Skip to content

Sub-processors

Last Updated: 5 September 2026

What are Sub-processors?

Sub-processors are third-party service providers that we engage to help deliver the ScreenIT platform. These providers may process personal data on our behalf in accordance with our instructions and data protection agreements.

Each sub-processor is engaged under a written agreement. Where one is not yet in place, the DPA column says so.

Current Sub-processors

Parties that process personal data for, or operate, the ScreenIT platform.

IDSub-processorLegal EntityPurposeProcessing LocationsTransfer MechanismDPA
SP-01AWSAmazon Web Services EMEA SARL (EMEA) / Amazon Web Services, Inc.Cloud infrastructure - compute, storage, database, CDN, and messaging servicesAustralia (ap-southeast-2), Europe (eu-west-1 Ireland), Europe (eu-west-2 London)Live identifiable data is held in the deployment region (Australia, or Ireland for UK and EU deployments). Encrypted backup copies are held in a second region: within Australia for Australian deployments, and in the United Kingdom for UK and EU deployments, so for an EU deployment the backup copy leaves the EU under the European Commission adequacy decision for the UK.Active
SP-02FirebaseGoogle Ireland Limited (EU/UK) / Google LLCAuthentication and identity management (Firebase Auth with MFA)United States (Firebase Auth is a global service)SCCs / UK IDTA - authentication metadata only, no clinical dataStandard
SP-03StripeStripe, Inc. / Stripe Payments UK LtdPayment processing (PCI-DSS Level 1 certified)Australia, United Kingdom, United StatesSCCs / UK IDTAActive
SP-04SendGridTwilio Inc. (Twilio SendGrid)Transactional email delivery and platform notificationsUnited StatesSCCs / UK IDTA - email addresses and notification content onlyActive
SP-05NeuroFlexSaccade Analytics Inc.Optional VR-based neurocognitive assessment integrationAustraliaOptional integration, activated only where a Healthcare Organisation chooses it. Processing is in Australia, so activation for a UK or EU organisation would move assessment data out of the UK or EEA; not activated for any UK or EU organisation as at 2026-08-24, and a safeguard must be confirmed before it is.Missing
SP-06Google AnalyticsGoogle LLCPlatform and website usage analyticsUnited StatesSCCs / UK IDTA - usage/telemetry, not clinical dataStandard
SP-09SentryFunctional Software, Inc. dba SentryError and exception monitoring for the ScreenIT backend and clinician portalUnited StatesNo transfer mechanism is in place between YBH and Sentry. The Sentry organisation is operated by our development partner, so the contractual terms run between that partner and Sentry; YBH holds no agreement with Sentry directly and is not the billed party. Error reports include the clinician’s IP address and the approximate location Sentry derives from it, and in a smaller number of cases a clinician, clinic-staff or CMS-user email address. They do not include patient names, dates of birth, contact details or screening answers.None
SP-12Microsoft AzureMicrosoft Corporation and its affiliates; the contracting entity follows the Microsoft Customer Agreement for the subscriptionHosting for the ScreenIT business-intelligence dashboards, and supporting web and logging servicesaustraliaeast, uksouth, eastasia, westeurope, Microsoft Static Web Apps global edge (content replicated to at least Amsterdam / Hong Kong / US)Microsoft Products and Services Data Protection Addendum, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers out of the EEA and UKStandard

Error monitoring and reports already stored

We have changed the ScreenIT code so that new error reports carry fewer identifiers than they used to.

That change applies to reports created from the point it was deployed. It does not alter reports already stored: those remain in the Sentry organisation until its owner deletes them, or until they age out under the retention that applies to that organisation’s plan. YBH holds a Member seat on that organisation, so we cannot set its retention, delete its stored data, or verify a deletion carried out by someone else. We will update this page if that position changes.

We have kept the clinician’s IP address in new reports deliberately. It is what lets us tell one clinic’s fault from another’s when something breaks, and removing it would leave us diagnosing a clinical tool blind. That is a decision rather than an oversight, and it is why Sentry is listed here.

Changes to Sub-processors

We will update this page when we add or remove sub-processors. In accordance with our Clinician Terms and Conditions (clause 8.4), we will inform customers of any intended changes concerning the addition or replacement of a sub-processor within a reasonable time prior to implementation. If you object to a change, we will make reasonable efforts to address your concerns.

Questions?

For more information about our data processing practices, contact us at legal@yourbrainhealth.io.