Skip to content

Legal

GetClinic Subprocessor List

Version 1.0Effective 1 September 2026

Previously identified as SUB-2026.1

Version1.0
PublishedSeptember 1, 2026
EffectiveSeptember 1, 2026
ProviderGetClinic, Inc., a Delaware corporation
Applies WithPatient Privacy Policy; Consumer Health Data Privacy Policy

GetClinic, Inc. uses the third-party providers listed below to deliver the GetClinic services. This page is the list referred to in the Clinic Data Protection and Data Sharing Addendum (DPSA) §8 and in the Patient Privacy Policy.

Notice of change. Where a provider processes data for a designated Processor Service, GetClinic gives Clinics at least fifteen (15) days' advance notice before adding or replacing that provider. A Clinic may object during that period on reasonable documented data-protection grounds, as set out in DPSA §8.

How to receive notices. Email [email protected] with the subject line "Subprocessor notifications" and the Billing Entity name.


1. Infrastructure and core platform

ProviderPurposeData categoriesProcessing location
Amazon Web ServicesCloud hosting, storage, database, backups, key managementAll categories in DPSA Annex 1eu-central-1 (Frankfurt, Germany). CloudFront edge locations globally
StripePayment processing, Connect payouts, card dataPayment references, transaction and payout records. Card data is handled by Stripe and does not reach GetClinic systemsUnited States and Ireland
Mailgun / SinchTransactional email deliveryEmail address, message content, delivery logsEU endpoint in use (api.eu.mailgun.net)

2. Product analytics and monitoring

ProviderPurposeData categoriesProcessing location
GoogleGoogle Analytics 4 and Google Tag Manager - usage measurementPseudonymous usage events, device and browser data, page addressesUnited States
MicrosoftMicrosoft Clarity - usage measurement and interaction recordingInteraction recordings, device and browser dataUnited States
SentryError and performance monitoringError reports, technical diagnostics, stack tracesUnited States
LaunchDarklyFeature management and A/B testingAnonymous experiment identifier, variant assignment, conversion eventsUnited States
Google FirebaseMobile app push notification delivery and app analyticsDevice push token, app usage eventsUnited States

Scope limitation. These providers are used for the public marketplace and app surfaces. They are not used inside authenticated medical-document, consultation, private message or other private health-information areas.

ProviderPurposeData categoriesProcessing location
CloudflareTurnstile - bot and abuse protection on public formsIP address, browser challenge signalsUnited States and globally distributed
Usercentrics GmbHConsent management platform and consent record storageConsent choices, consent record identifier, timestamp
ProviderPurposeData categoriesProcessing location
Prighter GmbHPrivacy Rights Manager - channels, filters and structures data subject requests, then transfers the request and its personal data to GetClinicName, identification and contact details, and the content of the requestAustria (EU)
Hetzner Online GmbHData centre for the Privacy Rights Manager, engaged by PrighterAs aboveGermany (EU)

Prighter also acts as GetClinic's representative rather than as a processor: under Article 27 GDPR (Prighter EU Rep GmbH, Vienna), Article 27 UK GDPR (Prighter Ltd) and Article 13 of the DSA (Prighter GmbH, Vienna). In those roles Prighter is a controller for the advice and support it gives, and a processor for the request-handling tool above.

5. AI-assisted features

ProviderPurposeData categoriesProcessing location
OpenAIPowers the GetClinic assistant. Generates responses to patient questionsAssistant conversation content, which may include health information a patient chooses to shareUnited States

Patient control. The assistant asks separately before storing health details for reuse across a conversation. Declining means the details are used for that answer only.

Vendor data-use rule. GetClinic does not authorize any provider on this page to use Patient Health Data for that provider's unrelated advertising or unrelated general-purpose model training.


6. Operated by GetClinic, not subprocessors

Certain platform functions - including sign-in and identity, teleconsultation audio and video, and internal record-keeping - run on software operated by GetClinic on GetClinic's own infrastructure. No third party processes personal data to provide those functions, so they are not subprocessors and no vendor is engaged for them.


7. International transfers

GetClinic stores patient data at rest in the European Union (AWS eu-central-1). Several providers above process data in the United States. Where a transfer requires a mechanism under applicable law, GetClinic relies on the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914, the UK Addendum or UK IDTA as applicable, or an adequacy decision where one is in force and covers the transfer.