Sub-processors
Every third party that processes information on our behalf, what it does, and which country it operates in.
Draft — no effective date set
Draft — not yet in force
This document has not been finalised and does not create binding obligations. It still needs company details that only we can supply, and review by Canadian privacy counsel. Anything shown as [[LIKE THIS]] is a blank, not a value.
Outstanding: entityName, entityJurisdiction, registeredAddress, privacyOfficerEmail, securityEmail, supportEmail, generalEmail, governingProvince, effectiveDate.
We use a small number of providers to run the service. Each gets only what it needs, is bound by written terms no less protective than our Data Processing Addendum, and may not use your information for its own purposes. We remain responsible to you for what they do.
This page is the authoritative list. We update it before a new provider starts handling customer information.
Website, accounts and billing
These are the providers behind healthcoresecurity.ca, your login and your subscription.
| Provider | What it does | Information it sees | Location |
|---|---|---|---|
| Supabase | Database and authentication | Clinic profile, account records, enquiries submitted through the website, hashed credentials | Canada — Montreal region |
| Cloudflare | Hosting, CDN, DNS and network protection | Web traffic in transit; request metadata | Global edge network; company in the United States |
| Stripe | Subscription payments | Billing contact, subscription status, payment method. Card details go to Stripe directly and never reach us. | United States and Ireland |
| Resend | Transactional email — welcome and account messages | Recipient name and email address, message content | United States |
| Anthropic | Drafting blog articles for this website | No customer information. See the note below. | United States |
| Calendly | Optional "book a call" scheduler | Name, email and booking details you type into the scheduler | United States |
Two notes worth reading
Anthropic receives no customer data. We use Anthropic's models to draft the educational articles on our blog. What we send is a topic from an editorial queue — a subject line like "ransomware recovery for a clinic with no IT staff". No clinic record, no enquiry, no account, no telemetry and no patient information is sent, and none is used to train any model. We list Anthropic here for completeness, not because your data goes there.
Calendly does not load unless you allow it. The scheduler is off by default and we do not load its script or let it set a cookie until you accept it in the cookie banner. See the Cookie Policy.
Service delivery
These are the providers behind the security service itself, once your clinic is protected.
| Provider | What it does | Information it sees | Location |
|---|---|---|---|
| CrowdStrike | Endpoint protection platform underlying the Apex Security plan | Security telemetry from protected devices: process, file and network activity, authentication events, device and user identifiers | United States, with regional cloud options |
This table is incomplete and we are not going to pretend otherwise. The remaining tooling in our security operations centre — case management, log retention, and the detection stack behind the Guardian AI plan — has not yet been published here. If you are evaluating us and need the complete list before you sign, write to [[PRIVACY OFFICER EMAIL]] and we will give you the full inventory under NDA. We would rather hand you a complete list privately than publish a partial one that reads as though it were complete.
Which parts leave Canada
Your account records, clinic profile and website enquiries are stored in Canada.
Everything in the "United States" rows above involves information crossing the border. Information processed outside Canada is subject to the laws of that country and may be accessible to its courts, law enforcement and national-security authorities. We use contractual protections with each provider, and we will not tell you those defeat a foreign court order.
If your professional college, regulator or insurer requires Canadian-only processing, raise it with us before you subscribe. Some of these providers have Canadian regions we can use; some do not, and the honest answer may be that we are not the right fit for your constraint.
Changes and objections
When we add a sub-processor we update this page before it starts processing customer information, and we notify account holders.
If you object to a new sub-processor on reasonable privacy or security grounds, tell us within 30 days of the notice. We will either find an alternative or let you terminate the affected part of the service without penalty and refund the unused portion of your term. That commitment is in section 7 of the Data Processing Addendum.
Questions
[[PRIVACY OFFICER EMAIL]]