Subprocessor List
This page lists the third-party subprocessors that Glass Box Solutions, Inc. ("Provider") engages to process Customer data in connection with the Adjudica.AI platform. This list is maintained pursuant to our Data Processing Agreement and Business Associate Agreements.
To receive notifications of subprocessor changes: Email privacy@adjudica.ai with subject "Subprocessor Updates Subscribe"
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| Google Cloud Platform (GCP) | United States (us-west1, us-central1) | Cloud infrastructure, data storage, computing | All Customer data including PHI | SOC 1/2/3, ISO 27001/17/18, HIPAA BAA, FedRAMP |
| Google Cloud SQL | United States (us-west1) | Database services | Structured data, case metadata, user data | SOC 2, ISO 27001, HIPAA BAA |
| Google Cloud Storage | United States (us-west1) | Document and file storage | Uploaded medical records, legal documents, PHI | SOC 2, ISO 27001, HIPAA BAA |
Contact: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043
Privacy Policy: https://cloud.google.com/terms/cloud-privacy-notice
Compliance: https://cloud.google.com/security/compliance
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| Google Gemini / Vertex AI | United States (us-west1) | AI language model for document analysis, legal research, OCR, text extraction | Medical records, legal briefs, user queries, case analysis (no model training) | SOC 2, ISO 27001, HIPAA BAA |
Google Contact: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043
Privacy Policy: https://cloud.google.com/terms/cloud-privacy-notice
Data Retention: Prompts and responses not retained beyond request processing (per BAA terms)
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| Pinecone | United States (us-west1-gcp) | Vector database for semantic search and document retrieval | Document embeddings (mathematical representations), metadata | SOC 2 Type II, HIPAA BAA |
Contact: Pinecone Systems, Inc., New York, NY
Privacy Policy: https://www.pinecone.io/privacy
Data Type: Embeddings only (not raw PHI text)
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| Google Identity Platform | United States | Authentication, SSO | User credentials, session data | SOC 2, ISO 27001, HIPAA BAA |
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| SendGrid (Twilio) | United States | Transactional email delivery | Email addresses, notification content | SOC 2 Type II, ISO 27001 |
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| Stripe | United States | Payment processing, billing | Payment information, billing details (no PHI) | PCI DSS Level 1, SOC 2 |
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| Google Cloud Operations | United States | System monitoring, logging | System logs, performance metrics (no PHI in logs) | SOC 2, ISO 27001 |
| Sentry | United States | Error tracking, application monitoring | Error reports, stack traces (no PHI) | SOC 2 Type II |
| Subprocessor | Location | Purpose | Data Processed | Certifications |
|---|---|---|---|---|
| [Support Platform TBD] | United States | Customer support ticketing | Support ticket content, contact info | SOC 2 |
| Subprocessor | PHI Access | BAA Executed |
|---|---|---|
| Google Cloud Platform | Yes | Yes |
| Google Gemini / Vertex AI | Yes | Yes |
| Pinecone | Limited (embeddings) | Yes |
| Google Identity | No | N/A |
| SendGrid | No | N/A |
| Stripe | No | N/A |
| Sentry | No | N/A |
Our AI provider (Google) is contractually prohibited from:
| Date | Change Type | Subprocessor | Description |
|---|---|---|---|
| [DATE] | Initial | All | Initial subprocessor list published |
User Upload → GCP Storage → Document AI (OCR) → Application Database (Cloud SQL)
↓
AI Processing (Google Gemini) → Vector Embeddings (Pinecone)
↓
Analysis Results → User Interface
| Activity | Subprocessors Involved | Data Movement |
|---|---|---|
| Document Upload | GCP Storage, Cloud SQL | User → GCP (us-west1) |
| OCR/Text Extraction | Google Vertex AI, Document AI | GCP Storage → Vertex AI → Cloud SQL |
| AI Analysis | Google Gemini | Cloud SQL → AI API → Cloud SQL (results) |
| Semantic Search | Pinecone | Document text → Embeddings → Pinecone index |
| Authentication | Google Identity | Browser → Google Identity → Application |
| Notifications | SendGrid | Application → SendGrid → User email |
| Error Logging | Sentry | Application errors → Sentry (no PHI) |
Geographic Boundaries: All data processing occurs within United States data centers. No cross-border transfers.
Note: We do not store Customer data outside the United States.
Pursuant to our Data Processing Agreement:
Notification methods:
Notification timeline:
To receive email notifications of subprocessor changes:
Update frequency: Immediate notification upon subprocessor addition/removal
If you object to a new subprocessor:
Step 1: Submit Objection (within 15 days of notification)
Step 2: Provider Response (within 10 business days)
Step 3: Resolution
Objections should be based on:
Before engaging any subprocessor, Glass Box Solutions conducts:
Security Assessment
Privacy Assessment
Contractual Requirements
Ongoing Monitoring
All subprocessors that process PHI have executed Business Associate Agreements:
| Subprocessor | BAA Status | BAA Date | Compliance Verified |
|---|---|---|---|
| Google Cloud Platform | ✓ Executed | [DATE] | Annual |
| Google Gemini / Vertex AI | ✓ Executed | [DATE] | Annual |
| Pinecone | ✓ Executed | [DATE] | Annual |
Verification: All BAAs reviewed annually and upon subprocessor security certification updates.
Subprocessors are designated as "Service Providers" under CCPA:
Service Provider Requirements Met:
| Subprocessor | SOC 2 Type II | Report Date | Next Review |
|---|---|---|---|
| Google Cloud | ✓ | [DATE] | Annual |
| Pinecone | ✓ | [DATE] | Annual |
| Sentry | ✓ | [DATE] | Annual |
| SendGrid | ✓ | [DATE] | Annual |
| Stripe | ✓ | [DATE] | Annual |
Monitoring: SOC 2 reports reviewed upon issuance; alerts set for expiration.
All subprocessors are contractually required to:
Upon subprocessor breach notification:
Within 24 hours:
Within 72 hours:
Ongoing:
Pursuant to our DPA and BAAs:
Customers may:
Limitations:
How to request:
For questions about our subprocessors:
Support hours: Monday-Friday, 9am-5pm Pacific Time
Emergency security contact: security@adjudica.ai (24/7 monitored)
| Date | Version | Changes |
|---|---|---|
| [DATE] | 1.0 | Initial publication |
| [DATE] | 1.1 | Added [Subprocessor Name] |
| [DATE] | 1.2 | Updated certifications |
Current Version: 1.0
Next Scheduled Review: [DATE]
This Subprocessor List is updated periodically. Last update: [INSERT DATE]
Glass Box Solutions, Inc.
@Developed & Documented by Glass Box Solutions, Inc. using human ingenuity and modern technology