Trust Center

Security and privacy at Filo

Filohealth Software, Inc. builds healthcare software, and we hold ourselves to high standards of security practices. This page documents our compliance posture, subprocessors, and data processing agreements.

Compliance

GDPR badge
GDPR
Compliant

EU General Data Protection Regulation. Customer data is hosted in the EU. Where a subprocessor processes data outside the EU/UK, transfers are covered by the EU-U.S. Data Privacy Framework (DPF) and/or the EU Standard Contractual Clauses, which are also incorporated into our Data Processing Agreement.

HIPAA badge
HIPAA
Compliant

Administrative, physical, and technical safeguards for protected health information. BAAs available for covered entities.

Security practices

Encryption everywhere
All personal data is encrypted in transit with TLS 1.2+ and at rest with AES-256.
EU data residency
Customer data is hosted in the EU. Where a subprocessor processes data outside the EU/UK, the transfer is covered by the EU-U.S. Data Privacy Framework (DPF) and/or the EU Standard Contractual Clauses under a signed DPA.
Access control
Role-based access, SSO enforcement, and least-privilege reviews every quarter.
Vendor management
Every subprocessor is risk-assessed and bound by a DPA or BAA before use.
Incident response
Documented IR plan with customer notification without undue delay: within 24 hours under our EU DPA and within 72 hours under our US DPA.
Business continuity
Daily encrypted backups, tested restores, and redundant infrastructure.

Subprocessors

Third parties that process customer data on our behalf, including their locations, data categories, and safeguards. Subprocessors marked AI process conversation data for AI features; see the evidence page for their training and retention controls.

Version 6 · Published 22 September 2026 · Version history

SubprocessorPurposeLocationData categoriesAgreementSafeguards
Amazon Web ServicesCloud infrastructure & data hostingFrankfurt, Germany (eu-central-1)Customer data, including PHIDPAEncryption at rest & in transit, VPC isolation
VercelWeb application hosting & CDNFrankfurt, Germany (eu-central-1)Application traffic metadataDPAEU region deployment, no PHI persisted at edge
RailwayApplication backend, background job hosting & managed PostgreSQL databaseAmsterdam, Netherlands (EU West)Customer data and records, including PHIDPAEU data residency, encryption in transit & at rest, private networking between services and the database
StripeStripe, LLC (and its affiliates)Payment processing, transaction settlement, merchant fraud prevention, financial reportingUnited StatesBilling contact & payment detailsDPAPCI-DSS Level 1, no PHI sharedTransfers: EU-U.S. Data Privacy Framework (DPF), UK Extension, and Standard Contractual Clauses embedded in Stripe's Data Transfers Addendum
ResendTransactional email deliveryDublin, Ireland (eu-west-1)Name, email address, notification contentDPAEU data residency, no PHI in email bodies
TwilioSMS & voice notificationsIreland (IE1)Phone number, appointment remindersDPAEU region processing, minimum-necessary message content
PostHogProduct analyticsFrankfurt, Germany (eu-central-1)Product and website usage events. After a user signs in, the events carry that user's account id, name and email address. No Customer Personal Data: no patient data, no message, call or content dataDPAEU data residency, session recording disabled, marketing sites load it only after the visitor accepts analytics cookies, no PHI and no conversation content sent
HubSpotHubSpot Ireland LimitedOur own CRM and the demo scheduling on our marketing websitesEuropean Union (EU1 region)Name, email address, website and meeting details of people who book a demo with us; no Customer Personal DataDPAEU data region, used for our own sales contacts only, no PHI
SlackSlack Technologies Limited (Salesforce)Internal notifications to our team (signups, payments, demo bookings)United StatesName and email address of a person who signs up or books a demo, and workspace and billing event names; no Customer Personal Data and no PHIDPAOne private channel, message content limited to the event and the person who triggered it, no patient data or message content postedTransfers: EU-U.S. Data Privacy Framework (Salesforce certification) and Standard Contractual Clauses in Salesforce's Data Processing Addendum
OpenAIAI SubprocessorAI language model inference for product featuresEuropean Union (EU data residency)Conversation content submitted to AI features, may include PHIDPAEU data residency, API data not used for model training, encryption in transit & at rest
ElevenLabsAI SubprocessorText-to-speech voice synthesisEuropean Union (EU data residency)Text content for voice synthesis, may include PHIDPAIsolated EU data residency environment, encryption in transit & at rest
LiveKitAI SubprocessorReal-time voice & audio infrastructure (WebRTC)Frankfurt, Germany & Paris, France (EU West)Real-time call audio & session metadata, may include PHIDPAEU West agent deployment, encrypted media transport (DTLS/SRTP), transient media processing
DeepgramAI SubprocessorSpeech-to-text transcriptionEuropean Union (EU dedicated endpoint)Call audio for transcription, may include PHIReferenceEU dedicated endpoint processing, encryption in transit & at rest, transient audio processing

Version history

Every change to the subprocessor list or the evidence page is recorded here with a version number and publication date. Previous versions of either page are available to customers on request for the term of their DPA and for 24 months after it ends.

  1. Version 6Published 22 September 2026
    • PostHog entry corrected: product analytics events carry the signed-in user's account id, name and email address, so the entry no longer describes them as anonymous. No Customer Personal Data, patient data or message content is sent, session recording is off, and the marketing sites now load PostHog only after the visitor accepts analytics cookies.
    • HubSpot added: our own CRM and the demo scheduling on the marketing websites, EU1 region, contact and meeting details of people who book a demo, no Customer Personal Data.
    • Slack added: internal notifications to our team about signups, payments and demo bookings, United States, name and email address of the person concerned, no Customer Personal Data or PHI, DPF and Standard Contractual Clauses.
  2. Version 5Published 18 September 2026
    • EU DPA Data retention clause: files sent by data subjects in messaging conversations (images, voice messages, videos, documents) are retained for no longer than 90 days from receipt; the text derived from them stays with the conversation.
    • EU DPA Data retention clause and Annex A: contact lists a Customer uploads for a WhatsApp campaign (the file as uploaded and the cleaned list of numbers) are retained for no longer than 12 months from upload; the messages sent stay with the conversation.
    • Deepgram now transcribes customers' voice messages and videos (EU endpoint, Model Improvement Program opt-out); evidence re-verified.
    • Evidence page: OpenAI stored responses switched off (store=false) on every model call, including the content engine, the website scan, media tagging and the ads assistant, not only the messaging agent; verification date added.
  3. Version 4Published 14 September 2026
    • Neon (managed PostgreSQL, London, UK) removed as a subprocessor. The PostgreSQL database now runs on Railway in Amsterdam, Netherlands (EU West), alongside the application backend; the Railway entry is updated accordingly.
    • Customer data is now hosted exclusively in the European Union. Hosting statements in the trust center, the US DPA (Data hosting clause and Annex B), and the EU DPA (EU hosting subclause and Annex B) updated from the EU and UK to the EU.
  4. Version 3Published 6 September 2026
    • Version identifier, publication date, and this change log added to the subprocessor list and the evidence page.
    • OpenAI, ElevenLabs, LiveKit, and Deepgram marked as AI Subprocessors, matching the EU DPA definition.
    • EU DPA updated: subprocessor list attached as Annex C, 30-day notice for AI Subprocessor changes, notice for location and transfer mechanism changes, AI Subprocessor configuration warranty, Conversation Data retention periods.
  5. Version 2Published 2 September 2026
    • Evidence page published: model training and data retention controls configured at OpenAI, Deepgram, and ElevenLabs, each with a verification date.
  6. Version 1Published 27 August 2026
    • Subprocessor list first published: 12 subprocessors with purpose, processing location and region, data categories, agreement, safeguards, and transfer mechanism where applicable.

Documents

Compliance documentation available to customers and prospects.

Data Processing Agreement (DPA)
Sign in required
Our standard DPA, available in a US version (HIPAA, CCPA) and an EU version (GDPR, with Standard Contractual Clauses). Generate a signed copy for your business from this portal.
Business Associate Agreement (BAA)
Sign in required
HIPAA BAA for covered entities and business associates.
Need a Data Processing Agreement?
Signed-in customers can generate a DPA pre-signed by Filohealth Software, Inc., made out to their own business name, in under a minute.