dailybuilt
  • Platform
  • Pricing
  • Writing
  • Get early access
Get early access
Trust

Subprocessors

The providers below process data on our behalf. This register is generated from the same source that fills Exhibit C of every dailybuilt Business Associate Agreement, so what you read here is what the agreements say.

Register version 1.2 · As of July 28, 2026

Subprocessors in the PHI scope

Each subprocessor listed here creates, receives, maintains, or transmits protected health information in connection with the Service, and each is bound by a business associate agreement or equivalent HIPAA addendum at least as restrictive as our own, consistent with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b).

SubprocessorService and PHI processedHIPAA basisLocation
Google LLC
Google Cloud Platform
Application hosting, the primary PHI database, encrypted object storage for executed and signed documents, superbills, issued agreements, and client file attachments (accessed via short-lived signed URLs), secret management, and system logging. Processes and stores all categories of PHI in Exhibit A-2.Google Cloud HIPAA Business Associate Addendum (account-wide); PHI confined to Google Cloud “Covered Products.”United States
Amazon Web Services, Inc.
SES, S3, Lambda
Delivery of appointment- and care-related email, and receipt and threading of client email replies (including any attachments a client sends). Processes client name, email address, message content, and attachments.AWS Business Associate Addendum (AWS Artifact), over HIPAA-eligible services; TLS enforced.United States

Providers outside the PHI scope

These providers support the Service but are not in the PHI scope:

  • Stripe, Inc.: payment processing; operates under the payment-processing exception at § 1179 of the Social Security Act and receives only opaque identifiers and generic descriptors, not clinical PHI.
  • WorkOS, Inc.: authentication for Covered Entity’s operators and staff only; clients do not authenticate and no client PHI is transmitted.
  • Cloudflare, Inc.: DNS, bot-protection challenge, and static marketing-site delivery; on these surfaces PHI hostnames are served DNS-only so TLS terminates at the BAA-covered host and Cloudflare does not decrypt or receive PHI request content.

SMS / text messaging is designated a non-PHI channel and is disabled for the Healthcare Edition; web analytics for Covered Entity’s hosted sites is performed on a de-identified basis and is not PHI.

The full list of service providers we use, including those that never touch health information, is in Section 5.1 of the Privacy Policy.

Changes to this register

We may add or replace a subprocessor that processes PHI provided we first bind it to written obligations at least as restrictive as our own agreement. On written request we will provide the then-current list and reasonable advance notice of a material change, and a covered entity may object on reasonable HIPAA-compliance grounds.

Prior versions of this document are archived by date and are available on request to hello@dailybuilt.co.

dailybuilt

The thinking layer for your whole business. Customers, bookings, payments, messaging, and your website in one login, one bill. In early access from Miami.

Platform
FeaturesHow it worksPricing
Company
Why we’re building itWritingFAQ
Contact
Get early accesshello@dailybuilt.coLinkedIn
Legal
TermsPrivacyEnd-User TermsConsumer Privacy NoticeDPAAcceptable UseSMS TermsBilling & RefundsCopyright & DMCASecurityAccessibilityCookiesLegal ProcessMeta Data DeletionSubprocessors
Consumer Health Data Privacy
dailybuilt
© 2026 DailyBuilt, Inc. All rights reserved.