Subprocessor List
Version 1.0 · Effective May 6, 2026 · Last Updated July 28, 2026
ABOUT THIS LIST
NurseKind AI, LLC ("NurseKind") acts as a Business Associate, not a Covered Entity, and uses the subprocessors below to deliver its clinical communication platform. This list covers every entity that may process personal data, FERPA-covered education records, or Protected Health Information ("PHI") on NurseKind's behalf. Regulatory basis: GDPR Art. 28(2); FERPA; HIPAA transparency best practices.
Institutional customers that have executed a Business Associate Agreement ("BAA") with NurseKind may request the full vendor-facing BAA register and copies of executed BAAs or DPAs by contacting hi@nursekindai.com.
SUBPROCESSORS
| Subprocessor | Service Provided | Data Types Processed | Country | HIPAA BAA | GDPR DPA / SCCs |
|---|---|---|---|---|---|
| Google Cloud Platform (Firebase Cloud Functions, Cloud SQL PostgreSQL 17, Vertex AI, Cloud Memorystore, Cloud Logging, Cloud Storage, Secret Manager, Cloud KMS) |
Core infrastructure, AI inference, audit logging, encryption key management | PHI (encrypted at rest); FERPA education records; operational logs | United States (us-central1) | BAA executed | Google DPA / SCCs in place |
| Firebase Authentication (Google Identity Platform) |
User authentication and identity management | Authentication PII (email address, Firebase UID) | Google-managed, multi-region — not pinned to us-central1 like the rest of the GCP footprint | BAA executed (same Google Cloud BAA) |
Google DPA / SCCs in place |
| AssemblyAI | Audio transcription of clinical assessment recordings | PHI — audio recordings and transcripts from the Clinical Recording & Assessment feature | United States | BAA executed | Standard Contractual Clauses available |
| OpenAI (Realtime API) | Voice simulation interactions (AI Patient Practice Sessions, synthetic scenarios only) | Synthetic scenario context only — no real PHI or student PII transmitted | United States | Not required (no PHI processed) | OpenAI DPA available |
| Canvas LMS / Instructure | FERPA roster sync via LTI integration | FERPA education records (student roster, course enrollment) — no PHI | United States | No BAA required (FERPA scope only) | Instructure DPA |
| Hostinger | Static website hosting (nursekindai.com); transactional email for FERPA-scope notifications | Static web assets; FERPA-scope contact email — no PHI | European Union (Lithuania) | No BAA required (no PHI hosted or processed) | Hostinger DPA / GDPR-compliant |
| Cloudflare | CDN, DDoS protection, TLS termination for nursekindai.com | Static assets only — no PHI cached or processed at the CDN layer | United States / Global edge | No BAA required (no PHI in CDN layer) | Cloudflare DPA |
| Telegram | Operational alerting (uptime notifications, system alerts) | Operational metadata only — no PHI included in alert payloads | International | No BAA required (no PHI transmitted) | N/A |
NOTES ON PHI SCOPE
- Google Cloud Platform is the primary infrastructure provider, covered by an executed Google Cloud HIPAA BAA. All PHI stored in Cloud SQL is encrypted at the column level using AES-256-GCM. Cloud Logging receives only redacted logs after PHI-sanitization middleware is applied.
- Firebase Authentication is a Google-managed service covered by the same executed Google Cloud BAA and Google DPA/SCCs as the rest of the GCP footprint, but unlike Cloud SQL and Cloud Functions it is not pinned to a single region — authentication PII (email address, Firebase UID) is not controlled to us-central1.
- AssemblyAI processes audio that may contain PHI as part of the Clinical Recording & Assessment feature. An AssemblyAI BAA is in effect. Audio is deleted by AssemblyAI after transcription per BAA terms.
- OpenAI Realtime API is restricted to synthetic AI Patient Practice Sessions scenarios. NurseKind's architecture and operational policy prohibit transmission of real patient data (ePHI) to OpenAI; the Platform technically blocks any scenario not flagged as fictional and educational from reaching this feature. No BAA is required for this use case.
- Canvas LMS / Instructure integration is FERPA-scoped only. No PHI flows through the LTI integration. The integration syncs course rosters for access provisioning purposes only.
- Hostinger hosts static web assets. NurseKind does not route PHI-bearing traffic through Hostinger. Transactional email is limited to FERPA-scope notifications. A software gate blocks any PHI-bearing email until an appropriate BAA is in place. Assessment PDFs are delivered in-app only.
UPDATE NOTIFICATION POLICY
NurseKind AI will provide 30 days' advance notice before adding any new subprocessor that will materially change the processing of PHI or FERPA-covered education records. Notice will be provided to institutional customers via:
- Email notification to the institution's designated privacy contact
- An update to this public disclosure page
Institutions that object to a proposed new subprocessor should contact NurseKind AI at hi@nursekindai.com within 14 days of receiving notice.
REQUESTING ADDITIONAL INFORMATION
Institutional customers may request:
- The full vendor-facing BAA register (internal, non-public)
- Copies of executed BAAs or DPAs for any listed subprocessor
- Data flow diagrams specific to their institution's deployment
Contact: hi@nursekindai.com.