Ohio’s Turn-Key DODD Compliance Platform.Not affiliated with the Ohio Department of Developmental Disabilities
Legal

Subprocessors

To operate DODD Agency Pro, we rely on a small number of trusted third-party service providers (subprocessors). This page lists who they are, what they do, and exactly what client information each one does — and does not — receive.

Last updated: August 12, 2026

Scope & Approach

This page describes providers and data paths that are visible in the current application code and configuration. It does not claim that a particular contract, BAA, certification, or regional hosting commitment is in place unless an executed agreement says so.

The Client Compliance Tracking encrypts client names with AES-256-GCM before storage. Its bounded service and service-span fields are not field-encrypted. Other enabled client-related modules have separate data models and may rely on tenant and role-based access controls instead.

AI-facing routes and the email queue include detectors intended to block likely client-identifying content before it is sent. Those controls reduce risk but are not described here as a guarantee that no sensitive content can ever reach a provider.

Current Subprocessors
SubprocessorPurposeRegionClient information received
DigitalOcean
Production cloud hosting and database infrastructureNot asserted hereHosts the application and database records. Client Compliance Tracking names use application-level AES-256-GCM encryption; other records may rely on infrastructure and access controls rather than field-level encryption.
Resend
Transactional and notification email deliveryNot asserted hereReceives account, contact-form, and notification content sent through the email pipeline. The pipeline scans outgoing content for likely client-identifying information before enqueueing it.
OpenAI
AI-assisted compliance features and knowledge-base embeddingsNot asserted hereReceives user prompts, retrieved compliance context, and text submitted to the embedding pipeline. Chat and form-generation routes scan prompts for likely client-identifying information before model calls. The application does not use OpenAI for client-record storage.
Stripe
Subscription checkout, billing, and payment lifecycle eventsNot asserted hereReceives billing and subscription information used for checkout and account billing. Client operational records are not part of the Stripe integration.

Provider exposure depends on the integration described above. Application-level encryption applies only to fields specifically identified as encrypted; it is not a claim that every database field or backup is encrypted by the application.

Requesting BAA & Subprocessor Details

Agencies may request a copy of our Business Associate Agreement (BAA) and additional detail about any subprocessor listed here — including the categories of data involved and the safeguards in place. We will provide this information to support your own compliance and vendor due-diligence obligations.

To make a request, contact the Privacy and security contact at support@doddagencypro.com, or reach us through our contact page. Please do not include any client or individual information in your request.

We may update this list as our services evolve. When a subprocessor that handles protected information is added or changed, this page will be revised and the "Last updated" date above will reflect the change.