Form SUB-01
Subprocessors
The third parties that process data on our behalf. This list is maintained as a matter of contract, and customers are notified before it changes.
Effective 15 August 2026
Notice of change
Customers under a data processing agreement receive advance notice of any addition to this list, with a window to object. The notice period and objection mechanism are set out in the DPA.
Current subprocessors
This list is a placeholder pending finalisation of our production infrastructure, and must be replaced with the real roster before launch. It is shown here so the page structure is complete, not as a statement of fact.
- Cloud infrastructure and hosting — compute, storage and networking, UK regions. Processes: platform data including patient identifiable data.
- Error and performance monitoring — application telemetry. Processes: operational metadata, configured to exclude patient identifiable data.
- Transactional email — delivery of account and notification email. Processes: business contact data only.
- Customer relationship management — sales and support records. Processes: business contact data only.
Patient data boundary
Only sub-processors explicitly designated as patient-data-handling receive patient identifiable data, and each is bound by a downstream agreement no less protective than our own Article 28 DPA. The remainder are contractually and technically scoped to business contact data and operational telemetry.
Pre-launch notice. These documents are drafted as realistic scaffolding for a clinical-data company and have not been reviewed by counsel. Entity details, postal address, data protection officer and the subprocessor roster are placeholders pending incorporation. Do not rely on them as executed legal terms.