Sub-processors
These are the vendors TheraFlow uses to deliver the service. We require each to meet contractual security and confidentiality standards. New sub-processors that touch Customer Data are announced to customer admins by email before they go live.
Last reviewed 7 June 2026
Vendor
Purpose
Data accessed
Location
- Amazon Web Services (AWS)Core servicePurposeCloud hosting — compute, database (RDS), object storage (S3), email (SES)Data accessedAll Customer Data at restLocationMumbai, India (ap-south-1)
- ClerkCore servicePurposeAuthentication and user identity (login, MFA, session management)Data accessedStaff user identifiers (name, email, password hashes)LocationUnited States
- Anthropic (Claude API)Opt-inPurposeAI features: scheduling suggestions, report generation, clinical reasoningData accessedOnly when AI features are enabled. Limited context per request; never used to train models.LocationUnited States
- Google AI (Gemini API)Opt-inPurposeAI features: alternative provider for scheduling and report generationData accessedOnly when AI features are enabled. Limited context per request; never used to train models.LocationUnited States
- RazorpayCore servicePurposePayment processing for TheraFlow subscriptions and (where used) parent payment collectionData accessedBilling contact, amount, invoice metadata. No patient clinical data.LocationBangalore, India
- NangoOpt-inPurposeThird-party connector framework (for integrations the centre opts into, e.g. Google Drive)Data accessedOnly data flowing through integrations the centre explicitly connectsLocationUnited States / European Union
Adding new sub-processors
We notify centre admins by email at least 30 days before any new sub-processor that handles Customer Data goes live. Customers may object during that window; if we cannot accommodate, we will work with you on transition options up to and including termination with a pro-rated refund.
Questions about sub-processors? Email founders@theraflow.in.