Armidus Subprocessors and Service Providers
Last updated: July 22, 2026
Effective from: July 22, 2026
Armidus uses carefully selected third parties to provide and operate its Service. This page distinguishes between:
- Authorized Subprocessors, which may process personal information in Clinic Data on behalf of a Clinic under the Armidus Data Processing Addendum;
- payment providers, which may act as a processor for some functions and independently for others; and
- website and business-operations providers, which generally process information for Armidus's own business purposes rather than core Clinic Data.
This distinction matters. Listing HubSpot or Microsoft 365 does not mean that Armidus sends patient records to its CRM or ordinary business email. Armidus instructs users not to submit patient records through general website forms, legal forms, or ordinary support communications.
1. Authorized Subprocessors for the Armidus Service
The following providers may process Customer Personal Data for Armidus in providing the Clinic Service.
| Provider | Service and purpose | Personal information involved | Primary processing location | Notes |
|---|---|---|---|---|
| Google Cloud Platform, provided by the applicable Google contracting entity | Cloud Run application hosting, Cloud SQL database, load balancing, secrets management, logging, monitoring, backup, and related cloud infrastructure | Clinic, owner, animal patient, care-plan, task, interaction, account, audit, and operational data stored or processed through the regional application | Singapore for the core Singapore production environment | Google and its authorized personnel or subprocessors may process limited support, security, metadata, or transfer data elsewhere under applicable contract terms. Each launched country is intended to use a dedicated project and configured region. |
| Clerk, Inc. | User authentication, session management, verified email, Clinic organization membership and roles, owner identity, account invitations, sign-in links, and identity webhooks | User name, email, phone where supplied, account ID, organization membership, role, verified-email status, session and authentication information, and limited regional enrollment metadata | United States and other locations used by Clerk and its subprocessors | Clerk identity is global. Patient records and full care plans are not stored in Clerk. Regional authorization remains in Armidus's regional databases. Clerk does not currently offer Armidus country-level identity data residency. |
| AC PM LLC, operating Postmark | Transactional email delivery and delivery-event processing for owner claim messages, care notifications, and operational messages | Recipient email, sender information, message content, claim-link URL, Clinic identity, delivery status, and technical delivery metadata | United States, including infrastructure outside Chicago and Amazon Web Services, subject to the provider's current documentation | Raw claim tokens appear in the message link delivered to the owner but are stored only as hashes in the Armidus database. Do not include unnecessary patient detail in email content. |
| Google Cloud Vertex AI, provided by the applicable Google contracting entity | AI-assisted organization and structuring of Clinic-authored care text when an authorized Clinic user invokes the feature | Prompt and system instructions, Clinic-authored source text, selected animal name, species or breed context, block-library content, generated response, and technical usage information | Singapore regional endpoint for the Singapore Service | Armidus configures supported Vertex AI models and features through the Singapore regional endpoint in the country-specific Google Cloud project. Global endpoints, cross-region fallback, and features that require processing outside the configured region are not enabled for Clinic Data. Google states that it does not use Customer Data (as Google defines that term in its Cloud agreement) to train or fine-tune AI or machine-learning models without prior permission or instruction. Service metadata and limited security processing remain subject to Google's applicable terms. |
Regional hosting qualification
For the Singapore Service, core application and database records are stored in Armidus's dedicated Google Cloud Singapore environment. Supported Vertex AI processing of Clinic Data is also configured through a Singapore regional endpoint. This does not mean that all information remains exclusively in Singapore. Authentication, transactional email, support, security, and provider metadata may involve the locations stated above.
2. Payment provider
| Provider | Service and purpose | Personal information involved | Processing location | Role |
|---|---|---|---|---|
| Stripe, Inc. and applicable affiliates | Stripe-hosted Checkout and customer portal, recurring billing, invoicing, tax, payment recovery, fraud prevention, refunds, disputes, and subscription administration | Clinic and billing contact, billing country, tax information, veterinarian seat quantity, subscription and invoice details, payment method and transaction information, IP and device information, and Stripe identifiers | United States and other locations described by Stripe | Stripe may act as Armidus's processor for some services and as an independent controller for payment, fraud, compliance, and network functions it determines. Card numbers and security codes are entered on Stripe-hosted surfaces and do not pass through Armidus application servers. |
Stripe is disclosed here for transparency but is not treated as an Authorized Subprocessor for every payment activity under the Armidus DPA.
3. Website and business-operations providers
These providers generally process information for Armidus's own website, sales, legal, support, and internal operations. They are not intended to store core Clinic patient or care-plan records.
| Provider | Service and purpose | Information involved | Primary processing location | Classification and restrictions |
|---|---|---|---|---|
| Netlify, Inc. | Hosting, content delivery, deployment, and security for the public marketing site | Visitor IP, device and request information, pages requested, technical logs, and information sent through a Netlify-hosted feature if one is enabled | United States and global edge locations | Website infrastructure provider. It does not host the regional Clinic or owner application database. |
| HubSpot, Inc. and relevant affiliates | Website forms, CRM, inquiry management, sales pipeline, support or legal request intake, cookie consent banner, live chat or messaging, and website analytics via the HubSpot tracking code | Business contact details, Clinic, form request type and message, correspondence, chat content and related identifiers, website identifiers, cookie and interaction data, and follow-up records | United States and other locations described in HubSpot's applicable service and subprocessor documentation | Website and business-operations processor for Armidus. General forms and chat must not collect patient records, passwords, payment-card details, or claim links. Tracking-data sharing, enrichment, and advertising integrations are not enabled unless separately reviewed and disclosed. |
| Microsoft Corporation | Microsoft 365 business email, calendars, office documents, collaboration, internal administration, security alerts, and communications with Clinics, owners, vendors, regulators, and advisers | Business contact details, correspondence, attachments, meeting details, operational alerts, legal and security records, and internal working documents | The Microsoft 365 tenant's configured geography and other locations described in Microsoft's applicable terms | Business-operations provider. Microsoft 365 is not intended to be the system of record for patient care. Users and personnel should not send patient records through ordinary email or store them in general collaboration spaces unless specifically authorized and protected. |
Why HubSpot and Microsoft 365 appear here
They should be disclosed because they process personal information in Armidus's business operations. Omitting them would make the Privacy Policy incomplete. They should not be placed in the core DPA subprocessor table unless Armidus actually uses them to process Customer Personal Data on a Clinic's behalf.
If a Clinic deliberately sends Clinic Data through a support channel, Armidus may need to process that information in a business system to resolve the request. Armidus will ask the Clinic to use a secure channel where the matter requires patient data, security evidence, or another sensitive attachment.
4. Providers not currently listed as active
Advertising networks, social-media advertising pixels, data brokers, and general-purpose consumer analytics tools are not currently used. If that changes, Armidus will update this page and the Cookie Policy and provide any notice or consent required by law.
5. Changes to Authorized Subprocessors
Armidus may add or replace an Authorized Subprocessor as the Service evolves. Where the DPA applies, Armidus will:
- update this page and its change log;
- provide at least 30 days' advance notice of a new Authorized Subprocessor that will materially process Customer Personal Data, where reasonably practicable;
- impose applicable data-protection and confidentiality obligations; and
- allow a Customer to object on reasonable, documented data-protection grounds as described in the DPA.
To request change notices, select Privacy at https://armidus.com/submit-request and write "Subprocessor notices" in the message. The form may be used to register an administrative contact without using email as the ordinary intake channel.
6. Subprocessor objections and questions
Use the Privacy or Legal option at https://armidus.com/submit-request. Identify the Customer, the provider concerned, and the specific data-protection grounds for the objection. Do not include patient records, passwords, payment-card details, claim links, or vulnerability evidence in the form. Armidus will provide a secure channel if supporting material is needed.
Privacy and data-protection questions may also be sent to Armidus's Data Protection Officer at privacy@armidus.com. See our Privacy Policy at https://armidus.com/privacy, DPA at https://armidus.com/dpa, and Security page at https://armidus.com/security.