Subprocessors

Last updated: April 17, 2026

Ralt Health uses the subprocessors listed below to operate the website and the Ralt Health Dashboard product. Practice customers subject to HIPAA can request a Business Associate Agreement (BAA) as part of any engagement where Ralt Health may create, receive, maintain, or transmit Protected Health Information on behalf of the customer. Where a subprocessor supports BAAs for their service tier, we execute them before that subprocessor is involved in handling customer data.

Website (ralthealth.com)

These subprocessors support the marketing website only. No Protected Health Information passes through the website; our Privacy Policy explicitly requests that visitors not submit PHI through contact forms.

SubprocessorPurposeData handledLocationBAA available
Cloudflare, Inc.Hosting (Cloudflare Pages), DNS, CDN, web analyticsAnonymous web analytics (pageviews, approximate region, device class). No cookies, no fingerprinting.USA (edge network global)Yes
Calendly, LLCAppointment schedulingName, email, appointment time selectedUSANot required
Web3FormsContact form backend + free-audit-tool submission loggingContact form: name, email, phone, practice name, free-text message. Audit tool: URL entered, IP address, IP-derived location (country, region, city, postal code), user agent, referrer, timestamp.USANot required
Google LLC (PageSpeed Insights API)Public-URL audit tool — fetches accessibility and performance scores for a URL the visitor providesThe URL submitted by the visitor. No personal data transmitted to Google.USANot required

Ralt Health Dashboard

These subprocessors support the Ralt Health practice performance dashboard offered to customers. The product is currently in a no-PHI v1: customer data includes operational signals (appointment flow, billable events with anonymous codes) but not names, dates of birth, medical record numbers, or clinical detail. Where a subprocessor is BAA-eligible, BAAs are executed before production data flows.

SubprocessorPurposeData handledLocationBAA available
Vercel, Inc.Dashboard hosting (Next.js runtime, edge functions)Dashboard session cookies, server logsUSAYes
Supabase, Inc.Dashboard Postgres database, authentication, realtimePer-practice operational data (appointments, billable events — no PHI in v1)USAYes
Microsoft CorporationMicrosoft Entra (SSO auth) and Microsoft Graph (Mail, Calendar, Teams integrations)User identity tokens, Graph API payloads as opted into by the practiceUSAYes
Anthropic, PBCAI features (read-only agent interface in v1)Structured queries and derived summaries; no PHI transmitted in v1USAYes
Functional Software, Inc. d/b/a SentryError monitoring and performance telemetryStack traces, request metadata; sensitive fields scrubbed server-side before transmissionUSAYes
Resend, Inc.Transactional email (magic-link sign-in, admin invites)Recipient email, message contentUSAYes

Changes

We will update this page before materially changing our subprocessor roster. Customers with signed Master Services Agreements will receive direct notice consistent with those agreements.

Contact

Questions about our subprocessors? Email us at contact@ralthealth.com.