SUBPROCESSOR SUMMARY
Who helps us run HarbourMind.
Argo Technology Group Limited, trading as HarbourMind 心港, uses contracted infrastructure and service providers ("subprocessors") that process limited personal data on our instructions. This page is a public summary to support transparency under the Personal Data (Privacy) Ordinance. It complements our Privacy Policy & Collection Notice at /privacy, which explains purposes, rights and safeguards in full.
How to read this page
Each entry below describes a vendor's role, the categories of data typically involved, and where processing may occur. Regions are indicative for the supervised beta and must be confirmed in each contract before production use.
We do not authorise subprocessors to use HarbourMind counselling content to train foundation models or build advertising profiles. Session audio and video are not recorded by default.
Status
This summary is draft for the supervised beta. Before public launch, Hong Kong counsel must approve the vendor list, each data-processing agreement, processing regions, retention, breach notification and cross-border safeguards. We will update this page when vendors change.
Fly.io
- Role: hosts HarbourMind API and background worker services.
- Typical data: account identifiers, booking and operational records, application logs and security telemetry needed to run the platform.
- Region: processing may occur outside Hong Kong (for example Singapore or other Fly.io disclosed regions). Location selection is not a residency guarantee.
Neon
- Role: managed PostgreSQL database for core platform data.
- Typical data: personal and operational records stored in HarbourMind, including profiles, matching intake, booking metadata, consent records and audit fields.
- Region: primary database region may be outside Hong Kong (for example Singapore — confirm project region in contract).
Upstash
- Role: Redis, queues and rate limiting for operational throughput and delayed jobs.
- Typical data: rate-limit counters, short booking-slot locks, and job payloads that reference record identifiers (for example reminder or retention job metadata).
- Region: processing may occur outside Hong Kong (for example Singapore or other disclosed Upstash regions).
Cloudflare (including R2)
- Role: content delivery network (CDN), DNS and object storage (R2) for static assets, counsellor verification documents and encrypted data-export packages.
- Typical data: IP addresses, request logs, cached static content; file names, checksums, storage metadata and encrypted export blobs where object storage is used.
- Region: global edge network; storage region hints (for example Asia-Pacific) do not guarantee Hong Kong residency.
Stripe or approved payment service provider (PSP)
- Role: client checkout, counsellor payouts, refunds and payment reconciliation (for example Stripe Connect where enabled).
- Typical data: name, email, payment references, connected-account identifiers, receipt and payout metadata. Full card numbers are handled by the PSP, not stored on HarbourMind servers.
- Region: processing often occurs outside Hong Kong per the PSP's data-processing agreement and card-network rules.
LiveKit (or approved selective forwarding unit)
- Role: real-time audio/video rooms for telehealth sessions.
- Typical data: room tokens, participant identifiers, connection telemetry and quality metrics. Session media are not recorded or transcribed by HarbourMind by default.
- Region: media routing may occur outside Hong Kong depending on vendor region choice and network path.
Identity provider (OIDC)
- Role: sign-in and token issuance for web and mobile applications.
- Typical data: authentication identifiers, email address, token metadata and sign-in audit events.
- Region: per the identity provider's region and data-residency settings configured for the beta.
Email, SMS and messaging (as configured)
- Role: transactional notices such as verification, booking reminders, receipts and operational alerts. WhatsApp Business or similar channels may be used for support where disclosed.
- Typical data: contact details, message templates and delivery metadata. Messages should not include counselling session content unless explicitly required for a disclosed support flow.
- Region: per each communications vendor's contract (often outside Hong Kong).
Device push (Expo, Apple, Google)
- Role: mobile push notifications for account, booking and safety notices.
- Typical data: device push tokens and notification metadata (titles and operational text — not clinical session content in notification bodies).
- Region: per Apple Push Notification service, Firebase Cloud Messaging / Google infrastructure and Expo's disclosed processing.
Related
For collection purposes, retention, your PDPO rights and cross-border safeguards, see /privacy. Questions about this register may be sent to the Privacy Officer listed there.