Oriste AI

Service providers and sub-processors

Last reviewed: 18 August 2026

Internally reviewed for a limited pilot. Independent legal review is required before public self-service sales.

HAGERSTANT LTD (HE 496930) operates Oriste AI. The product scope includes the providers below. The role column states how each provider handles personal data: the Article 28 sub-processor authorisation in our DPA covers only providers whose role is Sub-processor; independent controllers and controller-to-controller API counterparties are disclosed here for transparency but are not sub-processors. The status column distinguishes launch-required providers that remain technically blocked from providers enabled to process data on our behalf. Some providers may process or store data outside the EEA; before production use, each such transfer must be covered by an applicable Chapter V GDPR mechanism and documented safeguards. This list is kept current; material changes are reflected here. Questions and objections may be sent to privacy@oriste.ai.

Provider Role Purpose Data categories Region Status / transfer safeguards
Anthropic Sub-processor Core AI assistant, message generation, image description & intent classification Message text, appointment context, patient images Global processing; US storage by default Launch-required; runtime blocked pending written Article 9, DPA, transfer and retention approval
Deepgram Sub-processor Core voice-note transcription Voice audio, transcripts EU inference endpoint Launch-required; runtime blocked pending DPA and transfer approval
Meta Platforms (WhatsApp) Sub-processor (role allocation under review) WhatsApp Business messaging Phone numbers, message content Provider-dependent global infrastructure Public data and transfer terms identified; health-content role and retention review pending
Google Independent controller (controller-to-controller API terms) Calendar synchronisation Appointment metadata Provider-dependent global infrastructure API controller-to-controller terms, Limited Use compliance and OAuth approval required
Stripe Independent controller (payment services) Subscription billing Business billing details Provider-dependent Provider terms and regions must be verified before launch
Hetzner Sub-processor Application hosting All application data Germany / Finland (EEA) EEA processing
Sentry Sub-processor Error monitoring Technical logs (no client PII) Configured account region Data terms and applicable Chapter V safeguards required