Legal · Sub-processor register
Sub-processor register
Last updated 2026-07-12. Conversico Ltd will notify practices at least 30 days before adding or replacing a sub-processor so they can object before changes take effect, per the customer Data Processing Addendum.
Core sub-processors
These vendors are the expected launch sub-processors for Conversico customer workspaces. Each live workspace must have Article 28 processing terms and, where applicable, a UK International Data Transfer Addendum or equivalent transfer mechanism recorded before live patient traffic is enabled.
| Vendor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Twilio Ireland Ltd | Telephony, SMS, call-recording capture | EEA (Ireland) with UK fallback | Required where applicable: UK Addendum + SCCs |
| ElevenLabs Ltd | Voice synthesis + conversational-AI inference | United States (no-PII transcript controls applied) | Required: UK Addendum + SCCs |
| Anthropic, PBC | Claude LLM inference (no-training contractual control) | United States | Required: UK Addendum + SCCs |
| Microsoft Ireland Operations Ltd | Azure compute, storage, secrets, monitoring (UK South) | United Kingdom | Within UK / adequacy basis recorded in launch pack |
| Vercel Inc. | Frontend hosting + edge delivery for app.conversico.com | Global edge with London (lhr1) origin | Required where applicable: UK Addendum + SCCs |
| Clerk Inc. | Workforce identity (practice users only; not patient data) | United States | Required: UK Addendum + SCCs |
| Stripe Payments Europe Ltd | Billing + card processing (practice subscriptions only) | EEA (Ireland) | Adequacy basis recorded in launch pack |
| Functional Software, Inc. (Sentry) | Error monitoring + replay (PII scrubbed before transmission) | United States | Required: UK Addendum + SCCs |
| PostHog Inc. | Product analytics + rollout controls (EU instance) | European Union (Frankfurt) | EEA / adequacy basis recorded in launch pack |
| Upstash Inc. | Redis Serverless cache, rate-limit state, live-feed pub/sub, worker heartbeat state, and Copilot staged-write TTLs under ADR-012 | European Union (Frankfurt) | Required: UK Addendum + SCCs |
| ilert GmbH | On-call paging + incident notifications | European Union (Frankfurt) | EEA / adequacy basis recorded before engagement |
Optional sub-processors
These vendors are engaged only when a feature requiring them is enabled for a specific practice. We document them here for transparency even when not in use for every customer.
- Plain Systems Ltd — Customer support inbox; engaged from Cohort A onwards when the practice opts in to the in-app support channel.
- Instatus Inc. — Public status page subscriber list; processes practice email addresses only when a practice administrator subscribes to incident notifications.
- Braintrust Data — AI evaluation pipeline; used only after trace-redaction and no-PII controls are validated for production scoring.
- Resend Inc. — Transactional email primary; engaged only when the email channel is enabled for a practice and after DPA + UK Addendum execution.
- ActiveCampaign LLC (Postmark) — Transactional email secondary provider for high-deliverability paths (verification links, cancellations); engaged only when those routes are enabled and after DPA + UK Addendum.
- 360dialog GmbH — WhatsApp Business BSP; engaged when a practice opts in to the WhatsApp channel and after EU GDPR processor terms are complete.
How transfers work
Where a sub-processor must process personal data outside the UK, each customer launch pack must record a UK-approved transfer mechanism — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation — supported by a transfer risk assessment for the workspace. The customer Data Processing Addendum is completed during onboarding and sets out the full mechanism for each transfer used by the live service.
Notice of changes
Material changes to this register are communicated via:
- A revision to this page (with the "Last updated" date incremented), and
- An email to the practice owner's registered address at least 30 days before the change takes effect.
Practices may object to a proposed change by emailing the data protection contact named in the privacy policy.