Armidus Subprocessors and Service Providers

Last updated: July 22, 2026

Effective from: July 22, 2026

Armidus uses carefully selected third parties to provide and operate its Service. This page distinguishes between:

  1. Authorized Subprocessors, which may process personal information in Clinic Data on behalf of a Clinic under the Armidus Data Processing Addendum;
  2. payment providers, which may act as a processor for some functions and independently for others; and
  3. website and business-operations providers, which generally process information for Armidus's own business purposes rather than core Clinic Data.

This distinction matters. Listing HubSpot or Microsoft 365 does not mean that Armidus sends patient records to its CRM or ordinary business email. Armidus instructs users not to submit patient records through general website forms, legal forms, or ordinary support communications.

1. Authorized Subprocessors for the Armidus Service

The following providers may process Customer Personal Data for Armidus in providing the Clinic Service.

ProviderService and purposePersonal information involvedPrimary processing locationNotes
Google Cloud Platform, provided by the applicable Google contracting entityCloud Run application hosting, Cloud SQL database, load balancing, secrets management, logging, monitoring, backup, and related cloud infrastructureClinic, owner, animal patient, care-plan, task, interaction, account, audit, and operational data stored or processed through the regional applicationSingapore for the core Singapore production environmentGoogle and its authorized personnel or subprocessors may process limited support, security, metadata, or transfer data elsewhere under applicable contract terms. Each launched country is intended to use a dedicated project and configured region.
Clerk, Inc.User authentication, session management, verified email, Clinic organization membership and roles, owner identity, account invitations, sign-in links, and identity webhooksUser name, email, phone where supplied, account ID, organization membership, role, verified-email status, session and authentication information, and limited regional enrollment metadataUnited States and other locations used by Clerk and its subprocessorsClerk identity is global. Patient records and full care plans are not stored in Clerk. Regional authorization remains in Armidus's regional databases. Clerk does not currently offer Armidus country-level identity data residency.
AC PM LLC, operating PostmarkTransactional email delivery and delivery-event processing for owner claim messages, care notifications, and operational messagesRecipient email, sender information, message content, claim-link URL, Clinic identity, delivery status, and technical delivery metadataUnited States, including infrastructure outside Chicago and Amazon Web Services, subject to the provider's current documentationRaw claim tokens appear in the message link delivered to the owner but are stored only as hashes in the Armidus database. Do not include unnecessary patient detail in email content.
Google Cloud Vertex AI, provided by the applicable Google contracting entityAI-assisted organization and structuring of Clinic-authored care text when an authorized Clinic user invokes the featurePrompt and system instructions, Clinic-authored source text, selected animal name, species or breed context, block-library content, generated response, and technical usage informationSingapore regional endpoint for the Singapore ServiceArmidus configures supported Vertex AI models and features through the Singapore regional endpoint in the country-specific Google Cloud project. Global endpoints, cross-region fallback, and features that require processing outside the configured region are not enabled for Clinic Data. Google states that it does not use Customer Data (as Google defines that term in its Cloud agreement) to train or fine-tune AI or machine-learning models without prior permission or instruction. Service metadata and limited security processing remain subject to Google's applicable terms.

Regional hosting qualification

For the Singapore Service, core application and database records are stored in Armidus's dedicated Google Cloud Singapore environment. Supported Vertex AI processing of Clinic Data is also configured through a Singapore regional endpoint. This does not mean that all information remains exclusively in Singapore. Authentication, transactional email, support, security, and provider metadata may involve the locations stated above.

2. Payment provider

ProviderService and purposePersonal information involvedProcessing locationRole
Stripe, Inc. and applicable affiliatesStripe-hosted Checkout and customer portal, recurring billing, invoicing, tax, payment recovery, fraud prevention, refunds, disputes, and subscription administrationClinic and billing contact, billing country, tax information, veterinarian seat quantity, subscription and invoice details, payment method and transaction information, IP and device information, and Stripe identifiersUnited States and other locations described by StripeStripe may act as Armidus's processor for some services and as an independent controller for payment, fraud, compliance, and network functions it determines. Card numbers and security codes are entered on Stripe-hosted surfaces and do not pass through Armidus application servers.

Stripe is disclosed here for transparency but is not treated as an Authorized Subprocessor for every payment activity under the Armidus DPA.

3. Website and business-operations providers

These providers generally process information for Armidus's own website, sales, legal, support, and internal operations. They are not intended to store core Clinic patient or care-plan records.

ProviderService and purposeInformation involvedPrimary processing locationClassification and restrictions
Netlify, Inc.Hosting, content delivery, deployment, and security for the public marketing siteVisitor IP, device and request information, pages requested, technical logs, and information sent through a Netlify-hosted feature if one is enabledUnited States and global edge locationsWebsite infrastructure provider. It does not host the regional Clinic or owner application database.
HubSpot, Inc. and relevant affiliatesWebsite forms, CRM, inquiry management, sales pipeline, support or legal request intake, cookie consent banner, live chat or messaging, and website analytics via the HubSpot tracking codeBusiness contact details, Clinic, form request type and message, correspondence, chat content and related identifiers, website identifiers, cookie and interaction data, and follow-up recordsUnited States and other locations described in HubSpot's applicable service and subprocessor documentationWebsite and business-operations processor for Armidus. General forms and chat must not collect patient records, passwords, payment-card details, or claim links. Tracking-data sharing, enrichment, and advertising integrations are not enabled unless separately reviewed and disclosed.
Microsoft CorporationMicrosoft 365 business email, calendars, office documents, collaboration, internal administration, security alerts, and communications with Clinics, owners, vendors, regulators, and advisersBusiness contact details, correspondence, attachments, meeting details, operational alerts, legal and security records, and internal working documentsThe Microsoft 365 tenant's configured geography and other locations described in Microsoft's applicable termsBusiness-operations provider. Microsoft 365 is not intended to be the system of record for patient care. Users and personnel should not send patient records through ordinary email or store them in general collaboration spaces unless specifically authorized and protected.

Why HubSpot and Microsoft 365 appear here

They should be disclosed because they process personal information in Armidus's business operations. Omitting them would make the Privacy Policy incomplete. They should not be placed in the core DPA subprocessor table unless Armidus actually uses them to process Customer Personal Data on a Clinic's behalf.

If a Clinic deliberately sends Clinic Data through a support channel, Armidus may need to process that information in a business system to resolve the request. Armidus will ask the Clinic to use a secure channel where the matter requires patient data, security evidence, or another sensitive attachment.

4. Providers not currently listed as active

Advertising networks, social-media advertising pixels, data brokers, and general-purpose consumer analytics tools are not currently used. If that changes, Armidus will update this page and the Cookie Policy and provide any notice or consent required by law.

5. Changes to Authorized Subprocessors

Armidus may add or replace an Authorized Subprocessor as the Service evolves. Where the DPA applies, Armidus will:

To request change notices, select Privacy at https://armidus.com/submit-request and write "Subprocessor notices" in the message. The form may be used to register an administrative contact without using email as the ordinary intake channel.

6. Subprocessor objections and questions

Use the Privacy or Legal option at https://armidus.com/submit-request. Identify the Customer, the provider concerned, and the specific data-protection grounds for the objection. Do not include patient records, passwords, payment-card details, claim links, or vulnerability evidence in the form. Armidus will provide a secure channel if supporting material is needed.

Privacy and data-protection questions may also be sent to Armidus's Data Protection Officer at privacy@armidus.com. See our Privacy Policy at https://armidus.com/privacy, DPA at https://armidus.com/dpa, and Security page at https://armidus.com/security.