Data processing & sub-processors

Last updated 18 Jul 2026 · version 0.2 (draft)

Draft — pending legal review. This wording is a working placeholder and must be approved by counsel for each corridor before launch.

1. Our role

For referral data, LibaMed acts as processor to the referring clinician’s organisation (controller), under a data-processing agreement incorporating the corridor’s transfer mechanism. For clinician account data, LibaMed is the controller.

2. Sub-processors

Infrastructure providers under evaluation are listed with the safeguard each will operate under. This table becomes binding when hosting contracts are signed; we give notice before any change that touches patient data.

  • EEA cloud region (TBC)
    Purpose
    France-corridor data plane
    Location
    EEA
    Safeguard
    HDS certification · DPA
  • UK cloud region (TBC)
    Purpose
    UK-baseline data plane
    Location
    United Kingdom
    Safeguard
    UK GDPR · DPA
  • Transactional email (TBC)
    Purpose
    Account + case notifications (no PHI in emails)
    Location
    EU
    Safeguard
    DPA · no clinical content

3. Commitments

Every sub-processor touching patient data is bound to the same encryption, residency, and audit obligations we carry. A clean export-and-delete of a corridor’s data is contractually guaranteed from day one (reversibility), so no provider ever becomes a lock-in on patient records.

Questions about this document? Contact LibaMed Ltd, Cardiff, Wales — we aim to respond within two working days.