Subprocessors
Subprocessor register.
This register is the public review surface for vendors used to deliver ChiroVault. Data categories and agreement status must be confirmed during legal review before production PHI processing.
| Vendor | Purpose | Data categories | Region | Status |
|---|---|---|---|---|
| Cloudflare | Edge delivery, security, Workers | Request metadata, app traffic | Global / EU controls available | DPA required |
| Vercel | Public website and frontend hosting | Public site traffic, build metadata | EU/US infrastructure | DPA required |
| Supabase / Postgres | Database and authentication services where enabled | Clinic data, operational records | EU region target | DPA required |
| AWS SES | Transactional email | Email addresses, message metadata, transactional content | Region configured per deployment | DPA required |
| OpenAI / Google Gemini | Optional AI assistance | Minimized/scrubbed prompts unless explicitly approved | Provider-dependent | DPA; PHI routing requires legal review |
| Stripe / Mollie | Billing and payments | Billing contact, payment metadata | EU/US provider infrastructure | DPA required |
Final vendor scope may vary by tenant configuration. Request the signed subprocessor exhibit at legal@chirovault.ai.