1. What a subprocessor is
A subprocessor is a third-party service provider that Enamela engages to help deliver the platform, and that may process clinic or patient personal data as part of that role. Enamela remains responsible for these subprocessors under the Data Processing Agreement.
2. Current subprocessors
| Subprocessor | Purpose | Location / region | Data involved |
|---|---|---|---|
| Vercel | Application hosting and delivery | [confirm region] | All application traffic |
| Supabase | Database and file storage | ap-southeast-1 (Singapore) | Clinic and patient records, uploaded files |
| Cloudflare | Turnstile bot protection | [confirm region] | Limited technical/browser data for bot checks |
| Email provider [confirm] | Transactional and account email | [confirm region] | Name, email address, message content |
| WhatsApp Business Platform (Meta) | Appointment and clinic messaging | [confirm region] | Phone number and message content sent via WhatsApp |
| Payment processor(s) [confirm per country] | Billing and subscription payments | [confirm region] | Billing contact details and payment references (not full card numbers) |
| Anthropic | Optional AI assistant features | [confirm region] | Content a clinic user submits to an AI assistant feature, when enabled |
3. How subprocessors are used
Each subprocessor is engaged under a contract that requires it to protect data in a manner consistent with this policy and our Data Processing Agreement, and to use the data only to provide its service to Enamela.
AI assistant features powered by Anthropic are optional; a clinic's use of Enamela does not require enabling them, and clinics can choose whether to use AI features that send content to this subprocessor.
4. Changes to this list
We may add, remove, or change subprocessors as the service evolves. Where a new subprocessor will process patient data, we will provide reasonable advance notice (for example by email to clinic administrators or a notice on this page) so clinics can review the change, consistent with the Data Processing Agreement.
5. Contact
Questions about our subprocessors can be sent to privacy@enamela.app [confirm address].