GetClinic, Inc. uses the third-party providers listed below to deliver the GetClinic services. This page is the list referred to in the Clinic Data Protection and Data Sharing Addendum (DPSA) §8 and in the Patient Privacy Policy.
Notice of change. Where a provider processes data for a designated Processor Service, GetClinic gives Clinics at least fifteen (15) days' advance notice before adding or replacing that provider. A Clinic may object during that period on reasonable documented data-protection grounds, as set out in DPSA §8.
How to receive notices. Email [email protected] with the subject line "Subprocessor notifications" and the Billing Entity name.
1. Infrastructure and core platform
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| Amazon Web Services | Cloud hosting, storage, database, backups, key management | All categories in DPSA Annex 1 | eu-central-1 (Frankfurt, Germany). CloudFront edge locations globally |
| Stripe | Payment processing, Connect payouts, card data | Payment references, transaction and payout records. Card data is handled by Stripe and does not reach GetClinic systems | United States and Ireland |
| Mailgun / Sinch | Transactional email delivery | Email address, message content, delivery logs | EU endpoint in use (api.eu.mailgun.net) |
2. Product analytics and monitoring
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| Google Analytics 4 and Google Tag Manager - usage measurement | Pseudonymous usage events, device and browser data, page addresses | United States | |
| Microsoft | Microsoft Clarity - usage measurement and interaction recording | Interaction recordings, device and browser data | United States |
| Sentry | Error and performance monitoring | Error reports, technical diagnostics, stack traces | United States |
| LaunchDarkly | Feature management and A/B testing | Anonymous experiment identifier, variant assignment, conversion events | United States |
| Google Firebase | Mobile app push notification delivery and app analytics | Device push token, app usage events | United States |
Scope limitation. These providers are used for the public marketplace and app surfaces. They are not used inside authenticated medical-document, consultation, private message or other private health-information areas.
3. Security and consent
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| Cloudflare | Turnstile - bot and abuse protection on public forms | IP address, browser challenge signals | United States and globally distributed |
| Usercentrics GmbH | Consent management platform and consent record storage | Consent choices, consent record identifier, timestamp |
4. Privacy requests and legal representation
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| Prighter GmbH | Privacy Rights Manager - channels, filters and structures data subject requests, then transfers the request and its personal data to GetClinic | Name, identification and contact details, and the content of the request | Austria (EU) |
| Hetzner Online GmbH | Data centre for the Privacy Rights Manager, engaged by Prighter | As above | Germany (EU) |
Prighter also acts as GetClinic's representative rather than as a processor: under Article 27 GDPR (Prighter EU Rep GmbH, Vienna), Article 27 UK GDPR (Prighter Ltd) and Article 13 of the DSA (Prighter GmbH, Vienna). In those roles Prighter is a controller for the advice and support it gives, and a processor for the request-handling tool above.
5. AI-assisted features
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| OpenAI | Powers the GetClinic assistant. Generates responses to patient questions | Assistant conversation content, which may include health information a patient chooses to share | United States |
Patient control. The assistant asks separately before storing health details for reuse across a conversation. Declining means the details are used for that answer only.
Vendor data-use rule. GetClinic does not authorize any provider on this page to use Patient Health Data for that provider's unrelated advertising or unrelated general-purpose model training.
6. Operated by GetClinic, not subprocessors
Certain platform functions - including sign-in and identity, teleconsultation audio and video, and internal record-keeping - run on software operated by GetClinic on GetClinic's own infrastructure. No third party processes personal data to provide those functions, so they are not subprocessors and no vendor is engaged for them.
7. International transfers
GetClinic stores patient data at rest in the European Union (AWS eu-central-1). Several providers above process data in the United States. Where a transfer requires a mechanism under applicable law, GetClinic relies on the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914, the UK Addendum or UK IDTA as applicable, or an adequacy decision where one is in force and covers the transfer.