ANAHIT.CARE
← Back to ANAHIT.CARE

Transparency

Trust and compliance

ANAHIT.CARE documents the main technical services used to operate, secure and maintain the platform. This page describes their operational role and provides public sources concerning their security and data protection commitments.

Transparency principles

  • Minimisation of collected and retained data.
  • Access control according to least privilege.
  • Encryption of communications (TLS).
  • Private storage of professional documents.
  • Traceability of critical actions.
  • Separation between KYC/KYB data and medical data.
  • No activation of real medical data at this stage.
  • Regular review of technical providers.

This page describes operational practices and technical providers. It is not a claim of full GDPR compliance, an HDS certification, or an absolute security guarantee.

Technical providers

Public register of the main technical providers confirmed in the project. This public register is not the complete internal GDPR register. Private contracts remain off this website.

Scaleway

Storage

Published

Operational role
Private object storage for professional KYC/KYB documents.
Legal role (cautious)
Processor when applicable
Purpose
Privately retain professional documents required for partner onboarding.
Potentially concerned data
Professional identification documents and KYC/KYB evidence; object technical metadata.
Documented scope
French region of the European Union observed for KYB Object Storage.
Explicit exclusions
Storage of real patient medical data is not enabled at this stage.

Scaleway Object Storage is used for the private storage of professional KYC/KYB documents in a French region of the European Union. Storage of real patient medical data is not enabled. A separate commercial and contractual HDS qualification is in progress.

Information verified on:

Vercel

Deployment

Published

Operational role
Hosting, deployment and runtime execution of the ANAHIT.CARE web application (Preview and Production environments).
Legal role (cautious)
Processor when applicable
Purpose
Host, deploy and run the web application, and process technical logs according to configuration.
Potentially concerned data
HTTP requests, technical logs, IP addresses and session-related data depending on configuration.
Documented scope
Project-documented deployment region: fra1 (Frankfurt). No exclusively European localisation is asserted without project-specific contractual evidence.
Explicit exclusions
Does not constitute an HDS hosting claim. Hostinger is not presented as the application host.

Vercel provides hosting, deployment and runtime execution for the ANAHIT.CARE web application. Preview and Production environments may process requests, logs and technical data depending on project configuration.

Information verified on:

GitHub

Development and CI/CD

Published

Operational role
Source code repository, code review, Pull Requests and GitHub Actions CI/CD.
Legal role (cautious)
Technical provider
Purpose
Version software, automate quality checks and orchestrate CI/CD pipelines.
Potentially concerned data
Source code, contribution metadata, CI logs. No production business data should be intentionally stored there.
Documented scope
Global GitHub / Microsoft infrastructure. Exact localisation depends on the GitHub services in use.
Explicit exclusions
No medical or KYC/KYB data should be placed in the repository or CI artefacts.

GitHub is presented as a development and CI/CD provider. It is not automatically characterised as a processor of all platform user data.

Information verified on:

Stripe

Payment

Published

Operational role
B2B professional subscriptions, billing and subscription status management.
Legal role (cautious)
Mixed role depending on processing
Purpose
Collect and manage professional platform subscriptions.
Potentially concerned data
Professional billing identifiers, professional emails, subscription statuses and payment metadata.
Documented scope
Stripe services operated according to applicable Stripe entities and configuration (not presented as exclusively European).
Explicit exclusions
No patient payments in Phase 1 / current MVP.

Stripe may have different legal roles depending on the processing. It is not presented solely as a processor.

Information verified on:

Resend

Communication

Published

Operational role
Sending of platform transactional emails.
Legal role (cautious)
Processor when applicable
Purpose
Deliver transactional messages (verification, activation, operational notifications).
Potentially concerned data
Email addresses, transactional message content and delivery metadata.
Documented scope
Resend infrastructure according to account configuration; localisation is not asserted here as exclusively European.
Explicit exclusions
No documented use here for sending real medical data.

Resend integration is confirmed in the project’s transactional email code.

Information verified on:

Neon

Infrastructure

Published

Operational role
Managed PostgreSQL database used by the application.
Legal role (cautious)
Processor when applicable
Purpose
Persist application data required for platform operation.
Potentially concerned data
Account data, professional profiles, bookings, subscriptions, audit logs and related metadata.
Documented scope
Project region to be verified in the Neon console; documented UE-first objective, without an absolute geographic claim here.
Explicit exclusions
Real medical data must not be enabled until the target compliance framework is validated.

Neon is the managed database provider confirmed by project documentation and Prisma configuration. PostgreSQL as software is not presented as a separate subprocessor.

Information verified on:

Google

Authentication

Published

Operational role
Sign-in option offered on login pages via Google OAuth.
Legal role (cautious)
Independent controller when applicable
Purpose
Allow user authentication via a Google account.
Potentially concerned data
OAuth identifiers, email address and profile information made available by Google according to user consent.
Documented scope
Google services operated under applicable Google terms.
Explicit exclusions
No OAuth secrets, client IDs or internal callback URLs are published here.

The Google button is offered on login pages. Effective activation depends on environment configuration.

Information verified on:

Microsoft

Authentication

Published

Operational role
Sign-in option offered on login pages via Microsoft / Azure AD.
Legal role (cautious)
Independent controller when applicable
Purpose
Allow user authentication via a Microsoft account.
Potentially concerned data
OIDC identifiers, email address and profile claims made available by Microsoft according to user consent.
Documented scope
Microsoft services operated according to the applicable tenant and Microsoft terms.
Explicit exclusions
No OAuth secrets, tenant IDs or internal callback URLs are published here.

The Microsoft button is offered on login pages. Effective activation depends on environment configuration.

Information verified on:

Apple

Authentication

Published

Operational role
Sign in with Apple authentication, active in production on login pages.
Legal role (cautious)
Independent controller when applicable
Purpose
Allow sign-in with an Apple account.
Potentially concerned data
Apple identifier, real or relay email address, and technical authentication data.
Documented scope
Apple services operated under applicable Apple terms.
Explicit exclusions
No client identifiers, secrets or internal callback URLs are published here.

Apple Sign in is confirmed active in production for ANAHIT.CARE.

Information verified on:

Hostinger

Infrastructure

Published

Operational role
Domain name management and professional email.
Legal role (cautious)
Processor when applicable
Purpose
Manage the ANAHIT.CARE domain name and associated professional email.
Potentially concerned data
DNS/domain data and professional mailbox content depending on email usage.
Documented scope
Hostinger services according to applicable terms and contracting entity.
Explicit exclusions
Hostinger is not the host of the ANAHIT.CARE web application.

Hostinger only provides domain name management and professional email. Application hosting and runtime are provided by Vercel.

Information verified on:

Cloudflare Turnstile

Infrastructure

Published

Operational role
Prevention of bots, abuse and automated submissions on public forms.
Legal role (cautious)
Processor when applicable
Purpose
Protect public journeys against automated submissions and abuse.
Potentially concerned data
Technical connection data, browser data and security signals required for anti-bot verification.
Documented scope
Cloudflare services under applicable Cloudflare terms; no exclusive localisation is asserted here.
Explicit exclusions
No Turnstile secrets, site keys or internal integration details are published here.

Turnstile is integrated into the public signup, treatment-request, partner-request and password-reset journeys, with server-side verification via siteverify. Bypass is allowed only outside production when keys are not configured.

Information verified on:

Contact

For any question about this page, please use the internal contact form.

Do not submit medical data or health documents through this form.

Backup channel: anahit [at] anahit.care.