Clinically uses a small number of trusted third-party service providers ("sub-processors") to deliver the platform. This page lists each sub-processor, the role they play, the country in which they process data, and the contractual basis on which we rely on them. We disclose this list in accordance with APP 8 and APP 1.4(g) under the Privacy Act 1988 (Cth).
Primary data storage for practice details and signed consent records is in Australian regions. A small number of sub-processors (for example, our payments provider) may process some information outside Australia. In each case we take reasonable steps under APP 8(1) — including written data-processing terms and equivalent privacy protections — to ensure the recipient handles personal information consistently with the APPs.
| Sub-processor | Role | Processing location | Reasonable-steps basis |
|---|---|---|---|
| Supabase, Inc. Managed database, authentication, object storage, edge functions |
Primary store for practice and consent records. Holds the signed consent payloads, audit trail (viewed-at, signed-at, fingerprint), and practice configuration. | Australia (ap-southeast-2) | Data Processing Addendum with the platform vendor; AU-region project configuration; encrypted at rest by the managed service. |
| Amazon Web Services, Inc. Cloud hosting — static pages, patient consent page, and practice dashboard |
Serves the marketing site, the patient consent page, and the practice dashboard. Static assets only — no personal information is stored in the hosting layer, and patient identifiers placed in the URL fragment are never sent to the server. | Australia (ap-southeast-2, Sydney) | Data Processing Addendum; assets served from the Sydney (ap-southeast-2) region; Cache-Control: no-store and Referrer-Policy: no-referrer on the patient consent page. |
| SMTP2GO Pty Ltd Outbound email — magic-link sign-in, consent PDF delivery, patient consent links, NDB notifications |
Delivers practice-facing emails (passwordless sign-in links, signed AoB PDFs, billing receipts, breach notifications) and, where a practice has enabled patient communications, patient-facing emails containing a link to review and sign their Assignment of Benefit. We send the recipient's email address and the message content; no clinical detail beyond what the consent itself states is included. | Australia | Data Processing Addendum on file; TLS-encrypted submission; emails contain practice-side personal information, a signed AoB attachment for the practice's own records, or a patient's email address with a consent link. |
| Mobile Message Pty Ltd Outbound SMS — patient consent links and reminders (only where a practice enables patient communications) |
Where a practice has enabled patient communications, delivers SMS messages to patients on the practice's behalf — a link to review and sign their Assignment of Benefit, and related reminders. We send the patient's mobile number and the message text, which carries a consent link and practice identification only, not clinical detail. | Australia | Data Processing Addendum on file; Australian-based SMS aggregator; the message carries a tokenised consent link and the practice's name — no date of birth, Medicare number, or clinical information. |
| Stripe Payments Australia Pty Ltd Subscription billing |
Processes practice subscription payments and billing details. Operates as an independent controller of payment data under its own privacy policy. | Australia, with cross-border processing for fraud-prevention and payments-network operations under Stripe's own APP 8 disclosures. | Stripe is an APP entity itself; standard merchant terms; PCI DSS Level 1 service provider. |
Before engaging any sub-processor that may handle personal information, we:
We keep this page up to date as our sub-processors change. Material changes — new sub-processors, a change in processing location, or a change in role for an existing sub-processor — are reflected here, and practice administrators can check this page at any time.
For questions about a specific sub-processor, the contractual protections in place, or to request copies of the Data Processing Addendums on file, contact privacy@clinically.com.au.