Legal

Sub-processors

Last updated: 16 May 2026. Required by DPDP §5(c) — recipients of personal data must be disclosed.

A sub-processor is a third party that processes personal data on our behalf. We sign a Data Processing Agreement (DPA) or Business Associate Agreement (BAA) with every sub-processor before any personal data flows to them.

We notify hospitals + account holders at least 30 days before adding any new sub-processor.

Sub-processorRoleData locationAgreement
Microsoft Azure Cloud hosting — compute (Container Apps), PostgreSQL database, Redis cache, Blob object storage, Key Vault key management, AI Document Intelligence (culture-report PDF parsing), Azure OpenAI GPT-4o inference, Communication Services (transactional email), Application Insights / Log Analytics telemetry, and Front Door + WAF edge Central India (Pune); Azure OpenAI in South India (Chennai); email data-location pinned to India HIPAA BAA + DPA
GoDaddy Domain registration + DNS for vigiams.com (no personal data processed — DNS resolution only) Global anycast DNS DPA

Transactional email (e.g. break-glass and security notifications) is sent via Azure Communication Services with its data location pinned to India — it is part of the Microsoft Azure agreement above, not a separate provider. We do not use GoDaddy, Zoho, or any third-party mail host to process personal data.

Cross-border transfer

We do not transfer personal data outside India. The DPDP Act §16 cross-border transfer mechanism (whitelisted countries) is currently not invoked. All sub-processors above process personal data inside India.

How we monitor sub-processors

For any question about sub-processors, contact the DPO or Grievance Officer.