Subprocessor List
A provider is not automatically active merely because its integration exists in the code. The deployment owner must confirm enabled services, region and contract before launch.
Last updated 24 August 2026
Public-launch gate: this product-aligned draft must be reviewed and approved by qualified privacy, healthcare and commercial counsel for each supported jurisdiction before CareFlow accepts real healthcare data or payment under these terms. It is not presented as legal advice or a signed customer agreement.
Core or conditional providers
MongoDB — tenant application database when MONGODB_URI is configured; deployment region and backup settings are selected by the operator.
Cloudinary — organisation image/logo storage when Cloudinary credentials are configured.
Razorpay — order, payment, refund and dispute processing for online subscriptions.
Resend — transactional account, payment and support email when configured.
Google Gemini — optional My Care AI provider when a Gemini key is configured; otherwise CareFlow uses its local rule-based assistant.
Hosting and DNS/CDN provider — deployment-specific and must be named in the customer agreement or production register before real data is accepted.
What is not implied
Listing a provider does not certify CareFlow under HIPAA, GDPR, ABDM, SOC 2 or ISO 27001 and does not guarantee universal data residency in a customer-selected region.
WhatsApp delivery is not represented as active unless the Business provider credentials, worker, callback and retry path are operational and tested.
Questions or objections
Send subprocessor, location or security-review questions to hello@careflowosai.com before placing regulated data in production.
