Data processing & sub-processors
Last updated 18 Jul 2026 · version 0.2 (draft)
Draft — pending legal review. This wording is a working placeholder and must be approved by counsel for each corridor before launch.
1. Our role
For referral data, LibaMed acts as processor to the referring clinician’s organisation (controller), under a data-processing agreement incorporating the corridor’s transfer mechanism. For clinician account data, LibaMed is the controller.
2. Sub-processors
Infrastructure providers under evaluation are listed with the safeguard each will operate under. This table becomes binding when hosting contracts are signed; we give notice before any change that touches patient data.
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| EEA cloud region (TBC) | France-corridor data plane | EEA | HDS certification · DPA |
| UK cloud region (TBC) | UK-baseline data plane | United Kingdom | UK GDPR · DPA |
| Transactional email (TBC) | Account + case notifications (no PHI in emails) | EU | DPA · no clinical content |
- EEA cloud region (TBC)
- Purpose
- France-corridor data plane
- Location
- EEA
- Safeguard
- HDS certification · DPA
- UK cloud region (TBC)
- Purpose
- UK-baseline data plane
- Location
- United Kingdom
- Safeguard
- UK GDPR · DPA
- Transactional email (TBC)
- Purpose
- Account + case notifications (no PHI in emails)
- Location
- EU
- Safeguard
- DPA · no clinical content
3. Commitments
Every sub-processor touching patient data is bound to the same encryption, residency, and audit obligations we carry. A clean export-and-delete of a corridor’s data is contractually guaranteed from day one (reversibility), so no provider ever becomes a lock-in on patient records.
Questions about this document? Contact LibaMed Ltd, Cardiff, Wales — we aim to respond within two working days.