ORALZY will notify Customers of intended changes to this list — addition or replacement of a sub-processor — at least fifteen (15) days in advance, by email to the registered admin contact and by updating this page. Customers who reasonably object on data-protection grounds may terminate the affected feature or, if no workaround is feasible, the subscription as a whole, in line with Section 7 of the DPA.
| Sub-processor | Purpose | Hosting region | Data category |
|---|---|---|---|
| Amazon Web Services — Lightsail (Amazon Internet Services Pvt. Ltd.) |
Application hosting, compute, file storage | Mumbai, India (ap-south-1) | All Customer data at rest and in transit |
| MongoDB Atlas (MongoDB Inc.) |
Primary application database | Mumbai, India | Clinic, patient, appointment, billing, clinical records |
| Cloudflare (Cloudflare Inc.) |
CDN, DDoS mitigation, DNS, WAF, edge TLS | Global edge with India POPs | Request metadata, IP, headers; transient page content |
| GitHub Actions / GitHub (GitHub Inc.) |
Source-control, CI/CD, deploy automation | USA / EU | Source code only — no Customer data |
| Sub-processor | Purpose | Hosting region | Data category |
|---|---|---|---|
| Meta WhatsApp Cloud API (Meta Platforms Ireland Ltd.) |
Outbound and inbound WhatsApp Business messaging, templates, broadcast, lab portal alerts | Ireland / global | Patient name, mobile number, message content, delivery receipts |
| 2Factor (Voilo Tech Pvt. Ltd.) | OTP delivery for login & verification, transactional SMS | India | Mobile number, OTP, sender ID |
| Twilio Inc. optional | Voice OTP, fallback SMS | USA / global | Mobile number, OTP, call metadata |
| Google LLC — Gmail / Workspace SMTP | Transactional email (OTP, invoices, password reset, notifications) | USA / global | Recipient email, subject, body |
| Sub-processor | Purpose | Hosting region | Data category |
|---|---|---|---|
| Razorpay Software Pvt. Ltd. | Subscription billing, UPI / card / net-banking collections, refund processing, GST invoicing | India | Customer name, email, GSTIN, payment instrument tokens; no full PAN/card number stored by ORALZY |
| Sub-processor | Purpose | Hosting region | Data category |
|---|---|---|---|
| Google — Gemini API (Google LLC) |
Veeransh AI fallback for X-ray analysis, voice-note transcription, treatment-plan suggestions | USA / global | Anonymised X-ray images and prompt text only — see §7 |
| OpenAI optional | Optional language-model assistance for summaries, drafting | USA | Prompt text only; no patient identifiers sent |
| Anthropic optional | Optional language-model assistance | USA | Prompt text only; no patient identifiers sent |
| Sub-processor | Purpose | Hosting region | Data category |
|---|---|---|---|
| Expo / Expo Application Services (EAS) | Build and deliver the ORALZY mobile app (Android/iOS); over-the-air JS updates | USA / global | Build artefacts only — no Customer data |
| Apple Push Notification Service / Firebase Cloud Messaging optional | Mobile push notifications | USA / global | Device token, notification title/body |
| Sentry / equivalent error tracker optional | Crash and error monitoring | USA / EU | Stack traces, redacted user/clinic identifiers |
When ORALZY sends data to AI sub-processors:
Each listed sub-processor may rely on its own infrastructure providers (e.g. AWS, Google Cloud, Azure). ORALZY contracts with the headline sub-processor and relies on that vendor's published sub-processor list and DPA for downstream chains.
Questions about sub-processors, requests for additional documentation (DPA copies, ISO/SOC reports of upstream vendors), or objections to a planned change should be sent to [email protected].