Legal
Subprocessors
These are the third parties that can process customer data on our behalf. Vendor reviews usually ask for this list first, so it is public. Named vendor entities, regions, and copies of their certifications are available on request from support@clinready.com; we will also notify customers by email before adding a subprocessor that can access document content.
Managed application & database platform
Purpose: Hosting, application runtime, database, authentication, and document object storage
Data in scope: All account, document, and audit data unless a workspace is configured with external PHI storage
Commercial AI gateway
Purpose: Field detection, document drafting, contract review, and OCR when a workspace uses AI features
Data in scope: Document text and images submitted to those features. No training rights are granted
Transactional email provider
Purpose: Signature requests, reminders, completion notices, and account email
Data in scope: Recipient name and email address, message subject and body, delivery events
Payment processor (Stripe)
Purpose: Subscription billing, checkout, invoices, and receipts
Data in scope: Billing contact, plan and seat quantity, payment method data held by the processor — never by us
External object storage (optional, per deployment)
Purpose: Customer-elected storage of PHI-bearing document bytes in an S3-compatible bucket under the customer's own agreements
Data in scope: Document objects only, when a workspace configures it
Our hosting platform does not offer a Business Associate Agreement today, which is why the BAA chain for protected health information is not yet complete. That gap, and the storage adapter built to close it, is described on the security and compliance page.
