Patient Care Circle Back to home
Transparency

Subprocessors

Current as of 1 October 2026

To operate Patient Care Circle we rely on a small number of vetted third-party services ("subprocessors"). We keep the list short on purpose and route document bytes through our own servers rather than exposing storage directly. The table below shows what each provider does and the data it processes.

SubprocessorPurposeData processedRegionAgreement
NeonManaged PostgreSQL database hostingAccount & consent records, document metadata, encrypted message bodiesUnited StatesSigned
PSS Document Service → DigitalOcean SpacesDocument file storage (bytes routed through our server)Uploaded document contentsUnited StatesExecuted
Amazon SES (AWS)Transactional email deliveryRecipient email addresses & non-clinical notifications (no PHI in message bodies)United StatesExecuted (AWS BAA)
StripeSubscription billing & paymentsBilling/account data only — never PHIUnited StatesNot required

Business Associate Agreements

Every subprocessor that may handle protected health information maintains an executed Business Associate Agreement (BAA) with us before any such data flows to them. Stripe handles billing data only and never receives PHI, so no BAA is required there. See our Business Associate Agreement page for details.

Changes

We'll update this page when we add or replace a subprocessor. To be notified of changes, or to ask a question, contact privacy@patientcarecircle.com.