Skip to main content
Conexion
Login
Privacy Terms Cookies AUP Security Subprocessors

Effective version: 2026-05-02

Subprocessor List

Conexion Platform — Community Intelligence LLC

Last Updated: 2026-05-02

DISCLAIMER: This document is a template and should be reviewed by qualified legal counsel before use with clients.


1. Overview

This document lists the third-party service providers ("Subprocessors") that may process Client Data on behalf of Community Intelligence LLC in connection with the Conexion platform.

Subprocessors are engaged in accordance with our Data Processing Agreement. For Clients who process Protected Health Information (PHI), we maintain signed Business Associate Agreements (BAAs) with all Subprocessors that are capable of accessing PHI in unencrypted form.

We notify Clients at least 30 days before adding a new Subprocessor.


2. Active Infrastructure Subprocessors

These providers operate the Platform infrastructure for the current production deployment.

ProviderServiceData ProcessedLocationBAA Status
Google Cloud PlatformCloud Run (compute)All Client DataUS (multi-region, configurable)Covered by signed Google Cloud HIPAA BAA
Google Cloud PlatformCloud SQL for PostgreSQL (database)All Client DataUSCovered by signed Google Cloud HIPAA BAA
Google Cloud PlatformCloud Storage (uploaded documents + media)Files uploaded by Client staffUSCovered by signed Google Cloud HIPAA BAA; bucket-level encryption with Google-managed keys
Google Cloud PlatformMemorystore for Redis (cache + Celery broker)Session data, transient task payloadsUSCovered by signed Google Cloud HIPAA BAA
Google Cloud PlatformSecret ManagerEncryption keys, OAuth credentials, API keysUSCovered by signed Google Cloud HIPAA BAA
Google Cloud PlatformCloud LoggingApplication logs (PII-redacted)USCovered by signed Google Cloud HIPAA BAA

3. Active AI Processing Subprocessors

These providers process data only when Client staff initiate AI-powered features (grant writing, data analysis, chat assistant).

ProviderServiceData ProcessedLocationBAA Status
Anthropic (via Google Vertex AI)Claude family of large language modelsPrompt content as composed by Client staff (may include grant text, funder information, program descriptions, and Client-selected entity context)USCovered by Google Cloud HIPAA BAA — all model traffic is routed through Vertex AI; the direct Anthropic API is disabled in the production environment via the AI_HIPAA_MODE setting

Important Notes:

  • Conversation history is stored in the Client's own Conexion database, not retained by the model provider beyond the API request.
  • Data sent through Vertex AI is not used to train Anthropic or Google models, per Vertex AI enterprise terms.
  • Tracing is configured to record metadata only (AI_TRACE_CONTEXT="metadata_only") — full prompt content is not retained in trace logs.
  • Clients should still avoid pasting specific participant identifiers alongside health information into AI prompts as a defense-in-depth measure.

4. Off-Site Backup Storage

ProviderServiceData ProcessedLocationBAA Status
Google Cloud PlatformCloud Storage bucket in a separate GCP regionEncrypted database and media backupsUS (different region from primary)Covered by signed Google Cloud HIPAA BAA

Backups are encrypted both at the application layer (GPG / AES-256 before upload) and at the storage layer (Google-managed encryption keys). The off-site region is geographically separated from the primary deployment region for disaster-recovery purposes.


5. Monitoring Subprocessors

For the current production deployment:

ProviderServiceBAA StatusNotes
(none)Application error tracking is disabled in this deploymentN/ASentry is supported by the Platform but is not enabled for PHI-bound deployments. Errors are surfaced via Cloud Logging only.

If error tracking is enabled in the future for this Client, we will sign Sentry's BAA before activation, notify the Client at least 30 days in advance per Section 7 of the DPA, and update this list.


6. Client-Configured Integration Subprocessors

These services become Subprocessors only when the Client enables the integration. They are not active by default.

Currently active for this deployment

ProviderServiceData ProcessedBAA Status
Google Workspace (Drive)Document storage and retrievalDocuments the Client elects to sync to or from Google DriveCovered under the Client's Google Workspace BAA (the Client is the Google Workspace customer)

Available but not currently active

The following integrations are supported by the Platform but are not configured for this deployment. If the Client enables any of these in the future, we will notify the Client and update this list.

ProviderServiceData Categories
Microsoft 365 (Outlook + OneDrive/SharePoint)Email sync, document storageEmail messages, attachments, documents
Gmail (Google)Email syncEmail messages, attachments
Monday.comProject and grant management syncGrant data, program data, task data, contact names
SalesforceCRM data importParticipant data, organizational data
Meta (Facebook/Instagram)Page insights connectorPublic engagement metrics only
QuickBooks OnlineFinancial data syncBudget, expense, transaction data
XeroFinancial data syncBudget, expense, transaction data

7. Services NOT Used

For clarity, we do not use the following types of services:

  • No advertising or marketing analytics platforms
  • No social media tracking or pixels embedded in the Platform
  • No customer data platforms (CDPs)
  • No data brokers or enrichment services
  • No cookie-consent management platforms (we use only strictly-necessary cookies)
  • No third-party AI providers other than those listed in Section 3 (OpenAI and Google Gemini SDK code paths exist but are disabled in production by AI_HIPAA_MODE)

8. Changes to This List

We will notify Clients at least 30 days before adding a new Subprocessor or before enabling a Client-Configured Integration on the Client's behalf. Clients may object to new Subprocessors per the terms of our Data Processing Agreement.

To subscribe to Subprocessor change notifications, contact: privacy@communityintelligence.io


9. Contact

For questions about our Subprocessors:

Email: privacy@communityintelligence.io

© 2026 Community Intelligence LLC. All rights reserved.
Privacy Terms Acceptable Use Security Cookies Subprocessors