Sub-processors & Data Recipients
Nokairo relies on a small number of carefully selected third parties to run its service. The tables below list every sub-processor that processes personal data on our behalf, together with the statutory recipients we are legally required to transmit certain data to. We keep this distinction explicit: sub-processors act on our instructions under a data-processing agreement (GDPR Art. 28), while statutory recipients are independent data controllers that Italian law obliges us to report to.
Last updated: 28 July 2026
A. Sub-processors
These providers process personal data on our behalf, under contract and on our documented instructions (GDPR Art. 28).
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure and hosting — application server, PostgreSQL database, object storage for patient and clinic files, and encrypted off-site database backups. | All hosted data: patient records, clinical data, invoices, and documents. | EU (Germany / Finland) |
| Mailgun (Sinch) | Transactional email delivery — appointment reminders, recalls, invitations, and invoice/quote emails. | Recipient email address and email content. Reminders, receipts, and attached documents can reference appointments and treatments — health-related data (questionnaire-receipt PDFs contain the patient's answers). | EU (EU mail region) |
| Fatture in Cloud (TeamSystem) | Electronic invoicing — generates e-invoices and transmits them to the Italian Exchange System (SDI). | Invoice and billing data, patient fiscal identifiers (codice fiscale), amounts. Invoice line descriptions can reveal the treatments received — health-related data. | Italy / EU |
| Cloudflare | Turnstile CAPTCHA on the public inquiry form (anti-abuse / bot protection), and Cloudflare Workers hosting for this website and the clinic web app, both served through Cloudflare's network. | Challenge token and visitor IP address of marketing-form submitters; for the hosted sites, visitor, staff, and patient IP addresses and requested URL paths — which can include one-time links carrying capability tokens (password reset, login link, unsubscribe, questionnaire, quote signing) and patient/clinic identifiers. | Global (Cloudflare network) |
| Amazon Web Services (AWS Bedrock) | AI assistant inference — the in-app assistant sends conversation context to the Anthropic Claude model hosted on AWS Bedrock to generate responses. Conversation context now also includes text derived from files a user attaches to the chat (spreadsheet column headers and a small sample of rows, and PDF text), minimised to what the task requires. The text of each user message is also converted into search embeddings with the Cohere embed-multilingual-v3 model, likewise hosted on AWS Bedrock. | Assistant conversation content, the patient data staff reference in it (names, clinical and scheduling details), and text extracted from user-attached files (spreadsheet headers and sample rows, PDF text) which may contain personal data. | EU regions (EU cross-region inference profile; primary region Frankfurt, eu-central-1) |
| Meta Platforms Ireland Ltd (WhatsApp Business Platform) | WhatsApp Business messaging — appointment reminders, confirmations, and recalls delivered to patients over WhatsApp. | Patient mobile number and message content. | EU (Ireland) / Global (Meta network) |
B. Statutory recipients
We are legally required to transmit certain data to these public bodies. They are independent data controllers, not our sub-processors.
| Recipient | Purpose | Data categories | Region |
|---|---|---|---|
| Sistema Tessera Sanitaria (Sogei — MEF / Agenzia delle Entrate) | Mandatory transmission of healthcare expense data for the pre-filled tax return (modello 730). | Healthcare expense records and patient codice fiscale. | Italy |
| Sistema di Interscambio (SDI — Agenzia delle Entrate) | Statutory destination of electronic invoices (reached via Fatture in Cloud). | Electronic invoice data. | Italy |
Maintenance note: we keep this list current. It must be updated whenever a sub-processor or data recipient is added, changed, or removed. Where there is any doubt, this page — not an older document — reflects our current sub-processors. Planned additions: the regional FSE repository (statutory recipient of signed clinical documents) and a qualified remote PAdES document-signing provider are currently integrated in test mode only — they will be added to these tables the moment they go live.