Subprocessor and service-provider list
About this document
| Field | Value |
|---|---|
| Version | 1.2 |
| Effective date | 1 September 2026 |
| Publication date | 1 September 2026 |
| Last reviewed | 24 August 2026 |
| Status | Approved public document |
Version history
| Version | Effective date | Change summary | How this version applies |
|---|---|---|---|
1.2 | 1 September 2026 | Replaced Resend and OneSignal with Customer.io for email and mobile push notifications | The provider changes after the Institution notice period. The purposes, user choices and rights stay the same |
1.1 | 12 August 2026 | Plain-language copy edit | No provider or processing change; Institution notice and objection terms remain unchanged |
1.0 | 1 August 2026 | Initial public version | Available publicly; Institution Customers receive notice and authorise changes as provided by their applicable DPA |
1. How to read this list
A subprocessor follows Alessia's instructions when it processes personal information to provide part of the Service. Some payment providers and app stores instead act as independent controllers for their own transaction, fraud, store-account or legal purposes. A provider's inclusion in this list does not mean that every customer uses every optional feature.
This is Alessia's authoritative public register of routine technology providers that process personal information. Other public policies describe providers by function and link here for their current identities and material processing facts.
A service that handles only Alessia-authored static content and does not receive personal information is not listed as a subprocessor. Professional advisers, courts, regulators and law-enforcement bodies are not routine technology providers and are described by category in the Privacy Notice.
2. Subprocessors
| Provider and legal entity | Purpose | Personal information | Processing and storage locations | Transfer safeguards | Retention and material terms | Optional? |
|---|---|---|---|---|---|---|
| Microsoft Azure - Microsoft Ireland Operations Limited (MIOL) | Cloud hosting, database, object storage, networking, backup and infrastructure | Account holders, Institution contacts, supervisors and assessors; account, authentication, portfolio and other content stored for the Service; prohibited information only if submitted contrary to policy | Primary application databases and object storage are hosted in UK South, or another Azure region agreed with an Institution. Microsoft personnel and approved subprocessors may have restricted, logged access from other countries where necessary for support, security and service operations | Microsoft Customer Agreement and the applicable Microsoft Products and Services Data Protection Addendum, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with applicable adequacy arrangements | Microsoft product terms and Alessia's configured retention; consumer rolling backups up to 35 days and Institution backup periods as stated in the applicable Order Document, subject to mandatory deletion law | No |
| Webflow, Inc., 398 11th Street, Floor 2, San Francisco, California 94103, USA | Hosting and delivery of the Alessia marketing website | Website connection and interaction information, including IP address, browser and operating-system details, and content Alessia publishes through Webflow. Contact-form content is forwarded directly to Alessia by email and is not retained as a stored Webflow form submission | Webflow stores Customer and End User information in the USA and uses subprocessors in the USA and other locations identified on its current subprocessor list | Webflow's DPA, including the EU Standard Contractual Clauses, UK International Data Transfer Addendum and applicable Data Privacy Framework participation | Customer Personal Information is retained during Alessia's agreement with Webflow and deleted after termination unless applicable law prevents deletion. Technical request and security information follows Webflow's applicable service practices | No for visitors to the marketing website |
| Logto Cloud - Silverhand Inc., 2810 North Church Street, Wilmington, Delaware 19802, USA | Identity, authentication, credential and session management, token issuance and access logging | Email; name and avatar where supplied by a connected sign-in provider; Logto subject identifier, authentication events, IP/device/access records and token metadata | Alessia's EU tenant is hosted through Microsoft Azure in the selected EU region. Cloudflare provides global edge delivery and network protection and receives limited metadata such as IP addresses and request headers | EU Standard Contractual Clauses and the UK International Data Transfer Addendum under Logto's DPA | Authentication and access logs are retained for 14 days. Production identity records are retained while the account remains active unless removed. On termination, customer data is deleted or returned under Logto's DPA unless retention is legally required | No |
| PostHog Inc., 2261 Market Street #4008, San Francisco, California 94114, USA | Product onboarding, marketing measurement, product analytics, diagnostics and feature usage | Email, optional name, account/device identifiers and allowlisted usage or interaction events. Clinical, portfolio and AI content is excluded. Raw IP addresses are configured not to be retained; geolocation enrichment and session replay are disabled | PostHog Cloud EU stores analytics data in Frankfurt, Germany. Authorised personnel and subprocessors may access or process it from other countries where necessary to provide, secure and support the service under PostHog's DPA | EU Standard Contractual Clauses and the UK International Data Transfer Addendum under PostHog's DPA | Identifiable event and profile data is retained for no more than 365 days. Deletion is processed asynchronously. Product and Model Development use is disabled | Partly - marketing-site analytics requires consent; app analytics follows the consent or opt-out control applicable to the user |
| Customer.io - Peaberry Software, Inc. d/b/a Customer.io, 9450 SW Gemini Dr., Suite 43920, Beaverton, Oregon 97008-7105, USA | Transactional account, security, legal, billing and support email; optional onboarding and marketing email; registration and delivery of generic mobile push notifications | Recipient email, optional name, Alessia member public ID, Customer.io profile identifier, device or push token, platform, last-used and delivery status, minimum message content, subject, delivery, bounce, complaint and permitted marketing-click information. Clinical, patient, portfolio and AI content is excluded | Customer.io stores profile data in the region selected for Alessia's account, either its EU region based in Belgium or its US region. Customer.io and its authorised infrastructure and communications subprocessors may process in the EU and USA. Apple and Google also process device push delivery through their platform services | Customer.io's DPA, including the EU Standard Contractual Clauses and UK International Data Transfer Addendum, together with applicable EU-US Data Privacy Framework and UK Extension participation | Customer.io retains profile data for the agreement term unless Alessia deletes it sooner. Alessia deletes profiles and device tokens under the Retention Schedule and valid deletion instructions. Before processing begins, Alessia will disable open tracking, transactional link tracking, optional Customer.io AI and unapproved data integrations. Marketing links will be tracked only where permitted and disclosed. Alessia will not use the mobile SDK for in-app messages, location, screen or lifecycle tracking, or custom product events | Partly - essential service email is required; marketing email, permitted marketing-link measurement and mobile push notifications are optional |
| RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, Florida 33511, USA | Subscription and purchase-status processing, app-store and direct-web entitlement management, and subscription-management links | Alessia member/app-user identifier; product, entitlement, store, transaction and subscription identifiers; dates, price, currency, country, trial, renewal and environment data; and limited device/app technical information. Alessia does not set email or profile attributes for Apple or Google subscription tracking. Email is provided only where needed for direct-web checkout, receipts or subscription servicing. Portfolio, clinical and AI content is excluded | RevenueCat is based in the USA and its current hosting, database, monitoring, analytics and content-delivery subprocessors for this service are listed in the USA | RevenueCat's DPA, including the EU Standard Contractual Clauses and UK International Data Transfer Addendum | Subscriber records are retained while needed to manage the subscription. Following an Alessia account-deletion request, Alessia cancels direct-web renewal where it controls the subscription and invokes RevenueCat customer deletion within three days; RevenueCat states that customer deletion clears the profile and purchase history. Deleting the RevenueCat record does not itself cancel Apple, Google or Stripe-managed subscriptions, which must follow their separate cancellation route. Provider backup, archive and legal-retention exceptions may apply under the DPA. Optional advertising, attribution, analytics and data-export integrations are not used | Yes - applicable only to consumer subscriptions |
| Anthropic - Anthropic Ireland, Limited | Optional AI-assisted summaries and competency suggestions | Content selected by the user for the request, such as text, notes or a transcript; request instructions; and generated output. Patient personal data is prohibited | Customer data is stored in the USA and may be processed in selected locations in the USA, Europe, Asia and Australia | Anthropic's DPA, incorporated into its Commercial Terms, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum | Standard API inputs and outputs are deleted within 30 days. Material flagged for Usage Policy enforcement may be retained for up to two years, and associated safety-classification scores for up to seven years. Longer retention may apply where legally required. Anthropic does not use API customer content to train its models | Yes - only when the user invokes an applicable AI-assisted feature |
| AssemblyAI - AssemblyAI Inc. | Optional audio transcription | Audio selected by the user, the secure audio-file URL, transcription settings and prompts, and the resulting transcript and timing/confidence data. Patient personal data is prohibited | Audio and transcription artifacts are submitted to AssemblyAI's EU server endpoint. AssemblyAI is a US provider, and account, usage and operational information may be processed in the USA or other authorised provider locations under its DPA | AssemblyAI's DPA, including the EU Standard Contractual Clauses and UK International Data Transfer Addendum | Alessia instructs AssemblyAI to delete the transcript and linked provider artifacts immediately after Alessia successfully retrieves the result. A one-hour provider time-to-live is configured as a backstop. Provider-side deletion processing may not complete instantly, and limited metadata may remain for logging and billing or where legally required. Files submitted through the EU server or under Alessia's training opt-out are not used for model training | Yes - only when the user requests transcription |
3. Independent controllers and distribution providers
These organisations may act as independent controllers for some or all of their activities. Their own privacy notices and user or store agreements also apply.
| Provider and legal entity | Role and purpose | Information Alessia receives | Optional or applicable channel |
|---|---|---|---|
| Apple App Store - Apple Inc.; Apple Canada Inc.; Apple Services LATAM LLC; Apple Services Pte. Ltd.; iTunes K.K.; Apple Pty Limited; or Apple Distribution International Ltd., according to the user's Home Country | Apple operates the App Store and independently determines how it processes Apple Account, store-payment, subscription, refund, fraud, tax and legal-compliance information. Apple may act as agent or merchant of record under the store terms while Alessia remains responsible for the app and Service | Product and entitlement, transaction/receipt and subscription identifiers and status, price/currency/country and refund or renewal status. Alessia does not receive the user's full store-payment details | Apple App Store purchases and subscriptions only |
| Google Play - Google LLC; Google Ireland Limited; Google Commerce Limited; Google Digital Inc.; and the applicable Google Payments entity, according to the user's country and purchase terms | Google operates Google Play and independently determines how it processes Google Account, store-payment, subscription, refund, fraud, tax and legal-compliance information. The applicable Google entity may sell or act as agent for content under the regional store terms while Alessia remains responsible for the app and Service | Product and entitlement, transaction/order and subscription identifiers and status, price/currency/country and refund or renewal status. Alessia does not receive the user's full store-payment details | Google Play purchases and subscriptions only |
| Stripe Managed Payments - Sold through Link, LLC, with other applicable Stripe group entities | Merchant of record for eligible direct-web transactions and provider of checkout, payment, receipt, transaction-tax, fraud, dispute, refund and order/subscription-management functions. Alessia remains the seller and provider of the Service. Stripe acts as a processor for activities performed only on Alessia's instructions and as an independent controller where it determines its own compliance, fraud, tax, Link/account or service purposes | Purchaser email where required; product, order, transaction and subscription identifiers and status; price, currency, country, tax, refund and dispute information. Alessia does not receive full card details | Eligible direct-web purchases only; the checkout identifies the applicable merchant and terms |
4. Provider changes
Alessia will update this list when a provider is added, replaced or materially changes its role. Where a change materially affects how personal information is used, an individual's rights or a consent choice, Alessia will provide any additional notice or obtain any new consent required by law.
Institution customers authorise subprocessors under their Data Processing Addendum. Alessia will send formal notice by email to the Institution's nominated privacy and contract contacts at least 30 days before a non-urgent new or replacement subprocessor begins processing Customer Personal Data. An urgent security or continuity replacement will be notified by email as soon as reasonably possible, with an explanation. Institution objections follow the Data Processing Addendum.
Individual users can review the current position on this page at any time. The version history and the change line below record changes since publication. We announce a change through the Service or by email if this section requires notice or consent.
Version 1.2 replaces Resend and OneSignal with Customer.io for email and mobile push notifications from 1 September 2026. Customer.io will not process Institution Customer Personal Data before that date or before the applicable 30-day notice period has ended, whichever is later.
5. Contact
Questions about this list or an Institution subprocessor objection may be sent to privacy@alessiahq.com.
