Skip to content
← All legal documents

Subprocessors

A draft service inventory; actual providers and data flows require confirmation.

Draft dated: July 1, 2026

Draft — pending legal review. This document is a proposal for review, not an executed agreement or evidence of legal approval. Publication does not amend an existing contract, activate a service, or establish that a listed safeguard or vendor arrangement has been verified. Your applicable law and any existing agreement still apply. It does not constitute legal advice. Questions or help reaching the appropriate legal, privacy, or security contact: johnny@tourist-sos.com.

A draft service inventory to help explain potential data flows. Vendor activation, contractual roles, regions, and safeguards require confirmation for the service you actually use; this is not yet a finalized customer-specific subprocessor schedule.

1. About this list

This is a confirmation-required inventory of services identified for Tourist SOS LLC, a Delaware limited liability company's ecosystem, with proposed service-to-data mappings for review. It is not a statement that every service is active, that every vendor receives every record, or that all necessary vendor agreements have been executed.

Actual processing depends on the product, enabled feature, customer instructions, and vendor configuration. A provider may be engaged directly, through another supplier, or for a different legal role. Before relying on a customer-specific list, confirm the contracting entity, purpose, data categories, processing and support-access locations, retention, required safeguards, and relevant agreement status.

2. Service inventory — confirmation required

Scroll sideways to read all columns.

SubprocessorPotential service & data scopeLocation / configuration status
Amazon Web Services (AWS)Cloud infrastructure where selected, directly or through another supplier. Relevant hosted data and service metadata depend on that infrastructure use.Deployment, contracting chain and access locations to confirm
VercelWebsite/application hosting and delivery. May process request data, submitted content passing through the service, and operational logs for the selected deployment.Hosting, delivery and support-access locations to confirm
SupabaseDatabase, authentication and file storage. May process account data, authorized case records, documents and access metadata for the selected product.Actual project, backup and support-access locations to confirm
StripePayment services where enabled. Relevant billing contact, transaction and payment information; patient records are not an intended input to the payment workflow.Selected service and processing locations to confirm
AnthropicAI inference where selected. Prompts and context supplied to an enabled feature may be processed; the approved data scope and vendor terms must be checked.Model service, retention and processing locations to confirm
OpenAIAI inference where selected. Prompts and context supplied to an enabled feature may be processed; the approved data scope and vendor terms must be checked.Model service, retention and processing locations to confirm
ResendEmail delivery. Recipient details, message content and delivery metadata for the relevant communication; sensitive content must be minimized.Delivery, retention and access locations to confirm
StediInsurance eligibility and claims exchange where contracted and enabled. May involve patient, policy, provider and claim details for an authorized transaction.Service scope, processing locations and required agreements to confirm
Google AnalyticsLegacy analytics inventory entry; current activation remains to be confirmed. If enabled, the configured browsing/event and device data must be disclosed; anonymization is not asserted here.Activation, consent configuration and processing locations to confirm

3. What this inventory does not authorize

A listing is not permission to send unrestricted health, identity, payment, or confidential information to that service. Customer data must be limited to the authorized workflow and the vendor's approved role. Model training, vendor retention, and sensitive-data eligibility require service-specific confirmation; an AI provider's brand name alone does not establish those terms.

Clinicians, hospitals, insurers, and emergency services may receive information as independent providers or controllers. They are not automatically Tourist SOS subprocessors merely because we help users communicate with them. Their roles and disclosures must be explained separately in the applicable service and privacy documentation.

No EU-only hosting, US-only processing, zero-retention arrangement, executed vendor DPA or BAA, or completed transfer assessment is represented by this draft. Infrastructure certifications do not automatically certify Tourist SOS or its configuration.

4. Business-customer schedules

An approved customer DPA should identify the authorized subprocessors for that customer, their applicable services and data, and the required transfer safeguards. The public draft does not execute that DPA or grant subprocessor authorization. Any necessary vendor and customer agreements, including HIPAA arrangements where applicable, must be established before the affected processing is authorized.

5. Changes to this list

We will update the inventory as facts are confirmed or services change. For customers with an adopted Data Processing Addendum, additions or replacements must follow its agreed notification and objection process before the relevant processing begins. Updating this public page does not replace a required direct notice or customer authorization. Customers should keep their designated notice contact current.

6. Contact

Questions about this list or our subprocessors? Email privacy@tourist-sos.com.

This draft inventory is dated July 1, 2026. Entries and data mappings remain subject to verification and correction. Request a confirmed service-specific schedule before relying on it for procurement, sensitive-data processing, or transfer compliance.