Vendors & subprocessors

Who processes what, and where.

Five subprocessors can touch customer data. Three of them can see record content in full-data mode; two cannot see it at all. This page says which is which, in a table, without you reading a contract first.

This page is the readable view. Where it and the DPA differ, the DPA governs.

Subprocessors

Every vendor that can touch customer data

A subprocessor within the meaning of GDPR Article 28 and the HIPAA Rules. Region is where the workload runs, not where the company is incorporated.

VendorWhat it doesRegionCustomer records?
CloudflareWorkers compute (API + dashboard), KV (parsed uploads at a 24h TTL, rate-limit counters, statistics cache), R2 (asset storage), Analytics Engine, DNS, DDoS protection, edge cacheBAA available on Cloudflare EnterprisecommitmentGlobal PoPs (per-customer region selectable on Cloudflare Enterprise)Record content can reach it
SupabasePostgres (authentication, sessions, rate-limit ledger, audit log, upload metadata) + Auth. parsed_sample is clamped to ≤3 rows × ≤80 chars per cell; parsed_rows is null in schema-only mode.HIPAA add-on on Supabase Teams / EnterprisecommitmentUS or EU per project — Ireland for EU workloads (DPA Art. 8)Record content can reach it
phi-cloudLayer-5 LLM provider for full-data mode — a PHI-aware, OpenAI-compatible gateway. Also the reshape program sandbox.BAA in place with model providerscommitmentPer X-Region header — CH-, EU- or US-resident BAA-covered modelsRecord content can reach it
StripePrepaid wallet top-ups, payment processing, invoicing, customer-portal sessionsOut of PHI scope — no clinical data flows through billing. DPA and Standard Contractual Clauses in place via Stripe.Ireland (with US affiliate)No customer records
SMTP / transactional emailSign-in links, billing receipts, usage alerts, destructive-action noticesScoped to non-PHI content; no patient-identifying data in transactional emailPer configured providerNo customer records

“Commitment” marks coverage that depends on the plan or upstream contract in force, not on a capability that is always on. The authoritative statement of each is in the subprocessor list and DPA Article 8.

Out of scope

Operational vendors that see no customer data

Named here for completeness. These are not subprocessors within the meaning of GDPR Article 28 or the HIPAA Rules, and are listed as such in /legal/subprocessors §4.

Source control & CI/CD

GitHub, for the source tree and build pipelines. No customer data.

Error reporting

Cloudflare Workers logs and structured request tracing. IP addresses are truncated at the edge before they reach application logs; row content is never logged.

Status page

status.adaptivmapr.com, for incident and maintenance notices.

Changes

How you hear about a new one

Adding or replacing a subprocessor is a change to the DPA, not a silent config edit. The notice period, the objection right and the mechanism are all stated in the DPA rather than on this page, because that is where they are binding.

Reviewing us

Send the questionnaire. We answer in writing.

A BAA, the HIPAA security risk assessment, the DPA and the subprocessor list are all available on request — and most of what a reviewer asks is already on this site.

HIPAA-ready with a BAA offered · SOC 2 in progress · GDPR and nFADP aligned