Back to policies
PRV-002 Record

Sub-Processor Register

Download PDF
Version: 1
Effective: 25 Mar 2026
Category: Privacy & Information
Organisation: Clinically
Contact: hello@clinically.com.au
Phone: +61 2 4092 7710
Website: https://clinically.com.au

About This Document

This register lists all third-party sub-processors that process personal information on behalf of healthcare practices using the Clinically platform. It is maintained to support compliance with APP 8 (cross-border disclosure) of the Australian Privacy Principles and to provide transparency to customers during procurement and due diligence.

Definitions

  • Sub-processor: A third party that processes personal information on behalf of Clinically in connection with providing the platform to healthcare practices.

  • Tenant-directed: Data exchange initiated and configured by the healthcare practice. Clinically facilitates the integration but the practice controls what data is shared.

  • DPA: Data Processing Agreement — a contractual agreement that governs how the sub-processor handles personal information, including security obligations, data residency, and breach notification.

  • Cross-border: Whether personal information is transferred to, or processed in, a jurisdiction outside Australia.

Summary

Sub-Processor

Service

Data Types

Location

Cross-Border

DPA

AWS

Infrastructure, AI

All patient data

Australia

No

On file

Cloudflare

DDoS, CDN, TLS

HTTP data (transient)

Global

Yes (transient)

On file

SMTP2GO

Email relay

Email content

Australia

No

On file

Notifyre

SMS, Fax

Phone numbers, message content

Australia

Verify

On file

Stripe

Billing

Organisation billing data

US

Yes (no patient data)

N/A

Slack

Error alerts

Error logs (no patient data)

US

Yes (no patient data)

N/A

Halaxy

EMR sync

Patient data (tenant-directed)

Australia

No

N/A

Genie

EMR sync

Patient data (tenant-directed)

Australia (local)

No

N/A

Services Australia

Medicare/IHI

Gov identifiers, demographics

Australia

No

N/A

Self-hosted services (not sub-processors): Meilisearch (search indexing), ClamAV (virus scanning), ocrmypdf (document OCR). These run within our own infrastructure and do not send data to third parties.

Detailed Sub-Processor Profiles

1. Amazon Web Services (AWS)

Legal entity

Amazon Web Services, Inc.

Services used

S3 (file storage), RDS (PostgreSQL databases), SES (email send/receive), SNS (webhook notifications), Bedrock (AI document classification and patient data extraction)

Jurisdiction

Australia (ap-southeast-2, Sydney)

Cross-border transfer

No. All services configured in ap-southeast-2. Bedrock processing remains in-region. AWS does not replicate data outside the configured region.

Security certifications

SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, IRAP (Australian Government), PCI DSS, HIPAA eligible

AI data handling

Bedrock: prompts and responses are not used to train models. No data retention after processing. AWS commits to not accessing customer data except as necessary to provide the service.

DPA in place

Yes

Last reviewed

23 March 2026

Data processed:

  • All patient data: demographics, clinical documents, health information, communications, appointments, form submissions

  • Government identifiers (Medicare, DVA, IHI) — encrypted at field level

  • Clinical documents — envelope encrypted with per-tenant keys

  • AI processing: document text including patient names, health conditions, Medicare numbers (Bedrock)

  • Database backups (encrypted at rest)

2. Cloudflare, Inc.

Legal entity

Cloudflare, Inc.

Services used

DDoS protection, CDN (content delivery network), TLS termination, DNS, Turnstile CAPTCHA on public forms

Jurisdiction

Global edge network

Cross-border transfer

Yes — HTTP requests transit through the nearest Cloudflare edge node, which may be outside Australia. Data is processed in memory only and not persistently stored. Cloudflare's Data Localisation Suite is available if required.

Security certifications

SOC 2 Type II, ISO 27001, PCI DSS Level 1, HIPAA compliant

DPA in place

Yes

Last reviewed

23 March 2026

Data processed:

  • HTTP request/response data (transient — in memory during request processing)

  • IP addresses, HTTP headers, request URLs

  • No persistent storage of patient data

3. SMTP2GO

Legal entity

SMTP2GO (a Mailguard company)

Services used

Outbound email relay for practice inbox communications

Jurisdiction

Australia (Australian data centres configured for this account)

Cross-border transfer

No. Account configured to use Australian data centres.

Security certifications

SOC 2, SPF/DKIM/DMARC support, TLS encryption in transit

DPA in place

Yes

Last reviewed

04 March 2026

Data processed:

  • Email addresses (sender and recipient)

  • Email content — may contain patient names, health information, appointment details, clinical correspondence

  • Email delivery status and metadata

4. Notifyre

Legal entity

Notifyre Pty Ltd

Services used

SMS delivery to patients and referrers; fax delivery and receipt

Jurisdiction

Australia (verify)

Cross-border transfer

Verify with Notifyre whether any data is processed or stored outside Australia.

Security certifications

HMAC webhook signature validation, TLS in transit

DPA in place

Yes

Last reviewed

23 March 2026

Data processed:

  • Patient phone numbers

  • SMS message content — may contain appointment details, practice communications

  • Fax content — may contain clinical documents, referrals, pathology results

  • Delivery status callbacks

5. Stripe

Legal entity

Stripe, Inc.

Services used

Subscription billing, payment processing for healthcare practice accounts

Jurisdiction

United States

Cross-border transfer

Yes — billing data only. No patient health information, government identifiers, or clinical data is transferred. Stripe is certified under the Data Privacy Framework.

Security certifications

PCI DSS Level 1, SOC 1/2, ISO 27001

DPA in place

Yes

Last reviewed

23 March 2026

Data processed:

  • Organisation name, ABN, administrator email

  • Stripe customer ID, subscription ID, payment method tokens

  • No patient data is sent to Stripe

6. Slack Technologies (Salesforce)

Legal entity

Slack Technologies, LLC (Salesforce, Inc.)

Services used

Developer error notifications, system health alerts

Jurisdiction

United States

Cross-border transfer

Yes — operational/error data only. Error logging is configured to exclude patient-identifiable information. Stack traces may incidentally include request context but not patient records.

Security certifications

SOC 2/3, ISO 27001, ISO 27017, ISO 27018

DPA in place

N/A

Last reviewed

23 March 2026

Data processed:

  • Application error messages, stack traces (truncated)

  • System health check results

  • No patient data in normal operation — errors are sanitised before dispatch

7. Halaxy

Legal entity

Halaxy Pty Ltd

Services used

EMR synchronisation — patient demographics, appointments, clinical documents exchanged at the tenant's direction

Jurisdiction

Australia

Cross-border transfer

No.

Security certifications

Australian healthcare EMR provider. Verify certifications directly with Halaxy.

DPA in place

N/A

Last reviewed

23 March 2026

Data processed:

  • Patient demographics (name, DOB, gender, contact details)

  • Appointments and scheduling data

  • Clinical documents and referrals (where sync is configured)

  • Data exchange is bidirectional and initiated by the tenant

8. Genie Solutions

Legal entity

Genie Solutions Pty Ltd (Citadel Health)

Services used

EMR synchronisation via bridge client — patient demographics, referrals, clinical documents

Jurisdiction

Australia (local installation at practice site)

Cross-border transfer

No. Genie is locally installed at the practice. Data exchange occurs between the Clinically platform and the local Genie instance.

Security certifications

Locally hosted. Security is managed by the practice's IT environment.

DPA in place

N/A

Last reviewed

23 March 2026

Data processed:

  • Patient demographics, referrals, clinical documents

  • Data exchanged via locally installed bridge client at the practice's direction

9. Services Australia (PRODA)

Legal entity

Services Australia (Australian Government)

Services used

Medicare and IHI verification via PRODA B2B authentication; provider number validation

Jurisdiction

Australia (Australian Government)

Cross-border transfer

No.

Security certifications

Australian Government security standards. PRODA B2B authentication with digital certificates.

DPA in place

N/A

Last reviewed

23 March 2026

Data processed:

  • Medicare numbers, Individual Healthcare Identifiers (IHIs)

  • Patient name and date of birth (for verification matching)

  • Provider numbers