Subprocessors
Last updated: September 14, 2026
Ralt Health uses the subprocessors listed below to operate the website, the free website scan, and the Rounds and Census tenant products. Practice customers subject to HIPAA can request a Business Associate Agreement as part of any engagement where Ralt Health may create, receive, maintain or transmit Protected Health Information on behalf of the customer. Where a subprocessor supports BAAs for their service tier, we execute one before that subprocessor is involved in handling customer data.
Two things about the retention column, because a procurement review depends on the difference. Where we set the period, it is stated exactly and it is enforced in the database rather than by intention. Where the period belongs to the vendor’s own platform and we have not configured it, the cell says that instead of naming a number we do not control.
Website and the free scan
These support the marketing website at ralthealth.com and the free website scan on it. No Protected Health Information passes through either; our Privacy Policy asks visitors not to submit it through the contact form.
| Subprocessor | Purpose | Data handled | Location | Retention | Deletion | BAA available |
|---|---|---|---|---|---|---|
| Cloudflare, Inc. | Hosting (Cloudflare Pages), DNS, CDN, web analytics | Requests for public pages. No account, no customer records | USA | Nothing of yours is stored by us here. Edge request logs follow Cloudflare's own platform retention, which we do not configure. Our own log lines record no email address, no IP address and no browser user agent: those fields were removed on 21 September 2026 | Not applicable: no customer record is held | Yes |
| DigitalOcean, LLC | App Platform, running the free website scan service the homepage widget calls | The URL a visitor submits, their requesting address and country, the referrer, and the time and result of the scan | USA | The requesting address is deleted 90 days after the scan, by a scheduled database job and on every write. The URL, country, referrer, time and result have no deletion date yet | On request, by email, for any scan record | Not required |
| Resend, Inc. | Notification email for the contact form and the free scan, sent from notifications.ralthealth.com to our own inbox | What you put in the form, and the recipient address | USA | Message logs follow Resend's platform retention, which we do not configure. The notification itself lands in our inbox and is kept until deleted | On request, by email | Yes |
| Calendly, LLC | Appointment scheduling | Name, email and the meeting you book | USA | Kept in Calendly until we delete it. No automatic expiry is configured | On request, by email | Not required |
| Google LLC (PageSpeed Insights API) | Public-URL audit tool: fetches accessibility and performance scores for a URL the visitor provides | The public URL only. Your address is never sent to Google | USA | We store nothing at Google. Google's own retention for API calls follows its terms | Not applicable: no customer record is held | Not required |
Rounds and Census
These support the tenant products: Rounds for a practice, Census for an organization. Where a subprocessor is BAA-eligible, the BAA is executed before production data flows. Rounds sends nothing to an AI provider. A practice admin can issue a read-only token that lets the practice’s own AI assistant read its own data; that traffic runs under the practice’s account with its own provider, not through ours.
| Subprocessor | Purpose | Data handled | Location | Retention | Deletion | BAA available |
|---|---|---|---|---|---|---|
| Vercel, Inc. | Application hosting for the Rounds and Census surfaces | Requests and build artifacts. The database is not here | USA | No customer database is held at Vercel. Build and request logs follow Vercel's platform retention, which we do not configure | Not applicable: no customer record is held | Yes |
| Supabase, Inc. | Tenant Postgres database, authentication, realtime | Tenant records, users, member roster and identity, provisioning records, scan results and findings | USA | Kept for the life of the engagement or licence. There is no automatic expiry: see Customer data below | On request, as a supervised manual database operation. See Customer data below | Yes |
| Microsoft Corporation | Microsoft Entra (single sign-on) and Microsoft Graph (mail, calendar, Teams integrations) | Sign-in identity, and the mail, calendar or Teams data a connected account grants | USA | Held for the life of the connection. Revoking the connection stops further access | On disconnect, or on request | Yes |
| Functional Software, Inc. d/b/a Sentry | Error monitoring and performance telemetry | Stack traces and request metadata, with sensitive fields scrubbed server-side before transmission | USA | Event retention follows our Sentry plan's window, which is the vendor's default and not configured by us | On request, by email | Yes |
| Resend, Inc. | Transactional email (magic-link sign-in, admin invites) | Recipient email and message content | USA | Message logs follow Resend's platform retention, which we do not configure | On request, by email | Yes |
Data platform
The engine reads public data. This is where that public data is archived, and no customer or practice data is stored in it.
| Subprocessor | Purpose | Data handled | Location | Retention | Deletion | BAA available |
|---|---|---|---|---|---|---|
| Cloudflare, Inc. (R2 object storage) | Archive of the public payer-transparency and reference files the engine reads | Public source files published by payers and government agencies. No customer data and no practice data | USA | Kept indefinitely as a dated archive: the point of it is that a figure can be traced to the file it came from at the time of capture | Not applicable: no customer record is held | Yes |
Customer data: what we keep and for how long
The free website scan. Each scan records the URL you entered, the requesting address and the country it came from, the referrer, and the time and result. The requesting address is deleted 90 days after the scan. That is enforced, not promised: a scheduled database job runs daily and the insert path purges on every write. The rest of the record has no deletion date yet, and until it does we would rather say so than publish a number with no policy behind it. Ask and we will delete yours.
Rounds tenant data. Operational records are kept for the life of the engagement, and there is no automatic expiry. Appointments and billables are deliberately append-only: a cancellation is a status change and not a deleted row, and the database enforces it with a trigger so that the audit trail survives even a compromised application role. The consequence is the honest one to state here: deleting practice data, for an erasure request or an offboarding, is a supervised manual database operation rather than a button in the product, and we do that on request. The written step-by-step for that operation is not yet published; when it is, it will be named on this page.
Census tenant data.An organization’s tenant record, its users, its member roster and member identity, its provisioning records and its scan results are kept for the life of the licence, with no automatic expiry, and are deleted on request by the same supervised operation. One control is worth naming because it is stronger than a retention period: per-member findings are not readable by the organization at all today. The table holding them has row-level security enabled and no read policy of any kind, so no authenticated caller reaches a row however the application is written, and a gate in our build fails if that absence is ever quietly filled in. That hold stays until the question of what an organization may see about its own members is settled in writing.
Changes to this list
This page is the canonical list, and it is updated before a new subprocessor begins handling customer data, not after. For customers under a signed Master Services Agreement we give at least 30 days’ written notice before adding or replacing a subprocessor that will handle customer data, so that there is time to raise an objection, and we give notice as soon as we practically can where a change is forced on us by a vendor. Removing a subprocessor, or a change that does not touch customer data, is reflected here without separate notice. To be told directly when this page changes, email us and ask to be added to the list.
Contact
Questions about our subprocessors, or a deletion request? Email us at privacy@ralthealth.com.