Subprocessors
A subprocessor is a third-party service VoiceBloom uses to operate the platform. We're transparent about every subprocessor, what data they handle, where they're located, and the compliance certifications they hold. We'll notify subscribers by email at least 30 days before adding a new subprocessor that handles personal data.
Why this matters
Under GDPR Article 28, CCPA, PIPEDA, and HIPAA, organizations that process personal data must list every third-party service they share data with, the purpose of each, and the safeguards in place. This page is that list.
Current Subprocessors
| Provider | Purpose | Data location | Certifications / safeguards |
|---|---|---|---|
| Supabase supabase.com |
Database (Postgres), user authentication, file storage, real-time sync | United States (AWS us-east region) | SOC 2 Type II · HIPAA-eligible with BAA · GDPR DPA available · ISO 27001 |
| Vercel vercel.com |
Application hosting, edge functions, serverless API routes | United States (multi-region edge); Europe for EEA traffic | SOC 2 Type II · HIPAA-eligible with BAA · GDPR DPA · CCPA-aligned |
| Vercel Analytics vercel.com/analytics |
Page-view and custom event tracking on marketing pages. Loaded only after the user accepts optional cookies. Pseudonymous; no advertising identifiers | United States; Europe for EEA traffic | GDPR DPA · CCPA-aligned · cookieless by design |
| Vercel Speed Insights vercel.com/docs/speed-insights |
Real-user web-vitals telemetry (LCP, CLS, INP) to monitor site performance. Loaded only after the user accepts optional cookies | United States; Europe for EEA traffic | GDPR DPA · CCPA-aligned · no PII |
| Google Analytics 4 / Firebase Analytics marketingplatform.google.com/about/analytics |
Aggregate usage analytics for the website (Google Analytics 4) and the iOS / Android apps (Firebase Analytics): page and screen views, sessions, and feature and conversion events. Advertising signals disabled, Google Signals and ad personalization off, no advertising identifier (IDFA) collected, no names / emails / symbol-tap content sent. On the website, loaded only after the user accepts optional cookies, with sensitive URL parameters redacted | United States | GDPR DPA · Google Consent Mode (ad signals denied) · IP anonymized |
| HeyCatch heycatch.ai |
Product analytics on the public website and the signed-in account, clinic, and school pages: page views, clicks, and conversion events such as sign-up, trial start, and subscription. Loaded only after the user accepts optional cookies. Not loaded in the communication board or in the iOS and Android apps, so no symbol taps, board vocabulary, or child-composed phrases are ever sent. Receives the account holder's email address and internal user id as account properties; no child names and no child data. Session replay and form-input capture are disabled | United States (HeyCatch on DigitalOcean and Vercel; end-user analytics events stored by HeyCatch's own subprocessor PostHog, US Cloud) | GDPR DPA · EU SCCs 2021/914 Module Two · UK IDTA and Swiss addenda · session replay and input capture disabled · no SOC 2 or ISO 27001 certification |
| Cloudflare (Turnstile) cloudflare.com/products/turnstile |
Privacy-preserving anti-bot challenge on the contact, login, and newsletter forms. Receives visitor IP and user-agent; no advertising tracking | United States; global edge network | SOC 2 Type II · GDPR DPA · ISO 27001 · CCPA-aligned |
| beehiiv beehiiv.com |
Newsletter and product emails, and the subscriber list they are sent from: the welcome series, getting-started tips during a trial, product news, and reminders such as an unfinished setup or a checkout left open. Receives email address, first name, and flags for trial status, setup completion and discount claims; no child data. Every email carries an unsubscribe link | United States | GDPR data protection addendum · Standard Contractual Clauses for transfers · CCPA rights honoured |
| Mandrill (Mailchimp, Intuit) mailchimp.com |
Standby sender for transactional email (receipts, password resets, report notifications). Not in use today: it is kept configured, with its SPF record in place, so sending can be switched over quickly during a Resend outage. If switched on it receives email address and message content, and no child data beyond what that email itself contains | United States | SOC 2 Type II · GDPR DPA · CCPA-aligned · CAN-SPAM compliant |
| Stripe stripe.com |
Payment processing, subscription billing, invoicing. VoiceBloom never stores card details | United States, EU, UK (regional routing) | PCI DSS Level 1 · SOC 1/2 · GDPR DPA · Strong Customer Authentication (PSD2) |
| Anthropic (Claude API) anthropic.com |
AI text generation for Coach replies (the request includes a summary and a timestamped list of that day's symbol taps), weekly and daily report drafts, and IEP note drafts (the student's name is replaced with a placeholder before sending and restored on-device). The child's communication board sends nothing: character replies are generated on the device. Sent inputs are not used to train Anthropic's models per our API agreement | United States | SOC 2 Type II · HIPAA-eligible with BAA · ISO 27001 · inputs and outputs deleted within 30 days under standard commercial terms (zero-retention is a separate arrangement we have not entered) |
| Google Cloud Text-to-Speech cloud.google.com/text-to-speech |
Optional premium ("natural") voices. When a premium voice is selected, the text being spoken (which can include a child's composed phrases) is sent to Google to synthesize audio, then cached on the device. The default on-device voice sends nothing. Inputs are not used to train Google's models per the Cloud API terms | United States | SOC 1/2/3 · ISO 27001/27017/27018 · HIPAA-eligible with BAA · GDPR DPA · Cloud inputs not used for training |
| Resend resend.com |
Transactional email delivery (receipts, trial reminders, password resets, weekly reports, access notifications) | United States | SOC 2 Type II · GDPR DPA · sender domain authenticated (SPF, DKIM, DMARC) |
| Sentry sentry.io |
Error and crash monitoring. Receives stack traces, page URL, anonymous user ID. No symbol-tap content, no child names, no PII | United States | SOC 2 Type II · ISO 27001 · GDPR DPA · data-scrubbing enabled by default |
| Google Fonts fonts.google.com |
Web font (Nunito) on public marketing pages only. The in-app experience uses bundled fonts and does not call Google Fonts | Google global CDN | No cookies set · IP address visible to Google for font fetch |
| Google Gemini (image generation) ai.google.dev |
Used during development to generate the bundled symbol illustrations. Not called at runtime by end users | United States | Used for static asset generation only · no end-user data sent |
| GitHub github.com |
Source code hosting. Does not process end-user data | United States | SOC 2 Type II · ISO 27001 · two-factor authentication enforced |
International Transfers
Several subprocessors are based in the United States. Where data is transferred outside Canada or outside the EEA, transfers are governed by:
- Standard Contractual Clauses (EU SCCs) for EEA/UK personal data
- PIPEDA-aligned contractual safeguards for Canadian personal data
- Each subprocessor's individual data-processing agreement, attaching the protections above
Notification of Changes
We will notify subscribers by email at least 30 days before:
- Adding a new subprocessor that handles personal data
- Changing the data location of an existing subprocessor
- Materially changing the scope of data a subprocessor receives
If you object to a new subprocessor and the change is material to your use of VoiceBloom, you may cancel your subscription before the change takes effect and we will refund any prepaid amounts covering the period after the change.
Version History
- v1.0 · May 14, 2026: Initial subprocessor list published for launch.
- v1.2 · August 27, 2026: Added HeyCatch (product analytics for the website and signed-in account pages, consent-gated, not used in the communication board or the mobile apps).
How to request a DPA or BAA
Therapy and Education plan subscribers may request a Data Processing Agreement (GDPR Article 28) or a Business Associate Agreement (HIPAA) at any time. Email info@voicebloom.ca with your account email and we will route the request to the right team.