Legal
Sub-processors
Last updated 28 August 2026
These are the third parties that may process customer or patient data on our behalf. Each is bound by a written agreement no less protective than our own commitments. Optional connectors process data only after you switch them on.
| Provider | Purpose | Location | Data | Status |
|---|---|---|---|---|
| Amazon Web Services | Hosting, storage, key management, transactional email | United States (us-east-1) | All customer and patient data | BAA accepted 25 Aug 2026 |
| Retell AI | Telephony and voice for the AI receptionist | United States | Call audio, transcripts, caller number | BAA in place |
| Stripe | Subscription billing and card payments | United States | Billing contact and payment details. No patient data. | PCI DSS Level 1 |
| NexHealth | Practice management system connector | United States | Appointment and patient records you elect to sync | Optional — off by default |
| Calendar booking, where connected | United States | Appointment times and attendee details | Optional — off by default | |
| Microsoft | Calendar booking, where connected | United States | Appointment times and attendee details | Optional — off by default |
To be told when this list changes, write to privacy@minnato.ai and ask to be added to sub-processor notifications.
Start by finding out what your websites are leaking.
A free scan of any practice site tells you in ninety seconds which trackers are loading on pages that collect patient information. No account, no card.