Legal
Subprocessors
Every company that processes data on our behalf, what it receives, and whether a signed agreement covers patient information.
How to read this
Handles patient information is the column that matters, and a row is one of three kinds.
- Yes. The vendor receives information that HIPAA protects and works under a Business Associate Agreement with us. The Agreement column says whether that agreement is signed or still to be executed; no patient information goes to a vendor until it is signed.
- Kept out by design. The vendor sits in the patient's path but signs no agreement, so the product keeps clinical content away from it. Meta carries the messages a patient sends to your Instagram, Messenger or WhatsApp, and the assistant keeps those conversations non-clinical.
- No. The vendor never receives patient information: it hosts or measures this website, runs its demo, places a demo call a visitor asked for, bills your subscription, or sends email that carries none, and the row says which.
Bookings are written into your own Google Calendar. That calendar is yours, held under your own agreement with Google, so it is not a vendor of ours and has no row here. (The Google row below is this website's own lead register, which never holds patient information.)
Deposits, where you take them, go through your own payment processor account, which you connect during setup. It is yours too, under your own agreement with it, so it has no row here either. A deposit link carries only an amount, a generic description and a reference code: no treatment name or other clinical detail, in the description, the statement descriptor or the metadata. (The Stripe row below is our own billing of your subscription.)
The register
| Vendor | Purpose | Receives | Region | Handles patient information | Agreement |
|---|---|---|---|---|---|
| Amazon Web Services | Hosting the product and its storage, in the AWS account designated under our AWS agreement | Patient information the product holds: contacts, conversations, appointments, transcripts (no call audio is kept) | United States (single region) | Yes | BAA signed 2026-09-22 |
| Retell | The voice agent's telephony and speech: answers the calls a clinic forwards to it, and transcribes them | Caller audio and caller number during the call, and the call transcript. Call recording is kept off | Not yet confirmed | Yes | BAA to be executed before any patient information is processed; none is today |
| Anthropic (the product) | The language model behind every channel of the product, in a HIPAA-ready Anthropic organisation used only for the product | Conversation text and the clinic's public service information. Under the BAA Anthropic keeps inputs for 30 days, which its covered models require, except content its trust-and-safety systems flag or the law requires it to keep, which it may hold for up to two years. No training on any of it | United States | Yes | BAA to be executed before any patient information is processed; none is today |
| Anthropic (the website demo) | The language model behind the chat demo on this website, in a separate Anthropic organisation from the product's | What you type into the demo, and the public service information of the specialty being demonstrated. No training on any of it | United States | No | Not required — A separate organisation from the product's, with no BAA: the demo is for clinic owners and staff, not a patient channel, and no patient information is sent to it. |
| Meta (Instagram, Messenger, WhatsApp) | Carries the messages patients send to a clinic's Instagram account, Facebook Page and WhatsApp number, and the assistant's replies | The patient's own messages and the identifiers Meta attaches to them (on WhatsApp, their phone number). Clinical content is caught when it arrives and not stored, and replies carry no treatment names | Meta's own infrastructure; not region-pinned | Kept out by design | None, and none available — Meta signs no BAA for any messaging product. These channels are kept free of clinical content: anything clinical is moved to a call or the clinic's own secure route. |
| Stripe | Billing the clinic for its healdesk subscription | Clinic name, billing contact, card details (held by Stripe, never by healdesk) | United States | No | Not required — Our own billing carries business contact and payment details only. Deposits go through the clinic's own payment processor account, not this one; see the note above the register. |
| Synthflow | Places the one demo call a visitor asks for on this website. It carries no patient calls: the product's voice agent runs on Retell | The number you typed, the first name you gave, and the audio and transcript of the demo call | United States workspace | No | Not required — Demo calls to clinic owners and staff who asked for one; never a patient call. |
| Resend | Transactional email: invitations, agreement copies, account and billing notices | Recipient address and non-patient content only | United States | No | Not required — It carries only email that holds no patient information: the product refuses to send anything else through it (apps/app/src/lib/reporting). |
| Vercel | Hosting this marketing website | Page requests, the demo gate email, contact-form submissions | United States | No | Not required — The marketing site holds no patient information; the product is hosted elsewhere. |
| Google (Google Sheets / Drive) | The marketing site's lead register: demo leads, funnel events and the demo-call consent record, in a Google Sheet | Work email, business or personal domain, specialty demoed, referrer host, campaign code, the marketing-consent record | United States (Google Cloud; not region-pinned for a Google account) | No | Not required — Business contact data only; a separate store from the product's; no patient information ever reaches it. |
| PostHog (US cloud) | Funnel analytics on this website, after consent | Page views and named funnel steps; no form contents, no email, no chat text | United States | No | Not required — Runs only on the marketing site and only after the cookie notice is accepted. |
| Apify | Reading a practice's public website when we research it before a first email | Publicly published pages of the practice's own website | United States | No | Not required — Public web pages only. |
Notice of changes
Before a new vendor handles patient information we email the billing and clinical contacts of every customer at least 15 days in advance, naming the vendor, what it will receive and why. A customer that objects may terminate without penalty within that period. Vendors that do not handle patient information are added to this page without notice.
Questions about any row: privacy@healdesk.io.
Version 2026-10-03.2 · last updated 3 October 2026 · questions to privacy@healdesk.io