Vendor Disclosure
Subprocessor List
Vendor and subprocessor list for hosting, AI processing, telephony transport, payment, email, and referral workflows.
Last updated May 31, 2026
Status: Draft for legal and security review Document key: subprocessorList Version: 2026-05-31
This list identifies vendors that may support Happy Light AI. Counsel and security reviewers should confirm which vendors are active in production and whether each vendor is authorized for ePHI workloads.
| Vendor | Purpose | Data Categories | PHI Exposure Intended? | Contract / BAA Status To Verify |
|---|---|---|---|---|
| Google Cloud | Hosting, compute, private storage, logging, secrets, infrastructure | Tenant config, call metadata, recordings, logs, secrets | Yes, for covered workloads | Verify GCP BAA and covered services |
| OpenAI | AI reasoning, realtime voice, transcription or summarization where configured | Call content, summaries, voice prompts | Possible, depending on approved workload | OpenAI BAA executed and ZDR activated for eligible API workloads; verify each enabled workload remains eligible before routing ePHI |
| Telnyx | Telephony, phone numbers, real-time voice transport, call routing | Phone metadata, call audio in transit, phone numbers | Transmission-only conduit intended; no persistent PHI storage intended | Review HIPAA conduit exception posture. If Telnyx is later used to persist recordings, transcripts, or ePHI beyond transient transmission, reassess BAA or HIPAA-eligible service requirements before enabling that feature |
| Stripe | Checkout, subscriptions, invoices, payment method vaulting | Billing metadata, customer identifiers | No PHI intended | Payment processor terms |
| PromoteKit | Referral attribution and partner portal | Referral identifiers, partner profile, referred account metadata | No PHI intended | Partner platform terms |
| PayPal | Referral or partner payout rail where enabled | Partner payout profile, email, payout metadata | No PHI intended | PayPal legal agreements and payout fees/availability to verify |
| Wise | Referral or partner payout rail where enabled | Partner payout profile, payout metadata | No PHI intended | Wise legal agreements and payout fees/availability to verify |
| Paubox | Secure clinical email | Authorized clinic recipient email addresses, call summary notifications, transcript sections, secure recording links, dashboard call-detail links | Yes, for authorized clinical email workflows | Paubox BAA complete; verify production sending configuration and recipient authorization |
| Resend | Emergency/fallback transactional email infrastructure | Email address, notification content | No active production clinical email use intended | Keep disabled for clinical PHI email unless separately approved |
| Open Dental | PMS integration through official API | Scheduling, appointment, patient matching context | Clinic-controlled PHI source | Governed by clinic's Open Dental relationship and API authorization |
Notes
- Do not send PHI to referral, marketing, or public analytics tools.
- Do not expose raw Open Dental CustomerKeys to subprocessors except through approved backend secret access.
- Keep persistent recordings, transcripts, and ePHI storage in approved GCP-controlled systems rather than Telnyx, unless counsel approves a different HIPAA-eligible configuration.
- Production clinical call summary emails should use Paubox from
noreply@mail.happylight.techwith Reply-To routed to the appropriatehappylight.techGoogle Workspace inbox. - Maintain a change process for adding, removing, or materially changing subprocessors.
- Consider publishing a customer-facing subprocessor page after counsel review.
