Skip to main content

LEGAL // SUB-PROCESSORS

Sub-processors

Generated from lib/subprocessors.ts. We update this list within 30 days of any change. To be notified of changes, email support@brainiacstechsolutions.com with subject "subprocessor notice".

VendorPurposeRegionHIPAA / BAADPA
Stripe, Inc.Payments, subscription billing, payout, fraud screening (Stripe Radar).United States (global PCI scope)BAA availableexecuted
Cloudflare / Caddy front-endEdge TLS termination, DDoS shielding, rate-limiting.Global anycastNo PHI accessexecuted
Anthropic PBCLarge-language-model inference for natural-language workflows (intake summarization, response drafting).United StatesNo BAA — no PHI to this vendorstandard-terms
OpenAI, OpenAI LLCOptional secondary LLM for non-PHI flows.United StatesNo BAA — no PHI to this vendorstandard-terms
Twilio, Inc.Programmable SMS for booking confirmations, reminders, MFA.United StatesBAA availableexecuted
Deepgram, Inc.Speech-to-text for the voice receptionist.United StatesBAA availableexecuted
Postmark / SMTP relayTransactional email (receipts, password reset, dunning notices).United StatesBAA availableexecuted
Hetzner Online GmbHPrimary application + database hosting (EU primary, US fail-over).Germany (EU)No PHI accessexecuted

PHI handling

For our HIPAA-aware products (MedFlow, DentalFlowDesk, and any VetDeck deployment that captures human PHI), Protected Health Information is only sent to vendors that hold a current Business Associate Agreement with us. Vendors marked "No BAA" above are isolated from the PHI path: those products run in a "no-PHI to AI" mode until the BAA is executed.

Notification of changes

We notify customers at least 30 days before adding a new sub-processor that will process their data, except where the change is required for security or legal reasons, in which case we notify as promptly as practicable.