Subprocessor List
Version 1.0 · Effective May 6, 2026 · Last Updated July 28, 2026
ABOUT THIS LIST
NurseKind AI, LLC ("NurseKind") acts as a Business Associate, not a Covered Entity, and uses the subprocessors below to deliver its clinical communication platform. This list covers every entity that may process personal data, FERPA-covered education records, or Protected Health Information ("PHI") on NurseKind's behalf. Regulatory basis: GDPR Art. 28(2); FERPA; HIPAA transparency best practices.
Institutional customers that have executed a Business Associate Agreement ("BAA") with NurseKind may request the full vendor-facing BAA register and copies of executed BAAs or DPAs by contacting hi@nursekindai.com.
SUBPROCESSORS
| Subprocessor | Service Provided | Data Types Processed | Country | HIPAA BAA | GDPR DPA / SCCs |
|---|---|---|---|---|---|
| Google Cloud Platform (Firebase Cloud Functions, Cloud SQL PostgreSQL 17, Vertex AI, Cloud Memorystore, Cloud Logging, Cloud Storage, Secret Manager, Cloud KMS) |
Core infrastructure, AI inference, audit logging, encryption key management | PHI (encrypted at rest); FERPA education records; operational logs | United States (us-central1) | BAA executed | Google DPA / SCCs in place |
| Firebase Authentication (Google Identity Platform) |
User authentication and identity management | Authentication PII (email address, Firebase UID) | Google-managed, multi-region — not pinned to us-central1 like the rest of the GCP footprint | BAA executed (same Google Cloud BAA) |
Google DPA / SCCs in place |
| AssemblyAI | Audio transcription of clinical assessment recordings | PHI — audio recordings and transcripts from the Clinical Recording & Assessment feature | United States | BAA executed | Standard Contractual Clauses available |
| OpenAI (Realtime API) | Voice simulation interactions (AI Patient Practice Sessions, synthetic scenarios only) | Synthetic scenario context only — no real PHI or student PII transmitted | United States | Not required (no PHI processed) | OpenAI DPA available |
| Canvas LMS / Instructure | FERPA roster sync via LTI integration | FERPA education records (student roster, course enrollment) — no PHI | United States | No BAA required (FERPA scope only) | Instructure DPA |
| Hostinger | Transactional email for FERPA-scope notifications | FERPA-scope contact email — no PHI | European Union (Lithuania) | No BAA required (no PHI hosted or processed) | Hostinger DPA / GDPR-compliant |
| Cloudflare | Static website hosting (nursekindai.com), CDN, DDoS protection, TLS termination | Static web assets only — no PHI cached or processed at the CDN/hosting layer | United States / Global edge | No BAA required (no PHI in CDN/hosting layer) | Cloudflare DPA |
| Telegram | Operational alerting (uptime notifications, system alerts) | Operational metadata only — no PHI included in alert payloads | International | No BAA required (no PHI transmitted) | N/A |
NOTES ON PHI SCOPE
- Google Cloud Platform is the primary infrastructure provider, covered by an executed Google Cloud HIPAA BAA. All PHI stored in Cloud SQL is encrypted at the column level using AES-256-GCM. Cloud Logging receives only redacted logs after PHI-sanitization middleware is applied.
- Firebase Authentication is a Google-managed service covered by the same executed Google Cloud BAA and Google DPA/SCCs as the rest of the GCP footprint, but unlike Cloud SQL and Cloud Functions it is not pinned to a single region — authentication PII (email address, Firebase UID) is not controlled to us-central1.
- AssemblyAI processes audio that may contain PHI as part of the Clinical Recording & Assessment feature. An AssemblyAI BAA is in effect. Audio is deleted by AssemblyAI after transcription per BAA terms.
- OpenAI Realtime API is restricted to synthetic AI Patient Practice Sessions scenarios. NurseKind's architecture and operational policy prohibit transmission of real patient data (ePHI) to OpenAI; the Platform technically blocks any scenario not flagged as fictional and educational from reaching this feature. No BAA is required for this use case.
- Canvas LMS / Instructure integration is FERPA-scoped only. No PHI flows through the LTI integration. The integration syncs course rosters for access provisioning purposes only.
- Hostinger provides transactional email only. NurseKind does not route PHI-bearing traffic through Hostinger. Email is limited to FERPA-scope notifications. A software gate blocks any PHI-bearing email until an appropriate BAA is in place. Assessment PDFs are delivered in-app only.
- Cloudflare hosts the static website (nursekindai.com) in addition to providing CDN, DDoS protection, and TLS termination. NurseKind does not route PHI-bearing traffic through Cloudflare; the static site serves only public marketing and unauthenticated content.
UPDATE NOTIFICATION POLICY
NurseKind AI will provide 30 days' advance notice before adding any new subprocessor that will materially change the processing of PHI or FERPA-covered education records. Notice will be provided to institutional customers via:
- Email notification to the institution's designated privacy contact
- An update to this public disclosure page
Institutions that object to a proposed new subprocessor should contact NurseKind AI at hi@nursekindai.com within 14 days of receiving notice.
REQUESTING ADDITIONAL INFORMATION
Institutional customers may request:
- The full vendor-facing BAA register (internal, non-public)
- Copies of executed BAAs or DPAs for any listed subprocessor
- Data flow diagrams specific to their institution's deployment
Contact: hi@nursekindai.com.