Legal

    Subprocessors

    The core third-party service providers QR Rx uses to deliver the platform, where they sit in the system, and the data boundary at each layer.

    Trust registry 2026-09-01.1 · Content reconciled September 1, 2026 · Evidence reviewed May 12, 2026 · Review due September 9, 2026

    A subprocessor is a third-party company that QR Rx engages to help operate the platform. This page is the core service-provider registry for information governed by our Business Associate Agreement or our Privacy Policy. Optional systems a clinic connects, such as a calendar or practice-management service, are governed by the clinic's own connection and contract. If you are a healthcare provider doing procurement, share this registry with your privacy and compliance team.

    §1

    PHI-authorized services

    Each of the following providers may, in the course of operating the platform, come into contact with protected health information. Each must have a documented HIPAA-eligible contract posture, and the exact agreement status is shown below.

    Render, Inc.

    Purpose
    Application hosting and Postgres database infrastructure for the QR Rx application and its data plane.
    Region
    United States, HIPAA-eligible workspace
    Data accessed
    Application data, including PHI processed on behalf of customers.
    BAA
    Signed BAA.

    Amazon Web Services, Inc. S3 protected storage

    Purpose
    Object storage for clinic branding, provider uploads, patient-submitted recovery photos, and provider data snapshots, using server-side encryption at rest.
    Region
    United States, us-east region
    Data accessed
    Clinic branding, provider uploads, patient-submitted recovery photos, and provider data snapshots.
    BAA
    Signed BAA. Dedicated customer-managed KMS key management is not represented as active until deployment is complete.

    Paubox, Inc.

    Purpose
    Transactional email delivery for care plans, recovery reminders, password resets, team invitations, and outcome digests.
    Region
    Vendor-managed service under the recorded BAA
    Data accessed
    Recipient email address, patient first name, procedure type, secure care-plan link, and access PIN when included in the message.
    BAA
    Signed BAA.

    Telnyx LLC

    Purpose
    SMS delivery for care-plan links, recovery check-ins, and unscanned-plan nudges, with delivery-receipt webhooks.
    Region
    Vendor-managed service under the recorded HIPAA contract posture
    Data accessed
    Recipient phone number, patient first name, clinic name, secure care-plan link, and access PIN when included in the message.
    BAA
    HIPAA-eligible service terms are in place. Separate written confirmation of BAA status remains open, so QR Rx does not represent a signed BAA here.

    Google LLC Cloud Translation API

    Purpose
    Care-plan translation through QR Rx's HIPAA-authorized Google Cloud configuration. Requests are limited to care-plan copy and do not include patient identifiers.
    Region
    Google Cloud global service endpoint
    Data accessed
    Procedure type, instructions, milestone descriptions, medication names, and medication directions. Patient identifiers are not included.
    BAA
    Signed BAA.
    §2

    Non-PHI subprocessors

    The following subprocessors support specific platform features but are not authorized for Protected Health Information. These flows are designed to exclude PHI.

    Anthropic, PBC

    Purpose
    Restricted language-model assistance for administrative tools and explicitly governed clinical AI flows. Patient-specific calls require the deployment clinical AI policy gate. The default configuration fails closed.
    Region
    Vendor-managed service. PHI is not authorized.
    Data accessed
    Non-PHI administrative content. A patient-specific flow may be enabled only after the deployment owner documents an applicable BAA or a HIPAA-compliant de-identification basis for that exact flow. Direct-identifier removal is defense in depth and is not itself represented as formal de-identification.
    BAA
    No Anthropic BAA is recorded. Anthropic is not authorized for PHI. Patient-specific calls remain disabled unless the separate documented policy requirement is satisfied.

    Cloudflare, Inc. Turnstile

    Purpose
    Bot-protection challenges on public forms and patient verification surfaces.
    Region
    Global edge network
    Data accessed
    Challenge tokens and standard connection metadata. QR Rx does not send form contents or PHI to Turnstile.
    BAA
    Not authorized for PHI.

    Google LLC Sign-In

    Purpose
    Optional OAuth identity provider for provider-portal sign-in.
    Region
    Google global identity service
    Data accessed
    Email address, full name, and profile-picture URL from the standard Google OAuth scope. No PHI is sent for sign-in.
    BAA
    Not authorized for PHI. Used only for identity.

    Firecrawl, Inc.

    Purpose
    Public website discovery for admin-created clinic demos and branding intake.
    Region
    Vendor-managed service. Public website content only.
    Data accessed
    Public clinic website URLs and publicly available website content. Patient data and PHI are not authorized for this flow.
    BAA
    Not authorized for PHI. Intake is limited to public clinic website content.

    Stripe, Inc.

    Purpose
    Provider subscription billing, payment processing, and the customer billing portal. Patients are not billed by QR Rx.
    Region
    Vendor-managed service. Provider billing data only.
    Data accessed
    Provider billing contact, payment method, and subscription status. No patient information is sent to Stripe.
    BAA
    Not authorized for PHI. Stripe is limited to provider-account billing data.

    Google LLC Google Ads

    Purpose
    Conversion measurement on public marketing and provider-acquisition pages. The tag is disabled before loading on qrrx.care and patient care-plan routes.
    Region
    Global
    Data accessed
    Marketing-page interactions and conversion events. No patient identifiers, care-plan content, symptoms, photos, or other PHI are sent.
    BAA
    Not authorized for PHI. Google Ads is excluded from patient PHI surfaces.

    Functional Software, Inc. Sentry

    Purpose
    Application error monitoring. Session replay, tracing, logs, request bodies, cookies, and default PII collection are disabled, and events pass through PHI and credential scrubbing before transmission.
    Region
    Vendor-managed service. Scrubbed technical data only.
    Data accessed
    Scrubbed technical error metadata and an internal user ID when available. Patient names, contact details, tokens, request bodies, care-plan content, and session recordings are not authorized.
    BAA
    Not authorized for PHI under the configured data flow.
    §3

    Notification of changes

    Business Associate will provide at least 30 days of advance notice before enabling a new subcontractor to access PHI, except when an emergency replacement is reasonably necessary to protect security or continuity. Covered Entities may raise a reasonable data-protection objection during that period. The governing terms are in the BAA at qrrx.io/baa. The current core registry lives on this page.

    §4

    Contact us

    For procurement, security review, or compliance questions about any subprocessor on this list, email dnelson@qrrx.io with the subject line "Subprocessor Review."