The third parties that process TinyGuard® customer or end-user data on our behalf. Grouped by purpose, with BAA status per provider. This page is the single source of truth — our BAA §3.3 and our Privacy Policy §8 mirror what's here.
Your facility (the Center) is the data controller. TinyGuard is the data processor. Consent collection, signage, and operational compliance sit with the Center; TinyGuard provides the infrastructure, the audit log, and the compliance dashboard. The subprocessors listed below are sub-processors in that chain — TinyGuard contracts them on your behalf, and each is enumerated here for your transparency and your downstream-BAA review.
Two vertical stacks, separate at the data layer. Childcare facilities operate under our DPA (TG-DPA-001). Elder care facilities operate under the BAA (TG-BAA-E-001) — HIPAA path, not a DPA. We do not reuse childcare patterns for elder PHI; the two stacks remain isolated end-to-end. See the four covenants for the architectural decisions that shape this list.
Customer-impact rule: TinyGuard will not transmit PHI to a subprocessor marked 🟡 or 🔴 without an executed BAA at the time of transmission, per 45 CFR 164.502(e)(1)(ii) and 164.314(a)(2). We give customers 30 days' notice of material changes to this list.
| Subprocessor | Service | Data category | BAA status |
|---|---|---|---|
| Intuition Security, Inc. (hCaptcha) | CAPTCHA fraud/bot detection on public auth and signup forms when HCAPTCHA_SECRET is configured | Visitor IP address + browser user-agent fingerprint. Sent to api.hcaptcha.com/siteverify per form submission. No PHI. GDPR Art. 28 sub-processor disclosure. | ⚪ N/A — no PHI; visitor identifiers only |
| Subprocessor | Service | Data category | BAA status |
|---|---|---|---|
| Cloudflare, Inc. | Edge compute (Workers), R2 object storage, Cloudflare Tunnel, Cloudflare Calls SFU | All ePHI stored or processed on Cloudflare infrastructure; video segments | 🟡 In progress — Cloudflare BAA on Enterprise plan; required before first HIPAA-regulated facility goes live |
| Neon, Inc. | Serverless PostgreSQL — primary system of record | All platform data. Tenant isolation enforced via Row-Level Security (FORCE on every facility-scoped table) | 🟡 In progress — required before first HIPAA-regulated facility goes live |
Only one AI provider serves a given request. Customers can pick the provider per AI feature in their facility settings; default routing distributes requests across Anthropic and OpenAI by feature. Google Vertex AI is BAA-covered (Google Cloud BAA accepted 2026-06-05) and may serve PHI surfaces via Vertex AI only; the consumer Gemini (AI Studio) API, which signs no BAA, is never used for PHI.
| Subprocessor | Service | Data category | BAA status |
|---|---|---|---|
| Anthropic, PBC | Claude API — care summaries, daily reports, observation analysis, support chat | Care summaries, incident analyses, parent communications. Prompts may contain child/resident names, care events, health observations. Zero Data Retention available on commercial enterprise terms. | 🟡 In progress — Anthropic offers a HIPAA BAA; required before any PHI traverses this provider in production |
| OpenAI, L.L.C. | gpt-4o-mini — same care-summary, daily-report, observation, parent-comms, and support-chat flows as Anthropic | Same PHI categories as Anthropic | 🟢 Available — OpenAI Healthcare BAA executed 2026-07-03, with Zero Data Retention; PHI uses HIPAA-eligible endpoints only and is bound to the BAA organization. |
| Google LLC (Vertex AI) | Tertiary AI provider for the same flows when configured by the facility | Same PHI categories as Anthropic | 🟢 Available — Google Cloud BAA accepted 2026-06-05 covering Vertex AI (a HIPAA-eligible service). PHI is routed only via Vertex AI under Zero Data Retention; the public Gemini (AI Studio) API, which does not sign BAAs, is never used for PHI. |
| Subprocessor | Service | Data category | BAA status |
|---|---|---|---|
| Stripe, Inc. | Subscription + tuition payment processing (cards and ACH); bank account verification via Stripe Financial Connections | Billing identifiers, payment methods, and verified bank account references only; no clinical PHI | 🟢 Available — PHI handling limited to non-clinical billing identifiers |
| Subprocessor | Service | Data category | BAA status |
|---|---|---|---|
| Resend, Inc. | Transactional email (notifications, invitations) | Email addresses and generic notice text only; PHI excluded from payload by design (notify-only “log in to view”) | ⚪ N/A — Resend does not sign HIPAA BAAs; compliance is achieved by design (PHI excluded from all email payloads) |
| Twilio, Inc. | SMS notifications (pickup alerts, EVV reminders, two-factor) | Phone numbers and limited message text | 🟡 In progress — required before first HIPAA-regulated facility goes live. A2P 10DLC registration pending in our Twilio Console. |
| Subprocessor | Service | Data category | BAA status |
|---|---|---|---|
| Google Analytics / GTM | Marketing-site visitor analytics on tinyguard.co and vertical landing pages | Page views, anonymized visitor data. No app or device data is sent. | ⚪ N/A — no PHI; restricted to public marketing surfaces |
| Open-Meteo GmbH (open-meteo.com) | Weather data for facility dashboard contextual features (queried from the browser via api.open-meteo.com) | Facility latitude/longitude transmitted per weather query. No PHI. Open-Meteo is GDPR-compliant by design: no API key required, no personal data stored server-side. | ⚪ N/A — location data only, no PHI |
If this list changes — a subprocessor added, removed, or BAA status moved — we update this page first, then propagate to BAA §3.3, Privacy Policy §8, and the BAA template. Material additions or removals get a 30-day advance notice by email to facility administrators. The most-recent effective date is at the bottom of this page.
Effective date: July 17, 2026 (updated — removed Lago, integration never activated, zero data transferred) · Questions: privacy@tinyguard.co
Elder-care document codes (TG-*-E-*) denote the elder contract set, drafted on first elder engagement (elder onboarding deferred).