SERVICE PROVIDERS

Service Providers & Subprocessors

How RTH evaluates hosting, security, payment, analytics, AI, research, and other providers—and the subprocessor register required before sensitive product data is routed externally.

Effective: September 9, 2026  ·  Last reviewed: September 9, 2026  ·  Architecture: RTH Governance 2.0

Status: Current governance standard for applicable RTH public operations. Product-specific controls apply when the relevant product or program is enabled.

1. Why RTH uses providers

RTH may rely on providers for hosting, security, content delivery, email, analytics, payment, fulfillment, customer support, storage, identity, AI infrastructure, communications, or other functions. A provider receives only the data reasonably needed for the approved service and remains subject to applicable contract and law.

2. Current public website

The public website uses a managed hosting environment and may use additional providers when forms, commerce, analytics, email, or fulfillment features are enabled. RTH will keep the public Privacy Policy aligned with the technologies actually active rather than publish a speculative vendor list.

3. SuperstarIQ subprocessor register

Before SuperstarIQ accepts external product or health data, RTH will maintain a named subprocessor register identifying material providers, purpose, data categories, processing location or region where material, and whether the provider may engage subprocessors. Material changes will be reviewed before sensitive data is routed to the new provider.

4. Vendor due diligence

Review depth depends on risk. Sensitive-data and AI providers require review of security posture, privacy terms, breach notification, retention/deletion, training-data use, confidentiality, access control, availability/resilience, subprocessor chain, geographic processing, legal obligations, and relevant certifications or independent reports where available.

5. Contracts and data-use limits

RTH will use appropriate data-processing, confidentiality, business-associate, research, school/student, or security terms when the workflow requires them. Provider use of RTH data for unrelated advertising or model training must be prohibited when inconsistent with the approved purpose.

6. Provider changes

A provider change can trigger privacy, security, connected-source, AI, research, contractual, or regional review. RTH will not treat a technical vendor swap as non-material when it changes where sensitive information goes or how it may be used.

7. Third-party services chosen by a user

When a user independently directs RTH to transmit data to an external recipient or integration, that recipient may act under its own terms rather than as an RTH processor. RTH will make that distinction clear where practical.

Privacy and data requests: privacy@restartingtheheart.com. Do not send medical records, passwords, authentication codes, government identifiers, or other unnecessary sensitive information by ordinary email.

Security reports: security@restartingtheheart.com. See the Vulnerability Disclosure Policy before performing security testing.

General questions may use the RTH contact page.