Sub-processor List
These are the providers that process data for the Akoua service in Australia and New Zealand, what each one does, and where it does it. Every external processing hop the service makes is recorded immutably and is disclosable to your practice in-product — this list cannot silently drift from what actually runs.
United Kingdom organisations run a separate deployment with its own providers and geography — that list is at UK sub-processors.
Clinical data sub-processors
| Sub-processor | Purpose | Processing location | Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure: storage, database, compute | Australia (ap-southeast-2, Sydney) | Processing in-country; AWS DPA |
| Deepgram, Inc. | Automated speech-to-text of consult audio | Australia (Deepgram's Australian regional service) | Processing in-country; zero-retention configuration; model-improvement opt-out, enforced at start-up; Deepgram DPA |
| Amazon Web Services (AWS) — Bedrock | Automated drafting of clinical documentation (managed AI inference). Receives the transcript only — never the audio | Australia: Sydney and Melbourne (cross-region inference, ap-southeast-2 and ap-southeast-4) | Processing in-country; AWS commitment that customer content is not used to train models; AWS DPA |
| Amazon Web Services (AWS) — Textract | Text extraction from documents a practice uploads to a patient's record, for organisations with clinical documents (beta) switched on. A scanned page is sent as an image; a PDF that carries its own text layer is read without it | Australia (ap-southeast-2, Sydney) | Processing in-country; AWS DPA |
Practice-management integrations (optional; only if your practice connects one)
Cliniko is available to Australian practices; Nookal is currently disabled, and listed here ahead of any activation. Neither is enabled for New Zealand. Neither engages unless your practice connects it, and each only ever receives what the table says, and only when a clinician explicitly sends it — how connecting works. The United Kingdom deployment's UK list carries both, with Nookal likewise disabled there.
| Sub-processor | Purpose | Processing location | Safeguard |
|---|---|---|---|
| Cliniko | Practitioner and appointment identifiers, one linked patient's minimum demographics, and a confirmed note or letter when the clinician explicitly sends it | Australia — your practice's own Cliniko account, which must sit in a region approved for the Australian deployment | Your practice's own system under its own agreement with the vendor; approved-region allowlist enforced in code; only what the clinician explicitly sends |
| Nookal | Same as Cliniko. Integration currently disabled; listed for completeness ahead of any activation. | Australia — your practice's own Nookal account, which must sit in a region approved for the Australian deployment | Your practice's own system under its own agreement with the vendor; approved-region allowlist enforced in code; only what the clinician explicitly sends |
Account data sub-processors (business operations; no clinical data)
Some of these operate outside Australia. None of them receives clinical data — no consult audio, no transcript, no note. What they handle is billing, sign-in and app-store plumbing. The clinical pathway above stays in Australia.
| Sub-processor | Purpose | Processing location | Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) — Simple Email Service | Transactional email (sign-in codes, billing notices). Contact-form enquiries are also delivered to our inbox this way and may be processed outside Australia in transit | Australia (ap-southeast-2, Sydney) | Processing in-country; AWS DPA |
| Stripe | Subscription billing and payment processing | Stripe's standard locations (US/EU) | Stripe DPA and its transfer mechanisms |
| Cloudflare | Marketing site hosting; signup bot-protection (Turnstile); cookieless, aggregate web analytics for the marketing site; storage of website records — the updates list and contact-form enquiries — in a globally replicated store | Global edge; website records may be held outside Australia | No clinical data touches Cloudflare — the application hosts are deliberately not proxied |
| Apple | App Store purchases and App Attest device attestation for the iOS and macOS apps | Apple's standard locations | Apple's terms and its transfer mechanisms |
| Google Play billing and Play Integrity attestation for the Android app. When the ad-click sign-up measurement described in the privacy policy is switched on, Google also receives the ad's own click identifier with a conversion time and a random reference — never a name, email address, IP address, account identifier or any clinical datum | Google's standard locations | Google's terms and its transfer mechanisms |
What this list also tells you
- No model training on your data. The transcription provider's model-improvement programme is opted out, and the platform refuses to start if that opt-out is disabled while managed transcription is in use.
- Consult audio never reaches the drafting model. Only the attributed transcript does, and only with consent.
- No analytics, crash-reporting or advertising SDKs. There is no analytics SDK, crash reporter or advertising SDK in any Akoua app or on this site. The one advertising-related flow is the click-ID sign-up measurement described in the privacy policy — a first-party exchange that tells Google an ad click converted, never who converted.
Questions about this list: privacy@akoua.ai. How data is handled overall is in the privacy policy and privacy by design.