Clinilo

Subprocessor List

This register is the authorized provider set proposed for ordinary-data-only Managed Launch. It identifies actual production roles, verified primary locations and known backup limitations.

Status
Published
Version
managed-launch-subprocessors-2026-08-17
Effective date
2026-08-17

A subprocessor processes Customer Personal Data for Clinilo in delivering the clinic service. Clinilo FZE LLC is the processor and importer, not its own subprocessor. Its legal contact and appointed EU representative are identified in section 1 of the Platform Terms. Provider brands below are paired with the contracted or DPA legal entity and their actual limited purpose under policy ordinary-data-only-2026-08-16.

Health data and all other special categories are prohibited. Vercel’s current DPA separately prohibits special-category Customer Data. No row authorizes a health-data payload, and provider activation cannot expand the Customer’s accepted instruction.

Managed Launch provider register
Provider / legal entityPurpose and data boundaryLocation, safeguards and verified limits
Vercel / Vercel Inc.Sites and Dashboard hosting: request metadata, credentials and ordinary submitted content. An authenticated every-minute cron in fra1 processes due database jobs.Functions are source-pinned to Frankfurt fra1 despite the dashboard default showing iad1. US provider/support and onward locations use the Vercel DPA and SCCs where required. Special-category Customer Data is prohibited by the DPA.
Supabase / Supabase Pte. Ltd.Managed PostgreSQL for ordinary application, authentication and audit data. It also stores the durable job_outbox queue, scheduled reminder instants, leases, attempt counters and fixed delivery outcomes.Production primary is Frankfurt eu-central-1 on Pro. Daily backups currently retain the last seven days, exclude Storage objects and do not establish PITR. Singapore entity/provider locations use the DPA and SCCs where required.
Cloudflare R2 / Cloudflare, Inc.Private non-clinical tenant assets.Bucket clinilo-prod has EU jurisdiction, public development access disabled, no custom domain and CORS limited to https://app.clinilo.com for PUT with Content-Type. Only incomplete multipart uploads have a seven-day abort rule. No independent backup, object versioning or lock is represented. US provider/support uses DPA/SCC safeguards where required.
Resend / Plus Five Five, Inc.Email recipient, sender, subject, ordinary body, secure booking links and non-clinical attachments.United States; Resend DPA and SCCs where required. No health data is permitted in messages.
GatewayAPI.eu / ONLINECITY.IO ApSSMS recipient number, clinic sender label, ordinary appointment time and secure manage/unsubscribe link.Denmark / EEA; no health data is permitted in SMS.
Sentry / Functional Software, Inc.Bounded error code/name, area, tenant ID, environment and release only; request bodies and contact/health text are excluded.United States; Sentry DPA and SCCs where required.
Not authorized to receive Managed Launch Customer Data
ServiceCurrent status
StripeNo platform subscription or client online-payment processing under DKK 0; no payment credentials collected.
PostHogDormant no-op adapter; no browser SDK or analytics cookie active.
Anthropic or another AI modelNo clinic or client content sent; a future AI purpose requires a separate assessment and agreement.
Mailpit, MinIO and console adaptersLocal development only and prohibited as production providers.

Source code, an environment variable or a dormant adapter is not authorization. Before any listed inactive service receives Customer Personal Data, Clinilo must verify entity, role, purpose, data, locations, retention, security and transfer mechanism; update the DPA, privacy/cookie notice where relevant; give required advance notice; and activate it through protected deployment.

Clinilo gives the clinic’s registered legal contact at least 30 days’ direct advance notice before a new or replacement subprocessor begins processing. Notice identifies the entity, purpose, data, locations and transfer safeguards. An objectively urgent security/legal need may shorten the period only to the extent necessary, with as much prior notice as practicable. No provider starts first and receives retroactive authorization.

A clinic may object on reasonable data-protection grounds at casper@swprlabs.com during the notice period. Clinilo seeks an additional safeguard or alternative; if none is reasonably available, the clinic may terminate the affected service before processing begins without a fee. Change history begins with this published 2026-08-17 revision and each published successor records its effective date and added, replaced or removed providers. Retained versions remain accessible.

Primary application compute and database are configured in Frankfurt; R2 is under EU jurisdiction. Contracting entities, support or onward processing for Vercel, Supabase, Cloudflare, Resend and Sentry may involve non-EEA countries. Where required, Clinilo uses DPA terms, SCCs, transfer assessment, minimization, least privilege, encryption where applicable, legal review, reasonable challenge of demands and notice where permitted. UAE access by Clinilo is covered by the Customer-to-Clinilo Module 2 SCCs in the DPA.

Recovery claims are deliberately limited: Supabase daily database backups currently cover the last seven days and exclude object assets; no PITR is represented. R2 has no represented independent backup, object versioning or lock. Current tenant-prefixed assets are included in the owner export when allowed by the ordinary-data policy. Provider-only dashboards, logs, versions and histories that Clinilo does not hold are not part of that archive.

Open the portability register