Trust Center
Security and privacy at Filo
Filohealth Software, Inc. builds healthcare software, and we hold ourselves to high standards of security practices. This page documents our compliance posture, subprocessors, and data processing agreements.

Compliance
Security practices
Subprocessors
Third parties that process customer data on our behalf, including their locations, data categories, and safeguards. Subprocessors marked AI process conversation data for AI features; see the evidence page for their training and retention controls.
Version 6 · Published 22 September 2026 · Version history
Version history
Every change to the subprocessor list or the evidence page is recorded here with a version number and publication date. Previous versions of either page are available to customers on request for the term of their DPA and for 24 months after it ends.
- Version 6Published 22 September 2026
- PostHog entry corrected: product analytics events carry the signed-in user's account id, name and email address, so the entry no longer describes them as anonymous. No Customer Personal Data, patient data or message content is sent, session recording is off, and the marketing sites now load PostHog only after the visitor accepts analytics cookies.
- HubSpot added: our own CRM and the demo scheduling on the marketing websites, EU1 region, contact and meeting details of people who book a demo, no Customer Personal Data.
- Slack added: internal notifications to our team about signups, payments and demo bookings, United States, name and email address of the person concerned, no Customer Personal Data or PHI, DPF and Standard Contractual Clauses.
- Version 5Published 18 September 2026
- EU DPA Data retention clause: files sent by data subjects in messaging conversations (images, voice messages, videos, documents) are retained for no longer than 90 days from receipt; the text derived from them stays with the conversation.
- EU DPA Data retention clause and Annex A: contact lists a Customer uploads for a WhatsApp campaign (the file as uploaded and the cleaned list of numbers) are retained for no longer than 12 months from upload; the messages sent stay with the conversation.
- Deepgram now transcribes customers' voice messages and videos (EU endpoint, Model Improvement Program opt-out); evidence re-verified.
- Evidence page: OpenAI stored responses switched off (store=false) on every model call, including the content engine, the website scan, media tagging and the ads assistant, not only the messaging agent; verification date added.
- Version 4Published 14 September 2026
- Neon (managed PostgreSQL, London, UK) removed as a subprocessor. The PostgreSQL database now runs on Railway in Amsterdam, Netherlands (EU West), alongside the application backend; the Railway entry is updated accordingly.
- Customer data is now hosted exclusively in the European Union. Hosting statements in the trust center, the US DPA (Data hosting clause and Annex B), and the EU DPA (EU hosting subclause and Annex B) updated from the EU and UK to the EU.
- Version 3Published 6 September 2026
- Version identifier, publication date, and this change log added to the subprocessor list and the evidence page.
- OpenAI, ElevenLabs, LiveKit, and Deepgram marked as AI Subprocessors, matching the EU DPA definition.
- EU DPA updated: subprocessor list attached as Annex C, 30-day notice for AI Subprocessor changes, notice for location and transfer mechanism changes, AI Subprocessor configuration warranty, Conversation Data retention periods.
- Version 2Published 2 September 2026
- Evidence page published: model training and data retention controls configured at OpenAI, Deepgram, and ElevenLabs, each with a verification date.
- Version 1Published 27 August 2026
- Subprocessor list first published: 12 subprocessors with purpose, processing location and region, data categories, agreement, safeguards, and transfer mechanism where applicable.
Documents
Compliance documentation available to customers and prospects.