The third parties we work with
SRS engages a small set of third-party service providers (“sub-processors”) to operate our marketing websites and run our business. This page lists each provider, what data they receive, where they process it, and on which of our domains they are deployed.
A sub-processor is a third party that processes personal information on behalf of SRS to help us deliver our websites and services. This page covers the sub-processors that handle data about website visitors and prospects.
The sub-processors that handle Customer Data (Protected Health Information and other regulated information about our customers’ patients, caregivers, and end users) are governed by our customer Business Associate Agreements and are described at category level in Section 4. The full list is provided to customers on request through the BAA notification process.
About This List
SRS Web Solutions, Inc. (“SRS,” “we”) maintains this Sub-Processor List to give our customers, prospects, and the public a clear, current view of the third parties we use. We update this list when we add, replace, or remove a sub-processor.
This document is published as a companion to our Privacy Policy and Cookie Policy, which describe what personal information we collect, how we use it, and your privacy rights. Capitalized terms not defined here have the meanings given in the Privacy Policy.
Two scoping points to keep in mind as you read:
- This list covers our marketing and website operations — the data flows that arise when someone visits one of our websites, requests a demo, applies for a job, or otherwise interacts with us as a prospect.
- It does not cover the third parties that handle Customer Data inside our products. Those are listed in the BAA Schedule we provide to each customer and updated under the BAA notification process. See Section 4.
How We Use Sub-Processors
We use sub-processors only where doing so is necessary to operate our business. Each sub-processor is selected through our vendor-review process, contractually bound to confidentiality and data-protection obligations appropriate to the data they handle, and limited to processing data for the purposes we direct.
2.1 What sub-processors can and cannot do
- Can: process the data we send them strictly to deliver the contracted service to SRS (for example, sending a demo confirmation email, generating analytics reports, recording a cookie preference).
- Cannot, except as expressly permitted under contract or as disclosed in our Privacy Policy and Cookie Policy: use that data for their own marketing, sell it, share it with other clients, or combine it with information from other sources to identify individuals.
2.2 Cross-context behavioral advertising sub-processors
A small number of our sub-processors—currently Meta Platforms, Inc. (Meta Pixel) and HubSpot, Inc.—may use the data we send them in ways that constitute “sharing” for cross-context behavioral advertising under California and similar state privacy laws. These are clearly identified in Section 3, and California residents and other consumers with applicable rights may opt out through the methods described in our Privacy Policy and Cookie Policy, including by clicking “Do Not Sell or Share My Personal Information” in the footer of mconsent.net or caretap.net.
2.3 Hosting regions
Most of our sub-processors are U.S.-based companies that process data on servers located in the United States. Several (Google, Microsoft, Meta, HubSpot, Zoho) operate globally and may process data on servers located in other regions of the United States or, in limited cases, abroad. SRS itself is a U.S. company, and our marketing websites are intended for use in the United States.
Marketing & Website Sub-Processors
The current sub-processors handling website-visitor and marketing data are listed below, organized by function. The deployment status indicates which of our domains each provider is currently active on. Each card links to the provider’s privacy policy so you can review their practices directly.
Automattic, Inc.WordPress.com / VIP
Active- Service
- Hosting and content delivery for srswebsolutions.com.
- Data Categories
- IP address, browser/device telemetry, server logs, form submissions in transit.
- Hosting Region
- United States
- Deployed On
- SRS mConsent · not deployed Caretap · not deployed
- Privacy Policy
- automattic.com/privacy
Google LLCGoogle Workspace
Active- Service
- Business email, document storage, and internal collaboration for SRS personnel.
- Data Categories
- Email correspondence, documents, calendar entries, and identifiers of SRS staff and the parties they communicate with.
- Hosting Region
- United States · Global Google infrastructure
- Deployed On
- SRS internal use across all domains
- Privacy Policy
- policies.google.com/privacy
WPForms, LLCWordPress form plugin
Active- Service
- Contact, demo, and investor inquiry forms on our Websites.
- Data Categories
- Name, email, phone, company, and other information you submit through forms.
- Hosting Region
- United States
- Deployed On
- SRS mConsent Caretap
- Privacy Policy
- wpforms.com/legal/privacy-policy
Google LLCGoogle Analytics 4
Active- Service
- Aggregate website traffic and performance analytics, subject to cookie consent.
- Data Categories
- Page views, time on site, referral source, browser and device telemetry, IP address (truncated).
- Hosting Region
- United States · Global Google infrastructure
- Deployed On
- SRS · planned mConsent Caretap
- Privacy Policy
- policies.google.com/privacy
Microsoft CorporationMicrosoft Clarity
Active- Service
- Heatmap and session-recording analytics. Captures visitor mouse movements, clicks, scrolls, and form interactions on the page in order to generate aggregated usability analytics.
- Data Categories
- Cursor movement, click and scroll events, page-level form interactions (excluding sensitive fields where Clarity’s masking is configured), browser and device telemetry, IP address.
- Hosting Region
- United States · Microsoft Azure
- Deployed On
- SRS · not deployed mConsent Caretap
- Privacy Policy
- privacy.microsoft.com/privacystatement
Zoho CorporationZoho Analytics
Active- Service
- Aggregate visitor analytics on mconsent.net.
- Data Categories
- Page views, time on site, referral source, browser and device telemetry, IP address.
- Hosting Region
- United States
- Deployed On
- SRS · not deployed mConsent Caretap · not deployed
- Privacy Policy
- zoho.com/privacy
Meta Platforms, Inc.Facebook Pixel & Conversions API
Active · CPRA “sharing”- Service
- Advertising-conversion measurement and retargeting on Meta platforms (Facebook and Instagram). Constitutes “sharing” of personal information for cross-context behavioral advertising under California and similar state privacy laws.
- Data Categories
- Page-view events, conversion events, browser and device identifiers, IP address, advertising identifiers.
- Hosting Region
- United States · Global Meta infrastructure
- Deployed On
- SRS · planned mConsent Caretap
- Privacy Policy
- facebook.com/privacy/policy
HubSpot, Inc.Marketing Hub & tracking pixel
Active · CPRA “sharing”- Service
- Marketing automation, lead tracking, and email-campaign attribution. May constitute “sharing” of personal information for cross-context behavioral advertising under California and similar state privacy laws.
- Data Categories
- Page-view events, form submissions, email engagement, contact records (name, email, company), browser and device identifiers, IP address.
- Hosting Region
- United States · Global HubSpot infrastructure
- Deployed On
- SRS · planned mConsent · not deployed Caretap
- Privacy Policy
- legal.hubspot.com/privacy-policy
Termly, Inc.Consent management platform
Active- Service
- Cookie consent banner, recording of consent choices, processing of opt-out requests, and honoring of Global Privacy Control signals.
- Data Categories
- Cookie consent records, opt-out requests, IP address, browser identifier.
- Hosting Region
- United States
- Deployed On
- SRS mConsent Caretap
- Privacy Policy
- termly.io/our-privacy-policy
Zoho CorporationZoho CRM & Zoho One
Active- Service
- Managing sales inquiries, prospect records, and customer communications. Separate deployment from Zoho Analytics.
- Data Categories
- Prospect and customer name, email, phone, company, role, opportunity history, sales-conversation notes.
- Hosting Region
- United States
- Deployed On
- SRS internal use across all domains
- Privacy Policy
- zoho.com/privacy
LinkedIn CorporationLinkedIn Talent / Recruiter
Active- Service
- Receiving and processing employment applications submitted through our careers page.
- Data Categories
- Applicant name, contact information, resume, work history, references, and other application data.
- Hosting Region
- United States · Global LinkedIn infrastructure
- Deployed On
- SRS careers
- Privacy Policy
- linkedin.com/legal/privacy-policy
Indeed, Inc.Indeed Hire / Employer
Active- Service
- Receiving and processing employment applications submitted through our careers page.
- Data Categories
- Applicant name, contact information, resume, work history, references, and other application data.
- Hosting Region
- United States
- Deployed On
- SRS careers
- Privacy Policy
- indeed.com/legal/privacy
SRS Affiliate OfficeTrivandrum, India
Active- Service
- Engineering, quality assurance, and Level 1 / Level 2 technical support performed by personnel of an SRS affiliate, under SRS direction and the same policies that apply to U.S. personnel.
- Data Categories
- Limited access to website analytics, support-ticket metadata, and (for personnel supporting Customer Data) Customer Data only as necessary to provide support and only under the applicable BAA.
- Hosting Region
- India (access only; primary data continues to reside on U.S.-based systems)
- Deployed On
- All domains and Services
- Governance
- Same confidentiality, security, and access-control requirements as U.S. personnel; access to PHI governed by the customer BAA.
Active — the sub-processor is currently receiving data from SRS on the listed domains. Planned — SRS intends to deploy this sub-processor on the listed domain in the future. We will update this list before any data begins flowing. Not deployed — the sub-processor is not active on the listed domain.
Customer Data Sub-Processors
This section covers sub-processors that handle Customer Data inside our Services (mConsent, Caretap, mPayr, Zaha AI), including any Protected Health Information uploaded by our customers. These are governed by our customer Business Associate Agreements rather than this public list.
The categories of Customer Data sub-processors we engage include:
- Cloud infrastructure and hosting — the cloud platforms on which our production environments operate, encrypted at rest and in transit, with role-based access controls.
- Database and storage — managed database and object-storage services that hold Customer Data within our production environment.
- Email and SMS delivery — transactional and customer-directed messaging that the customer enables through the Services (for example, appointment reminders, intake-form invitations).
- Payment processing — PCI-DSS-validated payment processor used by mPayr to handle card and ACH transactions. SRS does not store full primary account numbers (PANs).
- AI and speech services — the AI providers underlying Zaha AI’s automated speech recognition, natural language understanding, and large language model components, used only on Customer Data under the direction of the practice customer.
- E-prescribe — iCoreConnect, Inc. provides the underlying e-prescribing platform that mConsent’s E-prescribe feature integrates with. iCoreConnect is responsible for compliance with federal and state e-prescribing regulations, including DEA EPCS where applicable.
- EVV aggregator integrations — for Caretap, the state Medicaid program’s designated EVV aggregator or system of record receives EVV data under section 12006 of the 21st Century Cures Act, only at the customer’s direction.
- Customer-success and support tooling — ticketing, knowledge base, and customer-communications platforms used by SRS support staff.
4.1 How customers obtain the full list
The current, named Customer Data sub-processor list is maintained as a schedule to each customer’s Business Associate Agreement and Services Agreement. Existing customers can request the current list at any time by contacting privacy@srswebsolutions.com. Prospective customers conducting due diligence may request the list under a mutual non-disclosure agreement.
4.2 BAA-governed change notifications
Material changes to the Customer Data sub-processor schedule (for example, adding a new sub-processor that will handle PHI) are communicated to existing customers through the BAA’s change-notification process, with reasonable advance notice and, where applicable, an opportunity to object.
Onboarding & Removal
5.1 Onboarding a new sub-processor
Before SRS engages a new sub-processor that will handle personal information, we conduct a vendor review proportionate to the sensitivity of the data and the role of the vendor. The review typically covers:
- the vendor’s privacy and security posture (including SOC 2, ISO 27001, HIPAA, or other certifications, where relevant);
- the vendor’s contractual data-protection commitments, including any data-processing addendum or Business Associate Agreement;
- the data categories that will be processed, the purpose, and the geographic scope of processing; and
- the operational fit and our ability to oversee, monitor, and terminate the engagement.
5.2 Removing a sub-processor
When we remove a sub-processor (for example, because we are migrating to a different vendor or because a service is being decommissioned), we:
- terminate or wind down the data flow to that vendor;
- request return or deletion of any data the vendor still holds, in accordance with the contract;
- update this list and the Privacy Policy to reflect the removal; and
- retain a record of the removal in our internal vendor register.
Notification of Changes
We update this Sub-Processor List when we add, replace, or remove a sub-processor in scope. The mechanism for notifying you depends on whether you are a customer or a member of the public.
6.1 For customers
For customers under an executed Master Services Agreement and Business Associate Agreement, material changes to the Customer Data sub-processor schedule are communicated through the BAA’s change-notification process, as described in Section 4.2. Material changes to the marketing/website sub-processors listed in Section 3 are communicated through updates to this list and the Privacy Policy.
6.2 For visitors and prospects
The most current version of this list is always available at srswebsolutions.com/sub-processors. Changes are reflected in the “Last Updated” date at the top, in the Recent Changes log in Section 7, and in the version number.
6.3 Subscribe to update notifications
To receive an email when this Sub-Processor List is materially updated, send a request to privacy@srswebsolutions.com with the subject “Subscribe to Sub-Processor Updates.” Include your name, organization, and email address. You can unsubscribe at any time by replying with “Unsubscribe.”
Recent Changes
The log below tracks material changes to this Sub-Processor List. The most recent change is at the top.
Contact
For questions about this Sub-Processor List, to request the Customer Data sub-processor schedule, or to subscribe to update notifications, contact us using any of the channels below.
Mailing Address
SRS Web Solutions, Inc.
Attn: Privacy Contact
6885 139th LN NW, Suite 100
Ramsey, MN 55303
United States