Legal
Subprocessor list
Updated every time we change a subprocessor. We notify paid-tier customers 30 days before adding a subprocessor that processes their personal data.
| Subprocessor | Purpose | Data type | Location | BAA / DPA |
|---|---|---|---|---|
| Google Workspace | Per-agency Sheets (system of record) | Operational data, PHI | United States | BAA + DPA |
| Cloudflare (Enterprise) | Workers, R2, KV, DO, queues | Operational data, PHI (paid tiers) | Global edge | BAA + DPA |
| Anthropic | Claude API (redacted inputs only) | Redacted PHI projections, NOT raw PHI | United States | BAA (direct API) |
| DeepL | Document translation (general) | Redacted text, NOT medical/legal raw | EU | DPA |
| Deepgram | Streaming STT for live captions | Audio + transcripts | United States | BAA available |
| Twilio | SMS Verify and Programmable SMS | Phone numbers, OTP codes | United States | BAA (HIPAA-eligible products) |
| Postmark | Transactional email | Email addresses, message body | United States | BAA add-on |
| Stripe + Stripe Connect | Payment processing and payouts | Payment tokens, bank info | United States | DPA |
| track1099 | 1099-NEC and 1042-S issuance | TIN, payee info, payment totals | United States | DPA |
| Plaid | ACH account verification | Bank account verification | United States | DPA |
Reviewed and updated 2026-05-17.
Last updated: 2026-05-17. Questions: hello@madeby1891.com.