Sub-processors
Public, up-to-date list of third parties that process data on behalf of Sleep Health Services. This page exists for procurement, compliance, and privacy review teams.
Last updated: February 24, 2026
Active
Planned
Dormant
Active(5)
Stripe
Active
Payment processing
Data: Email, payment token (no PAN/CVV stored at SHS)
Region: US
Legal framework: PCI DSS Level 1; DPA available
HeyGen
Active
AI video generation for bilingual sleep education
Data: Topic script text only — no user data leaves SHS
Region: US
Legal framework: No PHI processed; commercial license
OpenAI (via Emergent Universal Key)
Active
AI tagging (GPT-4o-mini) + SHS-AI chat assistant
Data: Topic content + user chat messages
Region: US
Legal framework: OpenAI Enterprise data-handling policy; opt-out of training
Resend
Active
Transactional email (receipts, verifications)
Data: Email address, name, transactional body
Region: US / EU mirror available
Legal framework: GDPR-aligned DPA
MongoDB Atlas (platform-managed cluster)
Active
Primary application database
Data: All user-facing application data
Region: US (default)
Legal framework: Disk-level encryption; field-level encryption planned for any future PHI
Planned(2)
Cloudflare R2
Planned
Long-term mirror of AI-generated educational videos
Data: Generated videos only (no user data)
Region: US / EU configurable
Legal framework: DPA available; activation pending credentials
Sentry
Planned
Error tracking + performance telemetry
Data: Stack traces with PHI-scrubbing rules applied
Region: US
Legal framework: DPA available; activation pending DSN
Dormant(1)
Voyage AI
Dormant
Multilingual embedding model (alternative to OpenAI)
Data: Topic text only
Region: US
Legal framework: Activation requires key + DPA review
Designated SHS officers
Privacy Officer: privacy@sleephealthservices.org
Security Officer: security@sleephealthservices.org
Data-subject rights requests: dsr@sleephealthservices.org
For HIPAA Business Associate Agreements, GDPR Data Processing Agreements, or enterprise compliance documentation, contact security@sleephealthservices.org.
This page is kept in sync with /app/memory/COMPLIANCE.md (the canonical source). Any sub-processor change is announced at least 30 days in advance to enterprise customers with a signed DPA.
