NexavateAI Trust Center
Subprocessors
Third-party infrastructure and service providers that process data on behalf of NexavateAI to deliver platform functionality. This list supports vendor risk assessments and procurement due diligence.
Overview
How NexavateAI uses third-party processors
NexavateAI engages subprocessors to provide database hosting, AI inference, transactional email, vector search, and application hosting. Each subprocessor receives only the data necessary for its designated function and is subject to contractual data protection obligations.
NexavateAI acts as a data processor for clinic and patient operational data. The healthcare customer (clinic or hospital) is typically the data controller for patient records. Subprocessors support delivery of the platform under NexavateAI's direction.
Subprocessor List
Required infrastructure providers for standard platform operation
| Subprocessor | Category | Purpose | Data processed | Required | Deployment notes |
|---|---|---|---|---|---|
| MongoDB Atlas | Database | Primary data store for appointments, patient records, prescriptions, and operational data | Structured application data submitted through the platform | Required | Region selectable at deployment. TLS enforced. Encryption at rest provided by Atlas. |
| OpenAI | AI / ML | Language model inference and text embeddings for SYRA and NEXA | Chat messages, clinic knowledge context, embedding inputs | Required | OpenAI API services; processing region depends on provider configuration. API data usage governed by OpenAI API terms. |
| Resend | Email delivery | Transactional email for OTP verification and booking notifications | Recipient email address, message content (including OTP during delivery) | Required | Sender domain must be verified. Alternative email providers may be configured for customer-managed deployments. |
| Qdrant | Vector database | Semantic retrieval (RAG) for clinic knowledge base | Text embeddings derived from clinic documentation and FAQs | Required | Qdrant Cloud or self-hosted Qdrant depending on deployment. Region configurable. |
| Hosting provider | Infrastructure | Application runtime and static asset delivery | Application code, runtime configuration (secrets via environment variables only) | Required | Platform-managed or customer-managed depending on deployment model. No secrets stored in source code. |
Optional Subprocessors
These services are used only when the corresponding feature is enabled.
| Subprocessor | Category | Purpose | Data processed | Required |
|---|---|---|---|---|
| Groq | Speech-to-text | Voice input transcription for SYRA (when voice feature is enabled) | Audio segments submitted during active voice sessions | Optional |
Change Notification
We may add or replace subprocessors as the platform evolves. Material changes to required subprocessors will be reflected on this page. Enterprise customers with active agreements may receive advance notice where contractually required.
Related documentation: Privacy Policy — Third-Party Processors
Subprocessor Inquiries
For questions about subprocessor usage, vendor risk assessments, or deployment-specific processor configurations: