Clincue

Sub-processors

Clincue uses a small, deliberate set of sub-processors to run the platform. This page lists every one, what they do, where they process data, and the transfer safeguard that applies. It is updated whenever a sub-processor is added, removed, or its role changes.

Last updated: 19 July 2026

1. What counts as a sub-processor

Under UK GDPR / EU GDPR Article 28, a sub-processor is any third party engaged by Clincue that processes personal data on behalf of a clinic (the controller). This does not include vendors that only process Clincue's own operational data (e.g. our accountants) or services the clinic connects directly to its own account.

2. Current list

VendorPurposeRegionTransfer mechanism
Lovable Cloud (Supabase backbone)Application hosting, Postgres database, authentication, object storageEuropean Union (Frankfurt)Intra-EEA — no transfer mechanism required
Cloudflare, Inc.CDN, DDoS protection, edge routing for clincue.comGlobal edge network; contractual EU/UK data residency where applicableUK IDTA / EU SCCs (2021/914) — module 2/3
Paddle.com Market LtdMerchant of Record — payment processing, tax handling, invoicingUnited Kingdom / European UnionSeparate controller — Paddle Buyer Terms apply
Resend Inc.Transactional and authentication email deliveryEuropean Union (Frankfurt) primary; US secondaryEU SCCs / UK IDTA where US processing occurs
NVIDIA Corporation (NIM inference)Large-language-model inference for agent responsesUnited StatesUK IDTA / EU SCCs (2021/914) — module 2
Google LLC (Gemini API via Lovable AI Gateway)Fallback LLM inference and speech-to-textUnited States and European UnionUK IDTA / EU SCCs where US processing occurs
OpenAI, L.L.C. (TTS via Lovable AI Gateway)Voice sample generation and text-to-speechUnited StatesUK IDTA / EU SCCs (2021/914) — module 2
Meta Platforms Ireland Ltd (WhatsApp Business API)WhatsApp channel message delivery — only if the clinic enables WhatsAppEuropean Union / United StatesEU SCCs / UK IDTA per Meta's controller-to-processor terms

3. Notice of changes

We give clinic account owners at least 30 days' notice before adding or replacing a sub-processor, via in-product notice and email. If the clinic reasonably objects on data-protection grounds it may terminate the affected service under the Data Processing Agreement without penalty for the unused portion of the term.

4. Transfer safeguards

Where a sub-processor operates outside the UK/EEA, we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses (Commission Decision 2021/914), together with supplementary measures such as encryption in transit and at rest, access controls, and vendor security assessments. Copies of the applicable transfer mechanisms are available to clinics on request to privacy@clincue.com.

5. Questions

Data-protection questions about any vendor listed above go to privacy@clincue.com. General security enquiries are covered in our Security overview.