This page lists the third-party sub-processors that MYIA engages to provide the Heal service, as referenced in our Privacy Policy and Data Processing Agreement. We impose data-protection terms substantially equivalent to our DPA on each sub-processor.
Current sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and hosting | EU / US |
| Microsoft Azure | Cloud infrastructure and hosting | EU / US |
| Vercel | Frontend (website) hosting | US |
| HubSpot | Customer relationship management (CRM) | EU / US |
| Sentry | Crash and error reporting | EU |
| Better Stack | Backend logging | EU |
| Clerk | Authentication and user management | US |
| Anthropic | Large language model (AI) inference | US |
| Azure OpenAI | Large language model (AI) inference | EU / US |
| Langfuse | LLM observability and tracing | EU |
Where a sub-processor is located outside the European Economic Area, we rely on a valid transfer mechanism under Chapter V GDPR (Standard Contractual Clauses or, where applicable, the EU–U.S. Data Privacy Framework), as described in our Privacy Policy.
Not a sub-processor: usage analytics
For transparency: within the Heal application we use Aptabase (operated by Sumbit Labs Limited, Dublin, Ireland; EU-region data hosted in Germany) for in-app product-usage analytics. Aptabase receives only anonymous, aggregate usage events (feature used, application version, operating system) — no account identifiers, contact details, or Customer Content. IP address and user-agent are used transiently, server-side, to derive a 24-hour-rotating salted hash; the raw IP address is not stored. Aptabase therefore processes no Customer Personal Data and acts as an independent controller of anonymous data, not as an Article 28 sub-processor in the Heal service chain. It is listed here for transparency only and is not part of the customer-DPA sub-processor authorisation above. Retention is up to 5 years. See our Privacy Policy for details.
Changes
We will give at least 30 days' notice of any new or replacement sub-processor, and Customers may object on reasonable, documented data-protection grounds, as set out in the Data Processing Agreement. For questions, contact us at privacy@heal.dev.