Legal
Sub-processors
Every third party that receives any data through DoctorOS, what they get, and why. This is the list the Privacy Policy refers to.
What a sub-processor is
A sub-processor is a company that processes data on our behalf so a feature can work — sending an SMS, taking a payment, delivering an email. They act on our instructions only, for the purpose named in the table, and they may not use the data for their own purposes. Each is bound by contract to protect it to the standard our Privacy Policy sets.
The list
| Who | What for | What they receive | Processed in | When |
|---|---|---|---|---|
| Cloudflare, Inc. | Application hosting, database, file storage, edge caching, and the bot challenge shown on sign-in and sign-up forms. | All service data, processed on our behalf. The bot challenge additionally processes your IP address and browser signals; it does not profile you across other sites. | Global edge network | Always — this is our infrastructure |
| Resend | Delivering transactional email: address verification, sign-in links, receipts, and account notices. | Recipient email address and the contents of that message. | United States | When we send you email |
| SSL Wireless | Delivering transactional SMS: one-time codes and the alerts your account has switched on. | Recipient mobile number and the text of that message. | Bangladesh | When an SMS is actually sent to you or to a customer who consented |
| bKash · Nagad · SSLCommerz | Collecting a payment you or your customer chose to make. | The amount, a transaction reference, and the payer details the provider needs to complete the charge (for example the mobile-wallet number). We receive the result of the transaction, not your full card number. | Bangladesh | Only when your account enables that payment method |
| Telegram | Sending the owner alerts and support replies you asked to receive on Telegram instead of by SMS. | The chat identifier you link, and the text of the alert or support message. | Outside Bangladesh | Only if you link a Telegram chat yourself |
| Two separate, optional features: signing in with a Google account, and playing the in-app help videos, which are hosted on YouTube. | For sign-in: your Google account identifier and email. For a help video: your IP address, device and playback information reach Google as they would on any page with an embedded YouTube player. We send no account, business, or customer data to either feature. | Global | Only if you choose Google sign-in, or open a help video | |
| Apple | Signing in with an Apple account. | Your Apple account identifier, and the email address — or the private relay address — you choose to share. | Global | Only if you choose Sign in with Apple |
Categories we deliberately have none of
The absence of a row matters as much as the presence of one, so we state it plainly:
- No advertising network, ad SDK, or ad identifier — the apps contain none.
- No third-party analytics or product-telemetry vendor. Usage counts are computed by our own server from your own data.
- No third-party crash-reporting service. Crash diagnostics are stored in our own database on our own infrastructure.
- No data broker, no marketing list, and no sale of personal data — under any circumstance.
How we choose and review them
- We add a sub-processor only when a feature cannot work without it, and only for that feature.
- The optional ones stay off until you switch them on. If you never enable payments, no payment provider ever sees your data.
- We review the list whenever we ship a change that adds an outbound integration — the same change adds the row, or it does not merge.
- We do not use sub-processors for advertising, analytics, or crash reporting; those run on our own infrastructure or not at all.
Changes to this list
We will update this page before a new sub-processor starts receiving data, and tell account owners by email when the change affects a feature they use. If you object to a new sub-processor, reply to that email — for optional features you can simply leave them switched off. Questions: privacy@doctoros.work.