Sub-processors
Everyone who can touch your practice’s data
The short version
- Two are engaged for every practice. Amazon Web Services, in Auckland, holds your files. Amazon’s email service, in Sydney, carries your mail.
- Everything else is a choice you make. Nothing below the first table is engaged unless you use a feature or connect an account.
- This website has no sub-processors at all. clerq.nz loads nothing from anyone — no analytics, no fonts, no tag manager.
- None of them train models on your data, and that is a term of our agreement with them, not a hope.
That summary is accurate but not complete. The detail is below.
What this page is
A sub-processor is any company we use that could, in the course of doing its job, hold or handle information belonging to your practice and your clients. Under the Privacy Act 2020 your practice remains the agency responsible for that information; we act on your instruction, and so does everyone on this page.
We publish the list because the alternative is asking you to take our word for it. If you are assessing Clerq for a practice, this is the page to send to whoever asks you where the data goes.
Engaged for every practice
These two are not optional. Using Clerq at all means using them.
| Sub-processor | What it does | Where |
|---|---|---|
| Amazon Web Services Amazon Web Services, Inc. |
Runs the Clerq service and stores your client records, matters, documents and mail — compute, database, file storage, secrets and queues. | Auckland, New Zealand ap-southeast-6 |
| Amazon Simple Email Service Amazon Web Services, Inc. |
Sends and receives your practice email. Message content is stored in Auckland once received; the transport happens in Sydney. | Sydney, Australia ap-southeast-2 |
Why Sydney. AWS does not offer an email service in its Auckland region. No New Zealand provider can do this differently today — anyone claiming fully onshore email is either using a different definition of onshore or has not checked.
Engaged when you use an AI feature
| Sub-processor | What it does | Where |
|---|---|---|
| Anthropic Anthropic, PBC |
Generates the drafts and analysis you ask for, and answers the questions you put to Clerq’s assistant — including when you ask it to read your inbox, a folder or a document to answer. In every case, client names and identifying details are replaced with tokens before anything is sent, and restored only after the response comes back. Zero data retention is enabled, so Anthropic does not keep what we send. | United States |
The replacement step is not a setting anyone can switch off in the course of using Clerq — it runs inside our own network, on our own servers, before any request leaves. If it cannot run, the request does not go. This is as true of the assistant as of a drafted letter: it can read your mail and files to answer you, but what leaves for the model is the tokenised version, never the names.
Engaged when a payment is made through Clerq
| Sub-processor | What it does | Where |
|---|---|---|
| Windcave Windcave Limited |
Not engaged at present. Stripe is the gateway today. Windcave is named here anyway because the integration is retained rather than removed, so the software can still reach Windcave’s systems — and what Clerq can reach is what this page is for. While it is stood down nothing is sent to it and it receives nothing. Engaging it again would be adding a sub-processor, so the 30 days’ notice below applies before that happens. When it was in use it took only the payment: card details were entered on Windcave’s own hosted page, and it never received your clients’ files or any matter data. | New Zealand |
| Stripe Stripe New Zealand Limited |
Our payment processor, engaged in two places: when your practice pays for Clerq, and when an applicant pays one of your practice’s invoices through the client portal. In both cases card details are entered on Stripe’s own hosted payment page — Clerq never sees or stores the card number. Stripe receives the amount, the currency and the invoice number so the payment can be matched back; it never receives your clients’ files or any matter data. | United States and Ireland |
Engaged only if you connect the service
Each of these is off until someone at your practice connects an account, and can be disconnected at any time. Disconnecting stops any further exchange; it does not remove data the provider already holds, because that data is in their system under your relationship with them, not ours.
| Sub-processor | What it does | Where |
|---|---|---|
| Microsoft Microsoft Corporation |
Staff sign-in with a Microsoft work account, and a connected Microsoft 365 mailbox: Clerq reads its messages into your practice file, and — only when your practice turns it on — sends your outgoing mail through it, which means the message you send passes through Microsoft to leave from your own mailbox and lands in its Sent folder. | The region your own Microsoft tenant is in |
| Zoho Zoho Corporation Pvt. Ltd. |
Reads a connected Zoho mailbox so its messages appear in your practice file. | The region your own Zoho account is in — we connect to the data centre your account already uses |
| Google Google LLC |
Staff sign-in with a Google account, calendar availability, and importing documents from Google Drive. | United States |
| Meta Meta Platforms, Inc. |
Sending and receiving client messages over WhatsApp, Messenger and Instagram, including any media attached to them. | United States |
| LinkedIn LinkedIn Corporation |
Publishing posts your practice writes in Clerq’s marketing tools. Client file data is not involved. | United States |
| Xero Xero Limited |
Raising your practice’s fee invoices in Xero and reading their payment status back, if you connect your Xero organisation. Xero receives the invoice amount and the reference your practice types — never the client’s file, passport details or matter contents. | New Zealand (global cloud infrastructure) |
| Secured Signing Secured Signing Limited |
Digitally signing your engagement agreements, if your practice turns e-signature on. Secured Signing receives the agreement document and the signing client’s name and email; the signed copy comes back into your practice’s files. The matter contents beyond the agreement itself are never sent. | New Zealand |
| Twilio Twilio Inc. |
Sending booking confirmation and reminder text messages, if your practice turns SMS reminders on. Twilio receives the phone number the client typed on your booking page and a short message naming the appointment time — never the client’s file, email or matter contents, and nothing flows back. | United States |
| Browser notification relays Google LLC, Mozilla Corporation, Apple Inc., Microsoft Corporation |
Delivering the optional “new mail” desktop notification to staff browsers that turned it on. The relay belongs to whichever browser the staff member uses and carries only an encrypted, generic signal — never message content, sender names or client data. | United States (global relay networks) |
What is not on this list, and why
- The anonymiser. The service that strips client details before anything reaches an AI model is ours, and it runs on our own servers inside the Auckland region. It is not a third party and there is nobody else to name.
- This website. clerq.nz sets no cookies and loads nothing from any other company — no analytics, no tag manager, no hosted fonts, no embedded video. There is no sub-processor to disclose because there is no third party involved in you reading this page.
- Immigration New Zealand. Clerq never submits anything to INZ by itself. When your practice files something, that is your practice dealing with INZ directly.
When this list changes
We will give you at least 30 days’ notice before adding a sub-processor that would handle your practice’s data, and you have 15 days from that notice to object. If you object and we cannot resolve it — by using someone else, changing the arrangement, or letting you turn the feature off — you may end your subscription and we will refund the unused portion.
To be told when this page changes, email [email protected] with the subject Sub-processor notifications. It is a list of email addresses we write to; it is not run by anyone else, because putting a mailing-list provider in the way of this particular page would be an odd choice.
Asking us about any of this
Questions about a specific sub-processor, or a request for what we hold on our arrangements with them, go to [email protected]. If you are an applicant rather than an adviser, your privacy relationship is with the practice acting for you — ask them first, and they can ask us.
See also our privacy statement and terms.