דלג לתוכן

ספקים וזרימת נתונים

כל ספק שמעבד נתונים עבור TrusteeClear: מטרתו, הנתונים שהוא מטפל בהם, האזור, הסטטוס והבקרות סביבו.

הטקסט המלא של מדריך זה באנגלית; התקציר שלמעלה בשפתכם. תקצירי החוקים והנוסח האנגלי נשארים המקור המחייב.

כל הספקים

The authorized subprocessors are the providers that are always on, and those a firm or account holder connects. Dormant providers are wired into the code but carry no configuration and receive no data. This list is the one the data processing addendum refers to.

“Built” means TrusteeClear's software can work with the provider. “Set up” means this deployment holds the credentials the provider needs. Neither means that a firm has connected an account, or that a connection is working: that is recorded for each firm, and shown to that firm and to TrusteeClear's support.

Providers, status and configuration on this deployment
ProviderPurposeStatusOn this deployment
SupabaseDatabase, sign-in and private file storageAlways onIn use
VercelHosting, content delivery, server functions and privacy-preserving web analyticsAlways onIn use; nothing to set up
AnthropicModel provider for firm-staff generative features and for structured extractionAlways onIn use
SquarePayments: checkout, subscriptions and payment eventsAlways onIn use
ResendOutbound transactional email; mail forwarded to a matter's address, once email filing is switched onAlways onIn use
ImprovMXForwarding of mail sent to TrusteeClear's published addressesAlways onIn use; nothing to set up
PlaidBank-account connections for ledger feedsUsed only for the firms and account holders who choose itBuilt, not set up: no one can connect it on this deployment
ClioPractice-management sync for firms that connect itUsed only for the firms and account holders who choose itBuilt, not set up: no one can connect it on this deployment
Google CalendarCalendar sync for people who connect itUsed only for the firms and account holders who choose itBuilt, not set up: no one can connect it on this deployment
Microsoft calendar (Graph)Calendar sync for people who connect itUsed only for the firms and account holders who choose itBuilt, not set up: no one can connect it on this deployment
DocuSignElectronic-signature provider for firms that connect itUsed only for the firms and account holders who choose itBuilt, not set up: no one can connect it on this deployment
Microsoft Office add-in platformHosts the Word and Outlook add-ins inside OfficeUsed only for the firms and account holders who choose itAvailable: nothing to connect or set up
EstateDraftFL (sister platform)Membership codes issued with an EstateDraftFL purchaseDormantBuilt, not in use
StripeFormer payment rail, kept dormantDormantBuilt, not in use
OpenAIRetained code path for a second model providerDormantBuilt, not in use
TwilioText-message remindersDormantBuilt, not in use
Browser push services (Google, Mozilla, Apple, Microsoft)Carry a notification to a browser a person turned push notifications on forUsed only for the firms and account holders who choose itBuilt, not set up: no one can connect it on this deployment
PostmarkAlternative outbound email senderDormantBuilt, not in use

Supabase

Purpose
Database, sign-in and private file storage
Data
  • Account identities (email address)
  • Matter records, ledgers and audit records
  • Uploaded documents
Region
United States
Status
Always on
On this deployment
In use
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Row-level security on every table
  • Private storage with signed, matter-scoped access
  • Privileged credentials used only on the server

Vercel

Purpose
Hosting, content delivery, server functions and privacy-preserving web analytics
Data
  • Request metadata such as IP address and browser
  • Operational logs that carry markers and codes, not document text
  • Anonymous page-view and speed measurements
Region
United States
Status
Always on
On this deployment
In use; nothing to set up
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Security headers and a content-security policy on every response
  • Production variables held in the platform, never in source

Anthropic

Purpose
Model provider for firm-staff generative features and for structured extraction
Data
  • Document text and matter facts sent for the requested operation
Region
United States
Status
Always on
On this deployment
In use
Contract basis
The provider's standard terms and data-processing terms
Controls
  • The provider's terms prohibit training on this data; retention follows its API terms
  • Generative use only behind a firm-staff session
  • A monthly spend ceiling that fails closed

Square

Purpose
Payments: checkout, subscriptions and payment events
Data
  • Payer name and email address
  • Order amounts
  • Card data is entered with Square and never reaches TrusteeClear
Region
United States
Status
Always on
On this deployment
In use
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Payment events accepted only with a valid signature
  • Hourly reconciliation of provider events

Resend

Purpose
Outbound transactional email; mail forwarded to a matter's address, once email filing is switched on
Data
  • Recipient email address
  • Notification content
  • Mail forwarded to a matter's or a firm's address, with its attachments (once email filing is switched on)
Region
United States
Status
Always on
On this deployment
In use
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Sent from an authenticated domain (SPF and DKIM)
  • Forwarded mail is read by its identifier from a signed webhook; its attachments enter the upload quarantine and scanner

ImprovMX

Purpose
Forwarding of mail sent to TrusteeClear's published addresses
Data
  • Messages sent to the published addresses, such as working-session requests and accessibility feedback
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Always on
On this deployment
In use; nothing to set up
Contract basis
The provider's standard terms and data-processing terms
Controls
  • The domain's mail policy quarantines unauthenticated mail that claims to come from it

Plaid

Purpose
Bank-account connections for ledger feeds
Data
  • Account and transaction data the account holder chooses to connect
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Used only for the firms and account holders who choose it
On this deployment
Built, not set up: no one can connect it on this deployment
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Connected only by the account holder, and disconnectable at any time

Clio

Purpose
Practice-management sync for firms that connect it
Data
  • Matter summaries the firm chooses to sync
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Used only for the firms and account holders who choose it
On this deployment
Built, not set up: no one can connect it on this deployment
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Connected by the firm, and disconnectable at any time

Google Calendar

Purpose
Calendar sync for people who connect it
Data
  • Deadline titles and dates
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Used only for the firms and account holders who choose it
On this deployment
Built, not set up: no one can connect it on this deployment
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Connected by the account holder, and disconnectable at any time

Microsoft calendar (Graph)

Purpose
Calendar sync for people who connect it
Data
  • Deadline titles and dates
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Used only for the firms and account holders who choose it
On this deployment
Built, not set up: no one can connect it on this deployment
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Connected by the account holder, and disconnectable at any time

DocuSign

Purpose
Electronic-signature provider for firms that connect it
Data
  • Documents sent for signature
  • Signer names and email addresses
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Used only for the firms and account holders who choose it
On this deployment
Built, not set up: no one can connect it on this deployment
Contract basis
The provider's standard terms and data-processing terms
Controls
  • Provider callbacks accepted only with a valid signature
  • Only a clean document can be sent

Microsoft Office add-in platform

Purpose
Hosts the Word and Outlook add-ins inside Office
Data
  • None sent by TrusteeClear; the add-in runs inside the user's own Office host
Region
The user's Office host
Status
Used only for the firms and account holders who choose it
On this deployment
Available: nothing to connect or set up
Contract basis
The Office add-in platform terms that apply to the firm's own Office subscription
Controls
  • Only the add-in pages may be framed, and only by Office hosts

EstateDraftFL (sister platform)

Purpose
Membership codes issued with an EstateDraftFL purchase
Data
  • Membership codes and their redemption status
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Dormant
On this deployment
Built, not in use
Contract basis
Common ownership; the partner door refuses every call until it is configured
Controls
  • Partner calls accepted only with the partner secret

Stripe

Purpose
Former payment rail, kept dormant
Data
  • None while dormant
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Dormant
On this deployment
Built, not in use
Contract basis
None in force while dormant
Controls
  • Events accepted only with a valid signature

OpenAI

Purpose
Retained code path for a second model provider
Data
  • None while dormant
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Dormant
On this deployment
Built, not in use
Contract basis
None in force while dormant
Controls
  • Unused unless configured; the same gateway limits would apply

Twilio

Purpose
Text-message reminders
Data
  • None while dormant
Region
United States
Status
Dormant
On this deployment
Built, not in use
Contract basis
None in force while dormant
Controls
  • Unused unless configured

Browser push services (Google, Mozilla, Apple, Microsoft)

Purpose
Carry a notification to a browser a person turned push notifications on for
Data
  • A fixed sentence that something is waiting or new, encrypted for the one browser so the service cannot read it
  • The browser's push address and when a notification was sent
Region
Not stated in TrusteeClear's records; see the provider's published terms
Status
Used only for the firms and account holders who choose it
On this deployment
Built, not set up: no one can connect it on this deployment
Contract basis
None: the service is the one the person's own browser uses, and receives only what it cannot read
Controls
  • Nothing is sent until push is set up and a person turns it on for a browser; they turn it off there or from any of their browsers
  • Encrypted for the one browser (RFC 8291) and signed as TrusteeClear (RFC 8292)
  • Never a name, a trust, a document, a date or an amount; the page a notification opens is on TrusteeClear
  • Sent only to a known push service's address, checked before each send

Postmark

Purpose
Alternative outbound email sender
Data
  • None while dormant
Region
United States
Status
Dormant
On this deployment
Built, not in use
Contract basis
None in force while dormant
Controls
  • Unused unless configured

חיבורי הדפדפן

Every outside origin the site's content-security policy can allow, and the provider it belongs to. An origin is allowed only where its provider is set up; the browser refuses anything else.

Origins the content-security policy allows
OriginProviderAllowed for
This deployment's database originSupabaseData requests from the browser
https://va.vercel-scripts.comVercelScripts, data requests or frames the policy allows
https://vitals.vercel-insights.comVercelScripts, data requests or frames the policy allows
https://cdn.plaid.comPlaidNot allowed on this deployment: allowed only once it is set up
https://*.plaid.comPlaidNot allowed on this deployment: allowed only once it is set up
https://appsforoffice.microsoft.comMicrosoft Office add-in platformScripts, data requests or frames the policy allows
https://*.officeapps.live.comMicrosoft Office add-in platformMay frame the add-in pages only
https://*.office.comMicrosoft Office add-in platformMay frame the add-in pages only
https://outlook.office.comMicrosoft Office add-in platformMay frame the add-in pages only
https://outlook.office365.comMicrosoft Office add-in platformMay frame the add-in pages only

אבטחה ובידוד