A sub-processor is a third party that processes personal data on our behalf. We sign a Data Processing Agreement (DPA) or Business Associate Agreement (BAA) with every sub-processor before any personal data flows to them.
We notify hospitals + account holders at least 30 days before adding any new sub-processor.
| Sub-processor | Role | Data location | Agreement |
|---|---|---|---|
| Microsoft Azure | Cloud hosting — compute (Container Apps), PostgreSQL database, Redis cache, Blob object storage, Key Vault key management, AI Document Intelligence (culture-report PDF parsing), Azure OpenAI GPT-4o inference, Communication Services (transactional email), Application Insights / Log Analytics telemetry, and Front Door + WAF edge | Central India (Pune); Azure OpenAI in South India (Chennai); email data-location pinned to India | HIPAA BAA + DPA |
| GoDaddy | Domain registration + DNS for vigiams.com (no personal data processed — DNS resolution only) | Global anycast DNS | DPA |
Transactional email (e.g. break-glass and security notifications) is sent via Azure Communication Services with its data location pinned to India — it is part of the Microsoft Azure agreement above, not a separate provider. We do not use GoDaddy, Zoho, or any third-party mail host to process personal data.
Cross-border transfer
We do not transfer personal data outside India. The DPDP Act §16 cross-border transfer mechanism (whitelisted countries) is currently not invoked. All sub-processors above process personal data inside India.
How we monitor sub-processors
- Region pinning: Code-level
(
assert_dpdp_residency) and cloud-level (Azure Policy Allowed locations) gates refuse any non-India region - Ongoing review: We re-validate each sub-processor's DPA/BAA at renewal and on material changes (new services, new regions)
- Termination: If a sub-processor materially fails privacy/security obligations, we move to an alternative within 90 days
For any question about sub-processors, contact the DPO or Grievance Officer.