1. What counts as a sub-processor
Under UK GDPR / EU GDPR Article 28, a sub-processor is any third party engaged by Clincue that processes personal data on behalf of a clinic (the controller). This does not include vendors that only process Clincue's own operational data (e.g. our accountants) or services the clinic connects directly to its own account.
2. Current list
| Vendor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Lovable Cloud (Supabase backbone) | Application hosting, Postgres database, authentication, object storage | European Union (Frankfurt) | Intra-EEA — no transfer mechanism required |
| Cloudflare, Inc. | CDN, DDoS protection, edge routing for clincue.com | Global edge network; contractual EU/UK data residency where applicable | UK IDTA / EU SCCs (2021/914) — module 2/3 |
| Paddle.com Market Ltd | Merchant of Record — payment processing, tax handling, invoicing | United Kingdom / European Union | Separate controller — Paddle Buyer Terms apply |
| Resend Inc. | Transactional and authentication email delivery | European Union (Frankfurt) primary; US secondary | EU SCCs / UK IDTA where US processing occurs |
| NVIDIA Corporation (NIM inference) | Large-language-model inference for agent responses | United States | UK IDTA / EU SCCs (2021/914) — module 2 |
| Google LLC (Gemini API via Lovable AI Gateway) | Fallback LLM inference and speech-to-text | United States and European Union | UK IDTA / EU SCCs where US processing occurs |
| OpenAI, L.L.C. (TTS via Lovable AI Gateway) | Voice sample generation and text-to-speech | United States | UK IDTA / EU SCCs (2021/914) — module 2 |
| Meta Platforms Ireland Ltd (WhatsApp Business API) | WhatsApp channel message delivery — only if the clinic enables WhatsApp | European Union / United States | EU SCCs / UK IDTA per Meta's controller-to-processor terms |
3. Notice of changes
We give clinic account owners at least 30 days' notice before adding or replacing a sub-processor, via in-product notice and email. If the clinic reasonably objects on data-protection grounds it may terminate the affected service under the Data Processing Agreement without penalty for the unused portion of the term.
4. Transfer safeguards
Where a sub-processor operates outside the UK/EEA, we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses (Commission Decision 2021/914), together with supplementary measures such as encryption in transit and at rest, access controls, and vendor security assessments. Copies of the applicable transfer mechanisms are available to clinics on request to privacy@clincue.com.
5. Questions
Data-protection questions about any vendor listed above go to privacy@clincue.com. General security enquiries are covered in our Security overview.