Subprocessors
The providers below process data on our behalf. This is the register our Data Processing Addendum points to, and the second table is generated from the same source that fills Exhibit C of every dailybuilt Business Associate Agreement, so what you read here is what the agreements say.
Service subprocessors
Every provider that processes personal information on our behalf in connection with the Service, whether or not it ever touches health information. Each is bound by a written contract limiting its use of the information to providing its service to us. This is the list referred to in Section 10.2 of our Data Processing Addendum. A new subprocessor appears here before it begins processing, and you may object as described there.
| Subprocessor | What it does for us | Information it processes | Location |
|---|---|---|---|
| Google LLC Google Cloud Platform | Application hosting, the primary database, encrypted object storage, secret management, and system logging. | All categories of Customer Data and account data stored in the Service, including PHI for Healthcare Edition workspaces. | United States |
| Amazon Web Services, Inc. SES, S3, Lambda | Outbound email delivery, and receipt, storage, and threading of inbound email replies. | Sender and recipient names and email addresses, subject and message body, attachments. | United States |
| Stripe, Inc. Billing and payments | dailybuilt subscription billing, and payment processing for Customers through Stripe Connect. | Billing contact details, payment method data collected by Stripe directly, transaction and payout metadata. | United States |
| WorkOS, Inc. AuthKit | Authentication and email verification for Customer operators. | Name, business email address, credentials, session and device metadata. End users do not authenticate. | United States |
| Telnyx LLC Messaging | SMS delivery. | Mobile phone number, message content, delivery status. Text messaging is a channel not intended for PHI, and outbound text messaging is blocked from a Healthcare Edition workspace on every send path. | United States |
| Cloudflare, Inc. DNS, marketing site, Turnstile | Authoritative DNS, delivery of the marketing site, and the bot-protection challenge on public forms. | IP address and request metadata for the marketing site; browser and device signals submitted to the challenge. Hosted booking, signing, and payment pages are served DNS-only, so Cloudflare does not terminate TLS for them. | United States and global edge network |
| Functional Software, Inc. Sentry | Error monitoring, performance diagnostics, and session replay for the authenticated application. Error events, log events, performance traces, and session replay are suppressed for a Healthcare Edition workspace and on Healthcare Edition public booking and signing pages. | Error and performance events, session-replay recordings of the authenticated application, request metadata with query strings removed, workspace identifier. Configured not to collect user identity, cookies, or request bodies. | United States |
| PostHog, Inc. Product analytics | Product analytics, session replay, and heatmaps for dailybuilt’s own marketing site and authenticated application. Never loaded for a Healthcare Edition workspace, and never loaded on hosted booking, signing, payment, or tenant website pages. | Pages viewed, clicks and the text of the interface element clicked, session-replay recordings of the authenticated application, workspace identifier, plan and role, and the signed-in user’s identifier and email address. Form inputs are masked in replay and network request and response bodies are dropped. | United States |
| Hound Technology, Inc., d/b/a Honeycomb Distributed tracing | Distributed tracing and performance monitoring for the API. | Request method, URL path with record identifiers removed before transmission, response status, timing, request identifier, and workspace identifier. Carries no names, email addresses, or record content. | United States |
| Upstash, Inc. Rate limiting | Rate limiting and abuse control. | IP-derived identifiers and request counters. | United States |
| Metricool S.L. Marketing site only | Marketing-campaign attribution on the marketing site only. | Site visit events and a first-party cookie identifier. | Spain (EU) |
| Google LLC Analytics 4, Search Console | Site analytics and search-performance reporting on the marketing site only. | Site usage events, approximate location, device and referrer data. | United States |
Subprocessors in the PHI scope
A narrower set, and the one that fills Exhibit C of Business Associate Agreement version 1.3. Each subprocessor listed here creates, receives, maintains, or transmits protected health information in connection with the Service, and each is bound by a written agreement containing the assurances required of a business associate’s subcontractor under 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), which may take the form of that provider’s standard HIPAA business associate addendum. We remain responsible for our subprocessors’ acts and omissions with respect to protected health information to the same extent as for our own.
This register is Exhibit C version 1.3, as of 2026-08-12. It is versioned and dated independently of the Business Associate Agreement body, so adding or replacing a subprocessor does not require you to re-accept that agreement. We give at least 30 days’ notice before adding or replacing a subprocessor in the PHI scope.
| Subprocessor | Service and PHI processed | HIPAA basis | Location |
|---|---|---|---|
| Google LLC Google Cloud Platform | Application hosting, the primary PHI database, encrypted object storage for executed and signed documents, superbills, issued agreements, and client file attachments (written server-side and read through short-lived signed URLs), secret management, and system logging. Processes and stores the categories of PHI described in Exhibit A-2. | Google Cloud HIPAA Business Associate Addendum (account-wide); PHI confined to Google Cloud “Covered Products.” | United States |
| Amazon Web Services, Inc. SES, S3, Lambda | Delivery of appointment- and care-related email, and receipt and threading of client email replies (including any attachments a client sends). Processes client name, email address, message content, and attachments. | AWS Business Associate Addendum (AWS Artifact), over HIPAA-eligible services; TLS enforced. | United States |
Providers outside the PHI scope
These providers support the Service but are not in the PHI scope:
- Stripe, Inc.: payment processing; operates under the payment-processing exception at § 1179 of the Social Security Act and receives only opaque identifiers and generic descriptors, not clinical PHI.
- WorkOS, Inc.: authentication for Covered Entity’s operators and staff only; clients do not authenticate and no client PHI is transmitted.
- Cloudflare, Inc.: DNS, bot-protection challenge, and static marketing-site delivery; on these surfaces PHI hostnames are served DNS-only so TLS terminates at the BAA-covered host and Cloudflare does not decrypt or receive PHI request content.
- Functional Software, Inc. d/b/a Sentry: application error and performance monitoring for the customer-facing web application; configured not to collect user identity, request bodies, or cookies, and configured to suppress error events, log events, performance traces, and session replay originating from a Healthcare Edition workspace or from a Healthcare Edition public booking or signing page, so that no PHI is transmitted.
- Telnyx LLC: text messaging for non-healthcare workspaces only; text messaging is designated a channel not intended for PHI in Exhibit A-4, no business associate agreement covers it, and the Service blocks outbound text messaging from a Healthcare Edition workspace.
- Google LLC — services outside Google Cloud Platform: Google Calendar, Google Business Profile, Google Search Console, Google Places, and Google Ads, each used only where Covered Entity connects the corresponding account. These are not Google Cloud “Covered Products” and are not covered by the Google Cloud HIPAA Business Associate Addendum. The content Covered Entity manages through them is designated in Exhibit A-4 as not intended for PHI, and for a Healthcare Edition workspace the Service writes only an opaque busy block — with no client name, notes, or attendee address — to a connected calendar.
- Meta Platforms, Inc.: advertising and page management, used only where Covered Entity connects a Meta business account; no business associate agreement covers it, no PHI is transmitted, and Business Associate does not upload contact lists or customer audiences to Meta.
Text messaging is designated a channel not intended for PHI in Exhibit A-4. Business Associate blocks outbound text messaging initiated from a Healthcare Edition workspace in the Service and shall not send text messages containing PHI on Covered Entity’s behalf through any channel. Web analytics for Covered Entity’s hosted sites is performed on a de-identified basis, without setting cookies or storing raw IP addresses, and is not PHI.
The same providers, with a description of what each one receives, are listed in Section 5.1 of the Privacy Policy.
Changes to this register
Service subprocessors. We add a new subprocessor to this page a reasonable period before it begins processing personal information, so updating this page is how notice is given. Email hello@dailybuilt.co to be notified whenever the list changes. You may object on reasonable, documented data-protection grounds within thirty days of a change, as set out in Sections 10.4 and 10.5 of the Data Processing Addendum.
PHI-scope subprocessors. We may add or replace a subprocessor that processes PHI provided we first bind it to written obligations at least as restrictive as our own agreement. On written request we will provide the then-current list and reasonable advance notice of a material change, and a covered entity may object on reasonable HIPAA-compliance grounds.
Prior versions of this document are archived by date and are available on request to hello@dailybuilt.co.