Sub-processors
This page lists every third party with which CommunityCare shares personal information to operate the service. Each is bound by a written agreement requiring confidentiality and security measures no less protective than our own.
Last updated · 11 June 2026 (Sentry + Better Stack added for Stage 6 observability)
Material changes are notified by email to active organisation admins at least 30 days before they take effect, where doing so does not undermine security.
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Supabase supabase.com | Postgres database, authentication, file storage | All account data, all patient records, audit logs, uploaded photos and documents | London, UK (AWS eu-west-2) |
| Vercel vercel.com | Application hosting, serverless functions, edge CDN | HTTP request metadata (IP, user-agent), no patient record persistence — Vercel does not store our application data | London (function region); global edge CDN for static assets |
| Stripe stripe.com | Payment processing, subscription billing | Customer name, billing address, payment method details (tokenised by Stripe), invoice records. No patient health data is shared with Stripe. | Ireland (primary), United States |
| Postmark postmarkapp.com | Transactional email (invites, password resets, billing notifications) | Recipient email, recipient name, email content. No patient health data is sent by email. | United States (with EU Standard Contractual Clauses) |
| Sentry sentry.io | Application error and crash reporting | Stack traces, HTTP request metadata (route, method, response status), user agent. Cookies, authorisation headers, request bodies, names, emails, phone numbers, and free-text fields are stripped before transmission. No patient health data is sent to Sentry. | Germany (EU data residency) |
| Better Stack betterstack.com | Uptime monitoring, incident alerting, status page hosting | HTTP health-check probe results (response code, latency, content size) from public endpoints only. No account data, no patient data. | European Union |
| Plausible Analytics plausible.io | Privacy-first usage analytics | Anonymous, aggregate page-view counts. No cookies, no IP storage, no cross-site tracking, no identification of individual users. | Germany (EU) |
Notification of changes
We will notify active organisation administrators by email at least 30 days before adding a new sub-processor, removing one, or changing where data is processed in a way that materially affects the categories above. Organisations have the right to object to a new sub-processor; we will work with them to find an alternative or, if none exists, accept termination of the affected service for cause.
Want a copy of an agreement?
Each sub-processor publishes its own DPA / privacy commitments at the links above. We are happy to share our signed sub-processor agreements with GP practice partners under NDA on request to privacy@community-care.app.