1. Introduction
This Sub-Processor Register explains which service providers are engaged by Apeiron Digital Labs Ltd ("We", "Us", "Our", "the Company") in connection with eLogbookAI.
This register should be read alongside our Privacy Policy and Terms of Service. It identifies the main service providers used to provide, secure, monitor, and administer the Service, together with their processing purposes, data categories, hosting or transfer locations, and applicable contractual or transfer safeguards.
Where a provider supports more than one processing category, it may act in different capacities. For uploaded patient content, the provider may act as a sub-processor engaged by the Company in its capacity as processor for the subscribing surgeon. For subscriber account data, audit metadata, billing, analytics, monitoring, or service-administration data, the provider may act as a processor engaged by the Company for the Company's own processing purposes. Some providers, particularly payment service providers, may also act as independent controllers for limited purposes described in their own applicable terms.
Each provider is governed by a data processing agreement, published data processing terms, or equivalent contractual safeguards intended to meet the requirements of Article 28 UK GDPR where the provider acts as a processor or sub-processor. International transfer safeguards are documented per provider where relevant.
This register is maintained by the Company and reviewed at each DPIA review cycle and when material changes are made to the Service or its provider arrangements.
2. Data categories used in this Register
For consistency with our Privacy Policy, this register uses the following data categories:
- Category A – Subscriber Account Data: personal data relating to registered subscribers, including identity, contact, authentication, subscription, preferences, and account-administration data.
- Category B – Uploaded Patient Content: patient information contained in theatre-list images uploaded by a subscribing surgeon for professional logbook processing. This may include Confidential Patient Information and Special Category health data. It is held only in restricted transient processing storage, is not added to an account or long-term application datastore, and is deleted under the timings in the Privacy Policy.
- Category C – Audit Log Data: persistent operational records of CPI-processing events for which the Company acts as controller and which are used for accountability, security, legal compliance, and incident investigation. They can identify the subscriber and may include a restricted system-generated object path, but are designed not to contain readable patient names, patient identifiers, theatre-list images, or clinical content.
- Category D – Technical, Security and Usage Data: IP address, request URL and headers, user agent, device/browser information, TLS or edge-security signals, error diagnostics, pseudonymous internal user identifiers, and limited account, onboarding, validation, subscription, upload-status, processing-status, or consent-gated browser-analytics events.
3. Google Cloud Platform
Provider
Google Cloud Platform, including cloud hosting, transient object storage, AI-assisted extraction, key management, and scheduled deletion services.
Purpose
Application hosting, transient image processing, AI-assisted extraction, key management, and scheduled deletion controls.
Data Processed
- Category B – Uploaded Patient Content, processed transiently on behalf of the subscribing surgeon for logbook extraction and submission purposes.
- Category A – Subscriber Account Data, where required to operate and secure the Service.
- Category C – Audit Log Data, where required for deletion controls and accountability.
- Category D – Technical, Security and Usage Data required for service operation, protection, and troubleshooting.
Location / Transfer
The core Google Cloud workload resources used by the Service are configured for the United Kingdom – London region. Any provider access, support processing, or international transfer is governed by Google's applicable data processing terms and transfer safeguards.
DPA / Transfer Mechanism
Google Cloud Data Processing Addendum in force. Google Cloud contractual terms restrict use of Customer Data for AI/ML model training or fine-tuning without the customer's prior permission or instruction. Any provider access, support processing, or international transfer is governed by Google's applicable data processing terms and transfer safeguards.
4. Cloudflare
Provider
Cloudflare.
Purpose
Edge security, routing, and reverse proxying for browser traffic before it reaches the eLogbookAI application.
Data Processed
- Browser request and response content needed to proxy each request. This includes Category B uploaded patient content and extracted-result responses while they are in transit.
- Technical request metadata such as IP address, URL, headers, TLS details, and security signals.
- Cloudflare is not part of the separate Cloud Scheduler to Express automated-deletion path.
Location / Transfer
Cloudflare operates a distributed network and processing locations may vary. Browser traffic passes through this network before and after the London-hosted application, so applicable processing may occur outside the United Kingdom.
DPA / Transfer Mechanism
Cloudflare's applicable Data Processing Addendum forms part of its customer agreement and includes contractual safeguards for restricted transfers where required. The current terms are available at https://www.cloudflare.com/cloudflare-customer-dpa/.
5. MongoDB Atlas
Provider
MongoDB Atlas.
Purpose
Persistent database hosting for subscriber account data, CPI audit records, and limited application security metadata.
Data Processed
- Category A – Subscriber Account Data.
- Category C – Audit Log Data.
- Category D – limited application security metadata stored with the account or audit system.
- The application is designed not to write uploaded images, complete extraction results, or clinical content to MongoDB Atlas.
Location / Transfer
Service database content is hosted in the United Kingdom – London region.
DPA / Transfer Mechanism
MongoDB Atlas data processing terms in force. Any provider access, support processing, or international transfer is governed by MongoDB's applicable data processing terms and transfer safeguards.
6. Stripe
Provider
Stripe.
Purpose
Payment processing, subscription management, billing administration, invoices, receipts, and related financial records.
Data Processed
- Billing and subscription data.
- Payment-related identifiers and transaction records.
- Subscriber account reference used to match payment events to the relevant eLogbookAI account.
- Stripe is not intentionally sent uploaded patient content or extracted clinical fields.
- No card numbers are stored by eLogbookAI.
Location / Transfer
United States and other Stripe processing locations, as described in Stripe's applicable terms.
DPA / Transfer Mechanism
Stripe acts as a payment services provider. Depending on the processing activity, Stripe may act as our processor or as an independent controller, as described in Stripe's applicable terms. Stripe data processing terms are incorporated into the Stripe Services Agreement. For UK-to-US transfers, Stripe's certification under the UK Extension to the EU-US Data Privacy Framework is used as the primary transfer mechanism where applicable. The UK International Data Transfer Addendum to the EU Standard Contractual Clauses is incorporated into Stripe's data transfer terms as a fallback mechanism where required.
7. Sentry
Provider
Sentry.
Purpose
Application error tracking, diagnostics, and service reliability monitoring.
Data Processed
- Error events and diagnostic metadata.
- Category D subscriber or session-related technical metadata where required for debugging and service reliability.
- Uploaded patient content is not intentionally sent to Sentry.
- Error monitoring is configured to suppress or exclude sensitive fields from error events.
Location / Transfer
European Union – Frankfurt.
DPA / Transfer Mechanism
Sentry data processing terms in force. UK-to-EU transfers are covered by UK adequacy regulations for the EEA.
8. PostHog
Provider
PostHog.
Purpose
Consent-gated browser analytics and limited pseudonymous server-side operational events used to operate, secure, and improve the Service.
Data Processed
- Category D consent-gated browser page views, navigation, feature-usage, device, and interaction events.
- Category D server-side operational events linked to a pseudonymous internal user identifier and limited account, onboarding, validation, subscription, upload-status, or processing-status properties.
- Uploaded images, patient identifiers, extracted clinical fields, email, name, and GMC number are not intentionally sent.
- Session recording is disabled.
Location / Transfer
European Union – Frankfurt.
DPA / Transfer Mechanism
PostHog data processing terms in force. UK-to-EU transfers are covered by UK adequacy regulations for the EEA.
9. Resend
Provider
Resend.
Purpose
Transactional email, including verification emails, account notifications, receipts, and service-related communications.
Data Processed
- Subscriber email address.
- Subscriber name, where needed for the relevant communication.
- Non-clinical email content.
- Resend is not intentionally sent uploaded patient content or extracted clinical fields.
Location / Transfer
United States.
DPA / Transfer Mechanism
Resend data processing terms in force. For UK-to-US transfers, Resend's certification under the UK Extension to the EU-US Data Privacy Framework is used as the primary transfer mechanism where applicable. The UK International Data Transfer Addendum to the EU Standard Contractual Clauses is incorporated into Resend's data processing terms as a fallback mechanism where required.
10. BetterStack
Provider
BetterStack.
Purpose
Uptime monitoring and availability monitoring.
Data Processed
- Domain-level HTTP pings and availability monitoring data.
- The Company configures BetterStack for domain-level HTTP pings, not application logs, traces, session recordings, or request bodies.
- BetterStack is not intentionally sent uploaded patient content or extracted clinical fields.
Location / Transfer
EU data storage by default, with possible non-EEA processing or corporate/service-provider touchpoints governed by BetterStack's applicable data processing terms.
DPA / Transfer Mechanism
BetterStack data processing terms in force. Customer data stored in the EEA is covered by UK adequacy regulations for the EEA. To the extent any restricted transfer occurs outside the UK or EEA, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses applies where required.
11. Redis Cloud
Provider
Redis Cloud, provided by Redis Ltd.
Purpose
Managed Redis services for queue coordination, CPI-session validation, job progress and status, rate limiting, validation, other operational state, and procedure-taxonomy lookup caching.
Data Processed
- Subscriber, session, and job references needed to coordinate processing.
- Restricted Google Cloud Storage object references, timestamps, job progress, and status.
- Category D request, rate-limit, security, user-status, and validation metadata used to operate and protect the Service.
- Procedure-taxonomy cache entries, which map a procedure label to the corresponding elogbook.org taxonomy entry together with the confidence and reasoning recorded for that mapping. Each entry is keyed by a hash of the procedure label alone, has no subscriber linkage, and is designed not to contain patient names, patient identifiers, dates of birth, operation dates, or hospitals.
- Uploaded image bytes and extracted-result payloads are not stored in Redis.
Location / Transfer
Redis Cloud is a provider-managed service and connections use TLS. Provider access, support processing, processing locations, and any international transfer are governed by Redis Ltd's applicable terms. A more specific deployment location will be stated only while supported by retained account evidence.
DPA / Transfer Mechanism
The Redis Data Processing Addendum forms part of the Redis Cloud Agreement where Redis processes personal data for the customer. It includes processor obligations and transfer provisions and is available at https://redis.io/legal/data-processing-addendum-dpa/.
12. Patient data transfer position
Core application, object-storage, and AI resources that handle uploaded patient content are configured in the Google Cloud London region. Browser uploads and extracted-result responses also pass through Cloudflare's distributed network in transit, where processing locations may vary.
Cloudflare can therefore process uploaded patient content in transit outside the United Kingdom. Stripe, Resend, and BetterStack have international touchpoints but are not intentionally sent uploaded patient content. Sentry and PostHog are configured so uploaded patient content and extracted clinical fields are not intentionally sent to them.
Where provider access, support processing, or other service-provider operations could involve access from outside the United Kingdom, this is governed by the relevant provider's data processing terms and transfer safeguards.
13. Changes to this Register
We may update this Sub-Processor Register from time to time as the Service develops or as our provider arrangements change.
For an intended addition or replacement that will process patient data on our behalf, we will ordinarily provide at least 14 days' advance notice by email to your registered address and update this register. If an urgent security, legal, availability, or provider event makes advance notice impracticable, we will notify you as soon as reasonably practicable and explain the reason where lawful. You may object during the notice period on reasonable data-protection grounds by contacting privacy@elogbook.ai; clause 7 of Schedule 1 to the Terms of Service describes the objection process and consequences.
Previous versions are available on request.
14. Contact
For questions about this Sub-Processor Register or our data protection practices, please contact us at [privacy@elogbook.ai](mailto:privacy@elogbook.ai).