Subprocessors
Rehuman Subprocessors
Last Updated: October 21st, 2025
Overview
Rehuman uses the following third-party subprocessors to support the delivery of its services, including hosting, product infrastructure, analytics, communications, and customer support.
Rehuman is an insurtech platform helping individuals store, understand, and manage their insurance information. Because of the sensitivity of this data, we perform extensive diligence on all subprocessors’ privacy, security, and data handling practices.
All subprocessors are subject to a written data processing agreement that includes obligations equivalent to those imposed on Rehuman under applicable data protection laws (e.g., UK GDPR Art. 28, EU GDPR Art. 28, and CCPA §1798.140(v)).
We update this list periodically and will notify customers in advance of any material changes.
Cloud Infrastructure & Hosting
These subprocessors provide the cloud infrastructure that powers Rehuman’s core platform, including the Rehuman Wallet, AI-powered policy processing, user account management, and CRM tools.
Subprocessor: AWS
Geographic Location: Global
Role: Cloud Hosting
Data Transfer Mechanism: SCCs, DPA
Subprocessor: Google Cloud
Geographic Location: Global
Role: Cloud Hosting
Data Transfer Mechanism: SCCs, DPA
Subprocessor: Microsoft
Geographic Location: Global
Role: Email and Infrastructure (Outlook, Office365)
Data Transfer Mechanism: SCCs
Subprocessor: Supabase
Geographic Location: EU/US
Role: Managed Postgres Backend
Data Transfer Mechanism: SCCs
Subprocessor: SmartBear
Geographic Location: US
Role: Monitoring/testing
Data Transfer Mechanism: SCCs
Communication & Email Services
These subprocessors support Rehuman’s email delivery, outreach automation, and marketing workflows, including transactional messages from the platform.
Subprocessor: Brevo
Geographic Location: EU
Role: Marketing emails
Data Transfer Mechanism: SCCs
Subprocessor: Zapier
Geographic Location: US
Role: Sales/Outreach
Data Transfer Mechanism: SCCs
Subprocessor: Apollo
Geographic Location: US
Role: Automated email/workflows
Data Transfer Mechanism: SCCs
Subprocessor: Postmark
Geographic Location: US
Role: Transactional emails
Data Transfer Mechanism: SCCs
Product Analytics & User Behaviour Tracking
These tools support product usage tracking, session insights, and performance analytics. They help improve UX and personalize platform experiences.
Subprocessor: Hotjar
Geographic Location: EU
Role: UX tracking, heatmaps
Data Transfer Mechanism: SCCs
Subprocessor: Mixpanel
Geographic Location: US
Role: Product analytics
Data Transfer Mechanism: SCCs
Subprocessor: Pusher
Geographic Location: UK/EU
Role: Real-time data updates
Data Transfer Mechanism: SCCs
Form and Web Tools
Used for customer-facing website and form interactions.
Subprocessor: Webflow
Geographic Location: US
Role: Website hosting
Data Transfer Mechanism: SCCs
Subprocessor: Typeform
Geographic Location: EU
Role: Web forms
Data Transfer Mechanism: SCCs
Developer & Testing Tools
Any use of real user data is restricted to secure, access-controlled environments and minimized to what is strictly necessary for testing. Anonymization or pseudonymization is applied wherever feasible in line with the principle of data minimization (GDPR Art. 5(1)(c)).
Subprocessor: Postman
Geographic Location: US
Role: API testing/automation
Data Transfer Mechanism: SCCs
AI & Language Model Tools
Processing is based on Rehuman’s legitimate interests in maintaining platform functionality and internal efficiency (UK/EU GDPR Art. 6(1)(f)). No customer-specific decision-making or profiling is carried out using AI systems.
Subprocessor: OpenAI
Geographic Location: US
Role: Natural Language Processing
Data Transfer Mechanism: SCCs, API Terms
Note: Rehuman uses OpenAI APIs for internal automation tasks (e.g., summarization, general AI capabilities).No identifiable personal or customer data is shared with OpenAI. All prompts are anonymized or synthetic. Rehuman does not use OpenAI for outbound customer communication, profiling, or policy decision-making.
Support & Services
These subprocessors are used to provide customer support for our Services.
Subprocessor: Office 365
Geographic Location: US
Role: Support Communications (email, docs)
Data Transfer Mechanism: SCCs
Data Transfer Safeguards & Notification
All international transfers of personal data are governed by the use of Standard Contractual Clauses (SCCs) or similar safeguards. We assess subprocessor risk prior to engagement and notify customers of material changes to this list via email or dashboard notifications at least 30 days in advance.
Processors’ Subprocessors
Some subprocessors listed above may use their own subprocessors (e.g., cloud infrastructure, logging services), which are contractually bound to equivalent security and privacy obligations via back-to-back DPAs.
Other Tools and Services (Non-Core / Contextual Use Only)
Rehuman may use additional third-party tools on an ad hoc or non-production basis (e.g., recruitment platforms, event registration, beta-testing environments). These are isolated from core user data and subject to internal approval before use.