Subprocessor List
This Subprocessor List identifies material third-party service providers that Team OPS Inc. dba MYCURE (“MYCURE,” “we,” “us,” or “our”) currently engages to process Customer Data in connection with MYCURE CMS and related services.
Effective Date: August 11, 2026
This page should be read together with our Privacy Notice, Terms of Service, Security Overview, and any applicable data processing agreement, Business Associate Agreement, Order Form, or other written agreement with the Customer.
Where a Customer has a written agreement containing more specific provisions regarding subprocessors, processing locations, or deployment responsibilities, that agreement applies to the extent provided in that agreement.
1. What Is a Subprocessor?
A Subprocessor is a third-party service provider engaged by MYCURE that processes Customer Data on behalf of MYCURE in connection with providing MYCURE CMS.
A provider is not necessarily a Subprocessor merely because MYCURE uses its software, technology, or services.
For purposes of this list, Subprocessors generally do not include:
- •software libraries, frameworks, databases, caches, or other components operated within MYCURE-controlled infrastructure where no external provider independently receives Customer Data;
- •general website, corporate, administrative, sales, marketing, accounting, or business-service providers that do not process Customer Data on behalf of Customers through MYCURE CMS;
- •third-party services selected, enabled, or controlled independently by a Customer; or
- •infrastructure and service providers selected and controlled by a Customer for a client-hosted or customer-managed deployment.
Other personal data processed by MYCURE for its own business, account-administration, website, security, billing, or similar purposes is addressed in our Privacy Notice as applicable.
2. Current Material Subprocessors
The following providers currently process Customer Data in connection with the applicable MYCURE-hosted MYCURE CMS service.
| Provider | Service | Primary Processing Location | Customer Data Involved |
|---|---|---|---|
| DigitalOcean | Managed Kubernetes hosting, compute, networking, and managed database | United States | Potentially all Customer Data, depending on the infrastructure component used |
| Google LLC (Google Cloud) | Object and file storage, encrypted secret management, and Google sign-in (OAuth) | United States / configured per deployment | Customer Data (including file attachments), account identifiers, and application secrets |
| Postmark | Transactional and system email delivery, including account verification, password-reset communications, and other applicable service-related communications | United States | Primarily Authorized User names, email addresses, applicable message content, and delivery metadata |
Patient clinical information is not intentionally transmitted to Postmark as part of the currently described account-verification and password-reset workflows.
The providers and processing arrangements applicable to a particular Customer may vary based on deployment model, enabled functionality, geographic requirements, and the Customer’s applicable written agreement.
3. Deployment-Specific Processing
MYCURE CMS may be provided using different deployment models.
MYCURE-Hosted Deployments
For MYCURE-hosted services, MYCURE may engage infrastructure and other Subprocessors reasonably necessary to provide, operate, secure, maintain, support, and recover the applicable service.
Current material Subprocessors are identified above.
Client-Hosted or Customer-Managed Deployments
For client-hosted, private-cloud, or customer-managed deployments, the Customer may select, provide, administer, or control its own hosting environment, infrastructure providers, networks, storage, backup systems, security services, or other technology.
A provider selected or controlled by the Customer does not become a MYCURE Subprocessor solely because MYCURE CMS is deployed in or interacts with that environment.
The applicable Order Form, service agreement, data processing agreement, security agreement, Statement of Work, or other written agreement may further describe deployment-specific responsibilities.
4. Customer-Selected Third-Party Services
Customers may enable, request, or authorize MYCURE CMS to connect with third-party services.
Examples may include:
- •laboratories and diagnostic systems;
- •imaging or radiology systems;
- •pharmacies;
- •HMO, insurer, or payor systems;
- •payment services;
- •accounting systems;
- •messaging and communication services;
- •government or regulatory systems;
- •reporting or analytics services;
- •APIs; and
- •other Customer-selected integrations.
A third party selected or independently controlled by a Customer is not a MYCURE Subprocessor solely because MYCURE CMS transmits information to or receives information from that third party at the Customer’s instruction.
Customers are responsible for determining whether Customer-selected integrations and disclosures are appropriate and lawful for their use.
Third-party services may also be subject to their own terms, privacy notices, security practices, and data-processing arrangements.
5. Artificial Intelligence Services
MYCURE does not currently use a third-party artificial intelligence or large-language-model provider to process Customer Data as part of the production MYCURE CMS application.
MYCURE may introduce AI-assisted functionality in the future.
If an external AI or large-language-model provider is introduced and qualifies as a Subprocessor of Customer Data, MYCURE will address the applicable data-processing, authorization, security, and notice requirements and update this list as appropriate.
Use of development or internal productivity tools that do not receive production Customer Data does not make the provider of those tools a Subprocessor of Customer Data.
6. Subprocessor Safeguards
MYCURE requires Subprocessors processing Customer Data on its behalf to be subject to appropriate contractual, confidentiality, security, and data-protection obligations taking into account the nature of the service and applicable law.
Depending on the Processing, these arrangements may address matters such as:
- •processing instructions and permitted purposes;
- •confidentiality;
- •appropriate technical and organizational security measures;
- •access restrictions;
- •incident notification and cooperation;
- •data protection requirements;
- •onward processing;
- •return or deletion of data; and
- •other obligations appropriate to the Processing.
The specific obligations applicable to a Subprocessor may vary according to the nature of its service, the Customer’s deployment, and applicable law.
7. Changes to Subprocessors
MYCURE may add, replace, or discontinue Subprocessors as its services, infrastructure, security requirements, technology, availability requirements, and business operations evolve.
Where a new material Subprocessor will process Customer Data and an applicable written agreement or law requires notice or another documented mechanism, MYCURE will follow the applicable requirement.
Urgent changes may sometimes be necessary for security, legal, availability, continuity, or similar operational reasons. Where applicable, notice may be provided after such a change where prior notice is not reasonably practicable and the applicable agreement permits it.
This Subprocessor List is intended to remain current but does not permanently commit MYCURE to any particular infrastructure provider or technology.
8. Questions and Privacy Contact
Questions concerning this Subprocessor List, privacy, data protection, or security matters relating to MYCURE may be directed to:
Team OPS Inc. dba MYCURE
201 Malayan Plaza
ADB Avenue corner Opal Road
Ortigas Business Center
Pasig City, Philippines 1600
Privacy & Security Contact:
privacy@mycure.md