider for full-data mode — a PHI-aware, OpenAI-compatible gateway. Also the reshape program sandbox.BAA in place with model providerscommitment | Per X-Region header — CH-, EU- or US-resident BAA-covered models | Record content can reach it |
| Stripe | Prepaid wallet top-ups, payment processing, invoicing, customer-portal sessionsOut of PHI scope — no clinical data flows through billing. DPA and Standard Contractual Clauses in place via Stripe. | Ireland (with US affiliate) | No customer records |
| SMTP / transactional email | Sign-in links, billing receipts, usage alerts, destructive-action noticesScoped to non-PHI content; no patient-identifying data in transactional email | Per configured provider | No customer records |
“Commitment” marks coverage that depends on the plan or upstream contract in force, not on a capability that is always on. The authoritative statement of each is in the subprocessor list and DPA Article 8.
Out of scope
Operational vendors that see no customer data
Named here for completeness. These are not subprocessors within the meaning of GDPR Article 28 or the HIPAA Rules, and are listed as such in /legal/subprocessors §4.
Source control & CI/CD
GitHub, for the source tree and build pipelines. No customer data.
Error reporting
Cloudflare Workers logs and structured request tracing. IP addresses are truncated at the edge before they reach application logs; row content is never logged.
Status page
status.adaptivmapr.com, for incident and maintenance notices.
Changes
How you hear about a new one
Adding or replacing a subprocessor is a change to the DPA, not a silent config edit. The notice period, the objection right and the mechanism are all stated in the DPA rather than on this page, because that is where they are binding.
Reviewing us
Send the questionnaire. We answer in writing.
A BAA, the HIPAA security risk assessment, the DPA and the subprocessor list are all available on request — and most of what a reviewer asks is already on this site.