1. About This Document
This document lists all third-party subprocessors engaged by the Provider under the AITACS platform
— comprising AITACS CRM (AI Therapy Assistant Calendar Suite), ELIA (AI companion for End Clients), and NEVY Navigator
(holonic self-analysis tool). AITACS CRM is operated under skillbuilder.club and
aitacscrm.app; ELIA is operated under eliachat.app; NEVY Navigator is operated under skillbuilder.club.
It is maintained for all three products in accordance with GDPR Article 28(2) and the
Data Processing Agreement (DPA).
Products Covered
AITACS CRM (B2B — therapists, coaches, psychologists) · ELIA (B2C — AI companion for End Clients) · NEVY Navigator (B2C — holonic self-analysis). All three products are operated by Artem Chukov. AITACS CRM is available at skillbuilder.club and aitacscrm.app; ELIA is available at eliachat.app; NEVY Navigator is available at skillbuilder.club. Users of all three products are subject to this Subprocessor List.
1.1. The Controller has granted general written authorization for
the Processor to engage the subprocessors listed below (see DPA
§6.1).
1.2. The Processor shall notify the Controller at least 14
days in advance of any addition, removal, or replacement of a subprocessor. Notification will be sent
via email to the address associated with the Controller's account.
1.3. The Controller may object to a new subprocessor on reasonable
data protection grounds within the 14-day notice period. If the objection cannot be resolved, the Controller may
terminate the affected service component without penalty (see DPA
§6.3).
2. Summary
| Subprocessor |
Country |
Function |
Receives PHI? |
Transfer Safeguard |
| OpenAI, LLC |
USA |
AI processing |
No — de-identified data only |
SCCs + Safe Harbor de-identification |
| Hetzner Online GmbH |
Germany |
Database hosting |
Yes — encrypted |
SCCs + TLS 1.2+ |
| Google LLC (Firebase) |
USA |
Authentication |
No — email & UID only |
Google DPA + SCCs |
| PayPal Holdings, Inc. |
USA |
Payment processing — AITACS CRM subscriptions; ELIA purchases; referral affiliate payouts |
No — financial data only |
PCI DSS Level 1 + PayPal DPA + SCCs |
| Paddle.com Market Limited |
Ireland / USA |
Merchant of Record — NEVY Navigator payment processing, tax invoicing, VAT collection |
No — billing data only |
Paddle DPA + EU SCCs; PCI DSS Level 1 |
| Daily.co, Inc. |
USA |
WebRTC video infrastructure for therapy video sessions & transcription recording |
Conditional — real-time AV streams; no HIPAA BAA |
Daily.co DPA + SCCs; ⚠️ No HIPAA BAA |
| OpenAI, LLC (Whisper API) |
USA |
Speech-to-text transcription of session audio recordings |
Conditional — raw audio (potential PHI); zero-retention |
OpenAI DPA + SCCs; zero-retention API |
| Google LLC (Calendar API) |
USA |
Calendar synchronisation — therapist appointment scheduling via Google Calendar OAuth |
No — scheduling metadata only; no clinical data |
Google Cloud DPA + SCCs |
| Google LLC (Gemini API) |
USA |
AI analysis engine for NEVY Navigator (holonic self-analysis) |
No — de-identified user input; no PHI |
Google Cloud DPA + SCCs; zero-retention API |
3. Detailed Subprocessor Information
Function:
AI-assisted clinical session analysis, technique recommendations, progress summaries, and
general chat assistance within the Platform.
Data received:
De-identified data only: client pseudonym (nickname), age (integer, not
date of birth), gender, clinical context (presenting complaints, session notes, therapeutic goals) — all
scrubbed of residual PII patterns. See Privacy
Policy §2–3 for full data flow.
Data NOT sent:
Real names, dates of birth, phone numbers, email addresses, physical addresses, emergency
contacts, or any other direct identifier.
PHI status:
Not PHI — data is de-identified per HIPAA
Safe Harbor (45 CFR §164.514(b)) before transmission. All 18 identifier categories removed via dual-layer
filter (client-side + server-side).
Data retention:
Data processed via OpenAI API with zero-retention policy. API inputs and
outputs are not used to train models. Retention: 0 days (per OpenAI API Data Usage
Policy, effective March 2023).
Transfer safeguard:
OpenAI Data Processing Addendum, which incorporates EU Standard Contractual Clauses
(SCCs, Commission Implementing Decision (EU) 2021/914). Additional risk mitigation: data is de-identified
before transfer and does not constitute personal data under GDPR Art. 4(1).
DPA/BAA status:
Not required — de-identified data is not PHI;
no BAA obligation. For Enterprise deployments with identified PHI, a direct BAA with OpenAI is available (see
BAA §10).
Function:
MySQL database hosting, PHP application server, SSL/TLS termination, automated
backups.
Data received:
All CRM data including client records (names, contacts, clinical data),
User account data, session history, calendar events. Data is encrypted in transit (TLS 1.2+).
PHI status:
Contains PHI — the hosting provider stores
the MySQL database which contains identifiable client records. This is the primary PHI storage location for
SaaS deployments.
Data retention:
Data retained for the duration of the hosting agreement. Backups retained for up to 30
days. Full deletion upon account termination.
Transfer safeguard:
Standard Contractual Clauses (SCCs). TLS 1.2+ encryption for all data in transit.
Server-level access controls.
DPA/BAA status:
DPA required — the Processor maintains a
data processing agreement with the hosting provider. Migration to a HIPAA-certified hosting environment is
planned for Enterprise deployments.
Function:
User authentication and identity management. Provides secure sign-in (email/password,
OAuth) and unique User IDs (UIDs) for data isolation.
Data received:
User email address and UID only. No End Client data, no clinical data,
no PHI.
PHI status:
No PHI — Firebase receives only the User's
(therapist's) email and UID. No End Client information is transmitted to Firebase.
Data retention:
Per Google Firebase terms. User account data retained until account deletion.
Transfer safeguard:
Google Cloud DPA (includes SCCs). See Firebase Privacy and
Security.
DPA/BAA status:
DPA included — Google Cloud Data Processing
Terms apply automatically to Firebase services.
Function:
Payment processing for subscription purchases. Instant Payment Notification (IPN) for
license activation.
Data received:
User payment information only: email address, transaction ID, payment
amount, subscription plan. No clinical data, no End Client data.
PHI status:
No PHI — PayPal processes financial
transactions only. No health information is transmitted.
Data retention:
Per PayPal's data retention policy and applicable financial regulations.
Transfer safeguard:
PCI DSS Level 1 certified. PayPal User Agreement and Privacy Statement apply. SCCs for EU
data transfers.
DPA/BAA status:
Not required — no personal data processing
beyond standard payment execution.
Function:
Merchant of Record for NEVY Navigator subscription and analysis-pack purchases.
Paddle acts as the legal seller in the transaction — it charges the end-user's payment method, issues VAT-compliant
tax invoices, remits applicable taxes (VAT/GST), and processes refunds. The Provider receives a net revenue transfer
from Paddle after applicable fees.
Products:
NEVY Navigator (holonic self-analysis packs). AITACS CRM and ELIA subscriptions/purchases are
processed via PayPal (separate entry).
Data received:
User email address, display name, billing address (country + postal code), IP address,
payment method details (card brand + last 4 digits, or PayPal / Apple Pay / Google Pay token), transaction ID,
purchase amount, applicable tax rate. No clinical data, no End Client data, no PHI.
PHI status:
No PHI — Paddle processes financial and
identification data only. Zero clinical, psychological, or health data is transmitted.
Data retention:
Per Paddle's data retention policy and applicable financial / tax regulations. Paddle retains
transaction records as required by law (typically 7 years for financial records in Ireland).
Transfer safeguard:
Paddle Data Processing Agreement (DPA) incorporated into Paddle's Seller Agreement. EU Standard
Contractual Clauses (SCCs) for international transfers. PCI DSS Level 1 certified payment infrastructure.
DPA/BAA status:
DPA included — Paddle DPA is part of the Seller
Agreement accepted at registration. No HIPAA BAA required (no PHI processed).
Privacy Policy:
paddle.com/legal/privacy
Function:
WebRTC video conferencing infrastructure for AITACS CRM's Video Session & Transcription
feature. Provides real-time audio/video transmission between therapist and client. Audio is also captured
client-side for subsequent Whisper transcription.
Products:
AITACS CRM only. ELIA and NEVY Navigator do not use Daily.co.
Data received:
Real-time audio and video streams during active sessions. Daily.co processes WebRTC media in
transit. Streams are not stored by Daily.co — they are ephemeral. Room metadata: room token,
session duration, participant count.
PHI status:
Conditional PHI risk — real-time AV streams
during therapy sessions may contain identifiable patient information (voice, image, verbal disclosures).
This constitutes potential ePHI if the User is a US-based HIPAA Covered Entity.
⚠️ HIPAA notice:
No HIPAA Business Associate Agreement is in place with Daily.co.
US-based Covered Entities or Business Associates subject to HIPAA must not use the Video Session feature
for sessions involving identifiable PHI until an independent BAA is executed with Daily.co
(see Daily.co HIPAA)
or until the Provider obtains a BAA. See also BAA §5.
Data retention:
Real-time streams only — not retained by Daily.co post-session. The Provider captures audio
client-side for transcription and deletes raw audio files immediately upon transcription completion. No video
recordings are stored by the Provider or Daily.co.
Transfer safeguard:
Daily.co Data Processing Agreement + EU SCCs. SOC 2 Type II certified. See
Daily.co DPA.
DPA/BAA status:
DPA — Yes; HIPAA BAA — No — Daily.co DPA covers
GDPR. HIPAA BAA is not in place. See HIPAA notice above.
Function:
Speech-to-text transcription of therapy session audio recordings within AITACS CRM's
Transcription Module. Raw audio captured during video sessions is sent to OpenAI Whisper API and converted
to text. This is a distinct data flow from the main AI analysis (GPT) pipeline.
Products:
AITACS CRM (Transcription Module) only.
Data received:
Raw audio file of the therapy session recording. This audio may contain
the therapist's voice, the client's voice, and any verbal disclosures made during the session.
Unlike the main AI pipeline (de-identified text), audio is not pre-processed for de-identification
before transmission to Whisper.
PHI status:
Potential PHI — raw session audio constitutes
potential Protected Health Information if the client is identifiable by voice. This is a higher-risk data flow
than the primary GPT analysis pipeline.
⚠️ HIPAA notice:
No standalone HIPAA BAA with OpenAI Whisper API is maintained by the Provider.
OpenAI's standard API DPA covers Whisper under its zero-retention policy. US-based Covered Entities requiring
strict HIPAA BAA coverage for audio transcription must either: (a) execute a direct Enterprise agreement with
OpenAI including BAA coverage, or (b) obtain client consent acknowledging this limitation before recording.
See BAA §5.
Data retention:
Zero-retention. Per OpenAI API Data Usage Policy (effective March 2023),
API inputs and outputs are not retained by OpenAI beyond the duration of the API call and are not used for
model training. Raw audio files are permanently deleted from Provider servers immediately upon transcription
completion (or upon any error). Audio is never archived or stored long-term by the Provider.
Transfer safeguard:
OpenAI Data Processing Addendum (DPA) incorporating EU Standard Contractual Clauses (SCCs,
Commission Implementing Decision (EU) 2021/914). Zero-retention policy provides additional data minimisation.
DPA/BAA status:
DPA — Yes; HIPAA BAA — No (see above)
Function:
OAuth-based calendar synchronisation within AITACS CRM. When the User connects their Google
Account, AITACS CRM can read and write appointment events to the User's Google Calendar, enabling scheduling of
therapy sessions directly from the CRM interface. Also supports export of session data to Google Sheets / Docs.
Products:
AITACS CRM only. ELIA and NEVY Navigator do not use Google Calendar.
Data received:
Calendar event metadata created or modified by AITACS CRM: event title, date, time,
duration, optional notes. Important: The User is solely responsible for what information
they include in calendar event titles and descriptions. The Provider recommends using only client pseudonyms
(nicknames) — never real names — in calendar event titles. No clinical session content, session notes, or
diagnostic data is automatically exported to Google Calendar.
PHI status:
User-controlled risk — AITACS CRM transmits
scheduling metadata only. PHI risk depends entirely on what the User includes in event titles/descriptions.
Provider recommends pseudonym-only naming convention (see Security Requirements).
OAuth scope:
The Google Calendar integration requests the minimum necessary OAuth scopes:
calendar.events (read/write events). The User may revoke access at any time via
Google Account Permissions.
Data retention:
Calendar events are stored in the User's own Google Calendar account — governed by
Google's data retention and the User's own account settings. The Provider does not cache or store Google
Calendar data on Provider servers beyond the active session.
Transfer safeguard:
Google Cloud Data Processing Terms (incorporating SCCs). All API communication over
TLS 1.2+. OAuth 2.0 token management with short-lived access tokens.
DPA/BAA status:
DPA included — Google Cloud DPA covers
Calendar API. No HIPAA BAA required given no PHI is automatically transmitted (User responsibility for
naming convention).
Function:
Large language model (LLM) AI analysis engine powering NEVY Navigator's
Holarchy Singularity Core — a multi-agent system (Reality Context, Phenomenological, Symbolic Archetype, and
Strategic Executive agents). Processes user-submitted self-analysis inputs to generate holonic synthesis,
strategic recommendations, and archetype interpretations. Model used: Gemini 2.0 Flash.
Products:
NEVY Navigator only. AITACS CRM uses OpenAI GPT (separate entry). ELIA uses OpenAI GPT
(via backend API).
Data received:
User-submitted NEVY Navigator inputs: goal/aspiration text, reality description, meditative
state description, optional birth data (date of birth for archetype analysis), language preference, session history
context. No therapist data, no End Client clinical data, no AITACS CRM data.
PHI status:
No PHI — NEVY Navigator is a B2C self-analysis
tool, not a clinical platform. Data submitted is personal self-reflection content (goals, current reality,
meditative insights). While this data is personal and sensitive, it does not constitute Protected Health
Information (PHI) under HIPAA as NEVY Navigator is not a HIPAA-covered service.
Data retention:
Per Google Generative AI API Terms: API inputs and outputs are not used to train Google's
models and are subject to Google's standard API data handling. Analysis results are stored in the User's NEVY
Navigator account (Firebase Firestore) for session history. Raw prompt data is not retained by Google beyond
the API call duration.
Transfer safeguard:
Google Cloud Data Processing Terms (incorporating EU SCCs). All API communication
over TLS 1.2+. See
Gemini API
Terms of Service.
DPA/BAA status:
DPA included — Google Cloud DPA covers
Gemini API. No HIPAA BAA required (no PHI processed; NEVY is not a HIPAA-covered service).
4. Change Notification Policy
4.1. The Processor commits to maintaining this list in an accurate
and up-to-date state.
4.2. Before engaging any new subprocessor or replacing an existing
one, the Processor shall:
a) Update this Subprocessor List at
least 14 days before the new subprocessor begins processing data;
b) Send an email notification to all
active Users (Controllers) describing the change, the identity and location of the new subprocessor, and the data
it will process;
c) Allow the Controller to object
within the 14-day notice period on reasonable data protection grounds.
4.3. If the Controller objects and the Processor cannot reasonably
accommodate the objection (including by offering an alternative subprocessor or configuration), the Controller may
terminate the affected service component without penalty, as specified in DPA §6.3.
5. Change Log
Feb 20, 2026
Initial publication. Four subprocessors listed: OpenAI LLC,
Hetzner Online GmbH, Google Firebase, PayPal Holdings.
May 25, 2026
Major update — platform expansion to ELIA and NEVY Navigator.
Document scope extended to all three AITACS products on skillbuilder.club. Five new subprocessors added:
(1) Paddle.com Market Limited — Merchant of Record for NEVY Navigator subscription payments;
(2) Daily.co, Inc. — WebRTC video session infrastructure (⚠ no HIPAA BAA — US Covered Entities
must not conduct PHI-bearing sessions over video);
(3) OpenAI LLC — Whisper API — real-time audio transcription (⚠ no HIPAA BAA — zero-retention
policy confirmed, PHI in raw audio is a residual risk);
(4) Google LLC — Calendar API — OAuth-based calendar sync for session scheduling;
(5) Google LLC — Gemini API — NEVY Navigator holonic analysis engine (gemini-2.0-flash).
PayPal entry updated to clarify scope: AITACS CRM subscriptions, ELIA one-time purchases, and referral
affiliate payouts.
Subscribe to Updates
To receive notifications about subprocessor changes, ensure your account email is current in the Platform
settings. All change notifications are sent to the email address associated with your AITACS CRM account. You
may also check this page periodically for updates.