Legal
Subprocessors
Last updated: September 2026
Renvia engages the sub-processors listed below to deliver the platform. Each sub-processor is bound by a written contract with data-protection terms equivalent to those Renvia offers customers under our Data Processing Agreement.
Current sub-processors
| Sub-processor | Purpose | Hosting region | Data category |
|---|---|---|---|
| Supabase (managed Postgres, auth, storage) | Primary platform database, authentication and object storage | United Kingdom / EU | All platform data |
| Cloudflare | Edge network, DDoS protection, WAF and application delivery | Global (UK/EU PoPs preferred) | Request metadata; no clinical payloads at rest |
| Resend | Transactional email delivery (invitations, password reset, notifications) | EU | Recipient email address and message content |
| Sentry | Application error monitoring | EU | Error metadata; PII scrubbed |
Change notifications
We will provide at least 30 days' notice by email to customer-nominated privacy contacts before adding or replacing a sub-processor. To subscribe to change notifications, email privacy@renvia.health with the subject line "Subprocessor updates".
Objections
A customer may object in writing to a proposed change on reasonable data-protection grounds within the notice period. Renvia will work with the customer in good faith to resolve the objection or, if that is not possible, allow the customer to terminate the affected service.