Not an HMSThe revenue layer above the one you already run — orchestration for hospitals, health aggregation for employers.See the difference →

Home · Trust

Sub-processors

A sub-processor is any third party that could touch your data in the course of us providing the service. This is the complete list.

NADI · DOCUMENT
● Status current
● Plain language yes
● Contact stated
✓ published, dated, binding
  • Hosting — infrastructure in India. Stores all application data.
  • Transactional email — delivers appointment confirmations and reports. Receives a name, an email address and the content of the message.
  • Payments — processes subscription payments from the hospital. Receives billing contact details. Never receives patient data.
  • Sentry — error monitoring Purpose: records technical faults in the application so they can be diagnosed and fixed. Data processed: diagnostic metadata only — the error type and message, the program stack trace, the route pattern and HTTP method that failed, the status code, the organisation identifier, and the server’s runtime and release version. Patient data processed: none. Patient names, phone numbers, dates of birth, ABHA identifiers, diagnoses, prescriptions, clinical notes, uploaded files, request bodies, query strings, cookies and authentication tokens are stripped before transmission and are never sent. This is enforced in code and verified on every release. Location of processing: United States.

Changes to this list

A new sub-processor is announced before it is used, not after. If you want that notice by email rather than by watching this page, write to us and we will add you.

Read the rest of it.

Every one of these pages says what we do, what we do not, and who to write to when it matters.