Skip to main content
Legal · Subprocessors

Vendors. Listed publicly.

PracticeIQ uses the subprocessors below to deliver the Service. Every vendor handling PHI either has a signed BAA in place or is held out of the PHI path until one is executed. Customers are notified by email 30 days in advance of any addition or material change.

Pilot-transparent status: we are pre-customer-1 and are mid-transition off Vercel (not BAA-eligible on our current plan) to AWS, with the migration scheduled for the weekend of 2026-05-03/04. BAA requests to OpenAI and Anthropic were submitted 2026-04-20 and are pending; until they return, all PHI-bearing LLM traffic routes through Google Vertex AI, whose BAA is signed.

Last updated 2026-04-21
SubprocessorPurposeData typeBAA statusRegion
Vapi AI, Inc.Voice AI orchestration + transcriptionPHI (transient)SignedUS
Twilio, Inc.SMS + voice (PSTN) originationPHISignedUS
Google, LLC (Vertex AI)LLM inference (specialty routing, fallback path)PHI (transient)SignedUS
OpenAI, LLCLLM inference (primary chat + intent)PHI (transient, ZDR required)Requested 2026-04-20 — PHI traffic held until BAA executedUS
Anthropic, PBCLLM inference (reasoning-heavy turns)PHI (transient, ZDR required)Requested 2026-04-20 — PHI traffic held until BAA executedUS
Amazon Web Services (primary database + hosting)Self-hosted Postgres (Supabase OSS) on EC2 us-east-2, root volume KMS-encrypted at rest, S3 backups with versioning + 90-day Glacier transitionPHIActive via AWS Artifact — executed 2026-04-22US East (Ohio)
Supabase, Inc. (retired)Previously hosted Postgres — migrated off 2026-04-22No current PHI — legacy project paused as rollbackNot applicable — project paused; no new PHI written after cutover
Vercel, Inc.Web app hosting (static + edge rendering, no PHI persistence)PHI in transit only — no storageNot required — all PHI persistence happens on AWSGlobal
Amazon SES (planned)Transactional emailPHICovered by AWS BAAUS East
Resend, Inc.Retired — replaced by AWS SESNot BAA-eligible on current plan — retired from PHI paths
Stripe, Inc.Billing, subscription managementPayment data only — no PHIN/A — no PHI processedUS
Cloudflare, Inc.CDN, DDoS protection, WAF (planned)PHI in transitPendingGlobal
Change notice

We tell you before we change anything.

When we add a subprocessor, remove one, or move data between regions, every active customer receives an email at the contact on file at least 30 days before the change takes effect. If you object, you may terminate per the master agreement.

Subscribe to subprocessor notices: email christian@practiceiq.tech.

Lock rate