Subprocessor List
Last updated: May 16, 2026
Compass engages the third-party service providers below ("subprocessors") to help deliver the Service. All subprocessors are bound by data processing agreements consistent with our DPA and GDPR Article 28 requirements. We will notify customers at least 30 days before adding a new subprocessor.
Legal pages
Amazon Web Services (AWS)
United States (us-east-1, us-west-2)
Cloud hosting and infrastructure (compute, storage, networking)
HIPAA-eligible services used: RDS, S3, SES, ECS, KMS, CloudWatch, Secrets Manager
Supabase
United States
Database hosting (PostgreSQL) — note: migration to AWS Aurora in progress
Currently used on Free tier only. Insights tier data moves to Aurora when migration is complete.
Stripe
United States
Payment processing, subscription billing, invoicing
Processes billing data only — no health or clinical data
AWS Simple Email Service (SES)
United States
Transactional email delivery (account notices, alerts)
Used for product notifications only
Cloudflare
Global (edge network); data processed in United States
DNS management, CDN, DDoS protection, edge caching
No health data transits Cloudflare beyond TLS-encrypted request routing
OpenLoop Healthcare Partners PC
United States
Clinical operations and pharmacy network coordination
A covered entity under HIPAA; governed by a separate Business Associate Agreement
To be notified of subprocessor changes, email privacy@joincompass.ai with the subject "Subscribe to subprocessor updates."
Compass is a product of Launchpad, operated by OpenLoop Healthcare Partners PC.