Effective Date: September 5, 2026
This page identifies every third party that may create, receive, maintain, transmit, store, or process customer data — including Protected Health Information (PHI) — on behalf of HALai, Inc. in delivering the Services. Under our Business Associate Agreement, we give Covered Entities at least 30 days' advance notice before engaging any new subprocessor that will process PHI, and the Covered Entity may object on reasonable grounds. SUBPROCESSORS THAT MAY PROCESS PHI Microsoft Corporation (Microsoft Azure) — United States Function: Cloud hosting, compute, storage, database, networking, key management, and real-time messaging. Azure also serves AI model inference for those workloads routed through its AI endpoints. Data received: All customer data, including PHI, at rest and in transit. Safeguard: HIPAA Business Associate Agreement with Microsoft. United States data residency. OpenAI, L.L.C. — United States Function: Large-language-model inference and realtime voice, where called directly rather than through Azure. Data received: Prompt content submitted for inference, which may include encounter-note text and voice audio. Safeguard: HIPAA Business Associate Agreement, with zero data retention on the endpoints we use. Anthropic, PBC — United States Function: Large-language-model inference, where called directly rather than through Azure. Data received: Prompt content submitted for inference, which may include encounter-note text. Safeguard: HIPAA Business Associate Agreement, with zero data retention on the endpoints we use. A note on inference routing. Inference is served through a mix of paths depending on the product and workload. Some calls are routed through Azure's AI endpoints, in which case the data remains within the Azure boundary and is covered by our Business Associate Agreement with Microsoft. Others go directly to OpenAI or Anthropic, in which case they are covered by our Business Associate Agreement with that vendor. Every path is under a signed Business Associate Agreement with zero data retention. SUBPROCESSORS THAT DO NOT PROCESS PHI Okta, Inc. (Auth0) — United States Function: Identity, authentication, and session management. Data received: Account identifiers only — name, email address, and authentication metadata. No clinical content, by design. Safeguard: Data processing terms. Auth0 is not a Business Associate because it does not receive PHI. Stripe, Inc. — United States Function: Payment processing and subscription billing. Data received: Billing contact details and payment card information. No clinical content. Safeguard: Data processing agreement. PCI DSS Level 1 Service Provider. HALai does not store full payment card numbers. AFFILIATES Artificial Healthcare Intelligence, Inc. — Delaware 501(c)(3), sole parent of HALai, Inc. Access is limited to authorized workforce members supporting the platform, for the purpose of operating and supporting the Services. DATA RESIDENCY All processing occurs in United States regions. There is no offshore processing and no offshore support access. WHAT WE DO NOT DO We do not sell customer data or PHI. We do not share customer data with advertising networks, data brokers, or analytics vendors. We do not use customer data or PHI to train general-purpose AI models, or any model that serves another customer. The ENCOUNTERai personalized model is trained solely on an individual provider's own notes and is tenant-isolated to that provider. We do not use third-party advertising or behavioral-analytics trackers in the authenticated application. CHANGES TO THIS LIST Material changes are published on this page and notified to Covered Entities in accordance with the Business Associate Agreement. To be notified of subprocessor changes, email security@halai.ai. CORRECTION NOTICE Marketing material previously stated that AHI uses "no third-party subcontractors" and that Microsoft Azure is "the only infrastructure provider." That statement was inaccurate and is superseded by this page. OpenAI and Anthropic models perform inference on content that may include PHI, in each case under a Business Associate Agreement with zero data retention.
Related: Privacy Policy · Healthcare Provider User Agreement · Consumer Health Data Privacy Policy · Security & Compliance