Ce document est actuellement disponible en anglais uniquement. La version française sera publiée après vérification juridique. (This document is currently available in English only.)

Legal

Subprocessors

These are the third parties that can process customer data on our behalf. Vendor reviews usually ask for this list first, so it is public. Named vendor entities, regions, and copies of their certifications are available on request from support@clinready.com; we will also notify customers by email before adding a subprocessor that can access document content.

  • Managed application & database platform

    Purpose: Hosting, application runtime, database, authentication, and document object storage

    Data in scope: All account, document, and audit data unless a workspace is configured with external PHI storage

  • Commercial AI gateway

    Purpose: Field detection, document drafting, contract review, and OCR when a workspace uses AI features

    Data in scope: Document text and images submitted to those features. No training rights are granted

  • Transactional email provider

    Purpose: Signature requests, reminders, completion notices, and account email

    Data in scope: Recipient name and email address, message subject and body, delivery events

  • Payment processor (Stripe)

    Purpose: Subscription billing, checkout, invoices, and receipts

    Data in scope: Billing contact, plan and seat quantity, payment method data held by the processor — never by us

  • External object storage (optional, per deployment)

    Purpose: Customer-elected storage of PHI-bearing document bytes in an S3-compatible bucket under the customer's own agreements

    Data in scope: Document objects only, when a workspace configures it

Our hosting platform does not offer a Business Associate Agreement today, which is why the BAA chain for protected health information is not yet complete. That gap, and the storage adapter built to close it, is described on the security and compliance page.