Subprocessors

Third-party service providers that process data on behalf of Clinic OS Pro

Last Updated: December 25, 2025

Notification of Changes: We will provide at least 30 days' notice before adding new subprocessors. Subscribe to updates by emailing ben@wiebe-consulting.com with subject "Subscribe to Subprocessor Updates".

Current Subprocessors

SubprocessorPurposeLocationData TypeHIPAAGDPR
Vercel Inc.Application Hosting & CDNUnited StatesAll application data in transitYesYes
Neon Inc.PostgreSQL Database HostingUnited States (AWS us-east-1)All stored data (encrypted at rest)YesYes
Twilio Inc.SMS Messaging ServiceUnited StatesPhone numbers, SMS message contentYesYes
Resend (or SendGrid)Transactional Email DeliveryUnited StatesEmail addresses, email contentYesYes
Stripe, Inc.Payment ProcessingUnited StatesBilling information, payment methodsN/AYes
Google (OAuth)Authentication ProviderUnited StatesEmail address, name, profile pictureN/AYes
SentryError Monitoring & LoggingUnited StatesError logs, performance data (no PHI)N/AYes

EMR Integration Partners

When you connect your EMR to Clinic OS Pro, we establish a connection to sync patient data. These are not subprocessors (they process data for you, not us), but for transparency:

  • WebPT - EMR for physical therapy practices
  • Jane App - Practice management software
  • Cliniko - Practice management software
  • Kareo (Tebra) - Practice management and EHR
  • SimplePractice - Practice management software
  • TherapyNotes - Mental health EHR (if applicable)

Your use of these services is governed by your separate agreement with them. We only access data you authorize us to sync.

Due Diligence

Before engaging any subprocessor, we verify:

  • Security certifications (SOC 2, ISO 27001, etc.)
  • Data protection policies and practices
  • HIPAA Business Associate Agreement availability (where PHI is involved)
  • GDPR Data Processing Agreement availability (for EU data)
  • Physical and technical security measures
  • Incident response capabilities

Objection Process

Under our Data Processing Addendum, customers have the right to object to new subprocessors. The process is:

  1. We notify you at least 30 days before adding a new subprocessor
  2. You may object in writing with specific, reasonable grounds
  3. We will work with you to address concerns
  4. If concerns cannot be resolved, you may terminate the service

Data Location

All primary data processing occurs in the United States. We use US-based data centers for:

  • Application hosting (Vercel - AWS regions)
  • Database storage (Neon - AWS us-east-1)
  • Backups (encrypted, US-based)

For customers requiring data localization, please contact us to discuss options.

Contact

For questions about our subprocessors:

Email: ben@wiebe-consulting.com
Subject: "Subprocessor Inquiry"

Change Log

DateChange
Dec 25, 2025Initial subprocessor list published

Document Version: 1.0
Last Reviewed: December 25, 2025