Sub-processors ‹ Back to Privacy Policy

Sub-processors

v1.1 · effective 11 June 2026

Clinically uses a small number of trusted third-party service providers ("sub-processors") to deliver the platform. This page lists each sub-processor, the role they play, the country in which they process data, and the contractual basis on which we rely on them. We disclose this list in accordance with APP 8 and APP 1.4(g) under the Privacy Act 1988 (Cth).

Primary data storage for practice details and signed consent records is in Australian regions. A small number of sub-processors (for example, our payments provider) may process some information outside Australia. In each case we take reasonable steps under APP 8(1) — including written data-processing terms and equivalent privacy protections — to ensure the recipient handles personal information consistently with the APPs.

Current sub-processors

Sub-processor Role Processing location Reasonable-steps basis
Supabase, Inc.
Managed database, authentication, object storage, edge functions
Primary store for practice and consent records. Holds the signed consent payloads, audit trail (viewed-at, signed-at, fingerprint), and practice configuration. Australia (ap-southeast-2) Data Processing Addendum with the platform vendor; AU-region project configuration; encrypted at rest by the managed service.
Amazon Web Services, Inc.
Cloud hosting — static pages, patient consent page, and practice dashboard
Serves the marketing site, the patient consent page, and the practice dashboard. Static assets only — no personal information is stored in the hosting layer, and patient identifiers placed in the URL fragment are never sent to the server. Australia (ap-southeast-2, Sydney) Data Processing Addendum; assets served from the Sydney (ap-southeast-2) region; Cache-Control: no-store and Referrer-Policy: no-referrer on the patient consent page.
SMTP2GO Pty Ltd
Outbound email — magic-link sign-in, consent PDF delivery, patient consent links, NDB notifications
Delivers practice-facing emails (passwordless sign-in links, signed AoB PDFs, billing receipts, breach notifications) and, where a practice has enabled patient communications, patient-facing emails containing a link to review and sign their Assignment of Benefit. We send the recipient's email address and the message content; no clinical detail beyond what the consent itself states is included. Australia Data Processing Addendum on file; TLS-encrypted submission; emails contain practice-side personal information, a signed AoB attachment for the practice's own records, or a patient's email address with a consent link.
Mobile Message Pty Ltd
Outbound SMS — patient consent links and reminders (only where a practice enables patient communications)
Where a practice has enabled patient communications, delivers SMS messages to patients on the practice's behalf — a link to review and sign their Assignment of Benefit, and related reminders. We send the patient's mobile number and the message text, which carries a consent link and practice identification only, not clinical detail. Australia Data Processing Addendum on file; Australian-based SMS aggregator; the message carries a tokenised consent link and the practice's name — no date of birth, Medicare number, or clinical information.
Stripe Payments Australia Pty Ltd
Subscription billing
Processes practice subscription payments and billing details. Operates as an independent controller of payment data under its own privacy policy. Australia, with cross-border processing for fraud-prevention and payments-network operations under Stripe's own APP 8 disclosures. Stripe is an APP entity itself; standard merchant terms; PCI DSS Level 1 service provider.

How we evaluate sub-processors

Before engaging any sub-processor that may handle personal information, we:

Notification of changes

We keep this page up to date as our sub-processors change. Material changes — new sub-processors, a change in processing location, or a change in role for an existing sub-processor — are reflected here, and practice administrators can check this page at any time.

Contact

For questions about a specific sub-processor, the contractual protections in place, or to request copies of the Data Processing Addendums on file, contact privacy@clinically.com.au.

Informational only — not legal advice. This list is published in support of APP 1.4(g) and APP 8 transparency obligations and forms part of the Clinically Privacy Policy at /privacy.