Legal

Subprocessors

Last updated · 29 Jul 2026

Radiant Science UG uses the subprocessors below to provide its services. A provider marked conditional processes data only when that integration or model is configured for a customer.

Processing location depends on the contracted service, account configuration, and provider. Where personal data is transferred outside the UK or EEA, Radiant requires an appropriate transfer mechanism under the UK GDPR and EU GDPR, such as an adequacy decision, Standard Contractual Clauses, and the UK International Data Transfer Addendum. For restricted transfers, Radiant records a transfer risk assessment covering the destination country, the applicable UK or EU transfer regime, and the legal basis before the provider is enabled.

Listing a technically available provider does not by itself authorize its use. Before a provider processes patient or other customer personal data, Radiant's DPO must confirm the DPA, transfer mechanism, processing location, retention and training settings, and any controller authorization required by the customer contract.

Patient and service-user data

The data in this section may include contact details, call audio, transcripts, appointments, and special-category health data, depending on the configured workflow.

  • Twilio Inc.

    Telephony and SMS between the service, clinics, and service users.

    Privacy policy · DPA

  • Microsoft Corporation (Azure, Azure OpenAI, Azure AI Foundry and Azure Realtime)

    Cloud infrastructure, databases, storage, communications, embeddings, speech, and language-model processing. Services are configured by deployment and customer use case.

    Privacy statement · Microsoft Products and Services DPA

  • Amazon Web Services EMEA SARL (AWS Bedrock) — conditional

    Language-model inference, including supported third-party models made available through AWS Bedrock. When a model is invoked through Bedrock, AWS is the infrastructure subprocessor for that request.

    AWS privacy notice · AWS data protection terms

  • Soniox Inc.

    Speech-to-text processing for call audio.

    Privacy policy

  • Deepgram Inc. — conditional

    Primary or fallback speech-to-text processing for call audio, depending on configuration.

    Privacy policy · Subprocessor information

  • Cartesia AI, Inc.

    Text-to-speech processing for generated call audio.

    Privacy policy DPA

  • Eleven Labs Inc. — conditional

    Speech-to-text or text-to-speech processing when an ElevenLabs integration is configured. Regional processing depends on the contracted ElevenLabs account and endpoint.

    Privacy policy DPA

  • Mistral AI SAS — conditional

    Text-to-speech or language-model processing when a Mistral integration is configured.

    Privacy policy DPA

  • LiveKit Inc.

    Real-time audio transport and managed call-session infrastructure.

    Privacy policy DPA

  • Anthropic PBC — conditional, direct API only

    Language-model inference when Radiant uses Anthropic's direct commercial API. Claude models invoked through AWS Bedrock are covered by the AWS entry rather than a direct Anthropic API transfer.

    Privacy information Commercial DPA information

  • X.AI LLC — conditional

    Language-model inference when an xAI enterprise API model is configured.

    Privacy policy DPA

  • Google LLC (Google AI / Gemini API) — conditional

    Language-model inference when a paid Google AI service is configured. Radiant does not use unpaid consumer-tier processing for patient data.

    Gemini API terms Google processor terms

Optional patient communications

Customer and operational data

These providers process customer contacts, staff account data, support information, or sanitized operational metadata. Radiant policy prohibits placing raw patient data, call recordings, transcripts, credentials, tokens, or request bodies in Slack, Linear, Plain, or similar business systems.

  • Vercel Inc.

    Hosts and deploys the web application.

    Privacy policy · DPA

  • WorkOS, Inc.

    Dashboard authentication, customer account setup, and access control.

    Privacy policy · DPA

  • Slack Technologies, LLC

    Internal and customer communication using sanitized business and incident data.

    Privacy policy · DPA

  • Microsoft Corporation (Microsoft 365 and SharePoint)

    Business communication, controlled documents, and restricted incident-evidence storage.

    Privacy statement · Microsoft Products and Services DPA

  • Google LLC (Google Cloud and Google Workspace)

    Business communication and configured cloud services.

    Cloud privacy notice · Cloud DPA

  • Linear Orbit, Inc.

    Product delivery and incident coordination using sanitized data and restricted evidence links.

    Privacy policy DPA

  • Not Just Tickets Ltd (Plain)

    Customer request management. Processes customer and clinic staff contact details and support correspondence using sanitized business data.

    Privacy policy · DPA

  • Browserbase, Inc. — conditional

    Remote browser rendering for customer website onboarding. It processes website content and technical session metadata; it is not used for live patient-call processing.

    Privacy policy