Back to Home

Sub-processors

Attorney review draft — not final

This page is provided for transparency during counsel review. It is not legal advice, not an offer to contract, and not evidence of HIPAA compliance or regulatory certification. Executed agreements control for paying customers.

Last reviewed: July 10, 2026 · Referenced by the Data Processing Agreement

The vendors below process or transmit customer data on ClinicWarden's behalf. We notify customers at least 15 days before adding a new sub-processor.

VendorPurposeData classesRegionBAA / DPA
SupabaseManaged Postgres, RLS, Storage buckets, AuthOperational, restricted identity, credential documents, intake documentsUSBAA on file
VercelApplication hosting, edge middlewareRequest metadata, cookies, IPUSDPA on file
ResendTransactional email (notifications, digests, magic links)Recipient email, subject, body summaryUS / EUDPA on file
UpstashRate limiting (Redis)IP-derived keys, countersMulti-regionDPA on file
StripeSubscription billingOrganisation billing contact, card metadata (never card PANs)USDPA on file
Cloudflare (via Vercel)Edge DNS, WAFRequest metadataGlobalSub-processor of Vercel

Sub-sub-processors

Vercel and Supabase publish their own sub-processor lists at vercel.com/legal/subprocessors and supabase.com/legal/subprocessors. Any change there is reviewed against the ClinicWarden risk register.

Change process

  1. Platform proposes the vendor and completes a security review.
  2. Legal reviews the vendor's DPA + BAA (when PHI is involved).
  3. Customers are notified 15 days before the vendor goes live.
  4. This page and docs/subprocessors.md are updated with the new row.

Contact

Sub-processor change notifications: founder@clinicwarden.com