← Back to home

Sub-processors

Last updated: April 22, 2026

Respondo uses third-party service providers (sub-processors) to deliver its services. As a data processor under GDPR, we engage these sub-processors to perform specific functions on our behalf. This page lists all current sub-processors.

We notify customers at least 30 days in advance of any changes to this list. For details on how we handle data processing agreements, please refer to our Data Processing Agreement.

Current Sub-processors

ProviderPurposeData CategoriesLocationCertificationsDPA statusDPA link
ClerkAuthentication & user managementEmail addresses, user IDs, session dataUnited States / United KingdomSOC 2 Type IIAccepted via platform termsView DPA
SupabaseDatabase & file storageAll tenant and end-user dataEU (Dublin, Ireland) — eu-west-1SOC 2 Type II, ISO 27001, GDPR compliantAccepted via platform termsView DPA
StripePayment processing & subscription billingBilling information, email addresses, payment method metadataUnited StatesPCI-DSS Level 1, SOC 2 Type IIAccepted via platform termsView DPA
TwilioSMS & voice communicationsPhone numbers, message contentUnited States (EU peering for EU-registered numbers)SOC 2 Type II, ISO 27001Accepted via platform termsView DPA
AnthropicAI processing: clinical summaries, follow-up suggestions, assistant chat (Claude). Anthropic does not use customer data to train its models.Session notes and appointment metadata submitted for generationUnited StatesSOC 2 Type IIAccepted 2026-04-22 (DPA effective 2025-02-24)View DPA
OpenAIAudio transcription via Whisper. OpenAI does not train on API customer data; audio retained up to 30 days under OpenAI's default retention policy before deletion.Audio files submitted for transcriptionUnited StatesSOC 2 Type IISigned 2026-04-22 (DPA v.010126)View DPA
VercelApplication hosting, CDN, scheduled jobsRequest logs, runtime data, cron execution logsUnited States, EU (edge / functions in cdg1)SOC 2 Type IIAccepted via platform termsView DPA
SentryError tracking and performance monitoring (PII-masked)Error stack traces, request metadata. User input is masked (`maskAllText` + `maskAllInputs`).EU (de.sentry.io)SOC 2 Type II, ISO 27001Accepted via platform termsView DPA
PostHogProduct analytics (opt-in)Anonymous usage events. No clinical data. Cookie-gated.EU (eu.i.posthog.com)SOC 2 Type IIAccepted via platform termsView DPA

Changes to Sub-processors

We will notify customers at least 30 days before adding or replacing a sub-processor. If you object to a new sub-processor, you may terminate your subscription as described in our Terms of Service.

Questions

For questions about our sub-processors or data processing practices, contact us at privacy@hectormoyanovelez.com.