To deliver the Babiha platform we use a small number of trusted third-party service providers, known as "sub-processors". This page lists our current sub-processors and the transfer-safeguard status recorded for each one. Where a status is still being verified, the table says so rather than presenting it as confirmed. Our Data Processing Agreement explains the standards that apply to processing for agency customers.
| Provider | What they do | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Database, authentication and file storage | All platform data, including care records | United Kingdom (London) | UK-hosted — no restricted transfer |
| Vercel | Application hosting and (with consent) privacy-friendly analytics | Request logs, IP addresses, usage data | Hosting: EU/UK · Vercel Inc.: USA | IDTA / UK Addendum, or UK–US Data Privacy Framework |
| Resend | Transactional email (verification, notifications) | Recipient identity and minimised care-service notification content, which can include visit, care-plan, medication-alert or incident context | United States | UK transfer safeguard and processor agreement status under owner/DPO verification |
| Sentry | Error and performance monitoring. Server-side always on (legitimate interest); in-browser monitoring and session replay only with analytics consent | Diagnostic data with PII scrubbed | United States | IDTA / UK Addendum, or UK–US Data Privacy Framework |
| Stripe | Subscription billing, payment processing and invoicing | Agency billing contact and address, payment card details (collected by Stripe, never by Babiha), and a count of billable clients — no service-user personal or health data | United States (Stripe Payments Europe / Stripe, Inc.) | UK transfer safeguard and processor agreement status under owner/DPO verification |
| postcodes.io | Postcode lookup for scheduling and travel estimates | Postcodes only (no names or full addresses) | United Kingdom | UK-based — no restricted transfer |
Mapping and route planning
Where an agency uses the scheduling map, only map-tile viewport references (not exact client addresses) are sent to the map-tile provider. External route optimisation is switched off by default: unless an agency configures its own UK/EU-hosted routing service, travel times are estimated locally and no client home coordinates are sent to any third party.
Changes to this list
We may add or replace sub-processors as the platform evolves. Where we do, we will update this page. Agency customers may ask to be notified in advance of changes and may object on reasonable data protection grounds, as set out in our Data Processing Agreement. To request advance notifications, email dpo@babiha.care.