Document ID: O-05
Register version: 2026-08-21.1
Version and date: 2026-08-21.1 - 21 August 2026
Company: FlowDule ApS, CVR 46273397
Contact and objections: privacy@flowdule.com
Important: An account, an invoice, a code integration or an EU region is not in itself documentation of a lawful supplier chain. Every active processing operation requires a verified legal entity, role, agreement/DPA, data, regions, remote support, onward chain, retention, security and, where applicable, a Chapter V basis.
1. How to read the list
| Category | Meaning |
|---|---|
| Sub-processor | Processes the customer’s personal data on FlowDule’s behalf. Requires an Article 28 chain, the customer’s approval under the DPA and FlowDule’s control. |
| Recipient/independent controller | Determines all or part of the purpose itself. FlowDule cannot describe the party as a sub-processor; separate information and a separate basis may be required. |
| Technical supplier without personal data | May only be classified as such where the actual data flow and network testing show that the supplier does not receive personal data. |
| Restricted/not released | An integration or account may exist, but the feature must not be used with the personal data stated until the open controls have been approved. |
2. Approval rule
A supplier is approved for a specific processing operation when FlowDule’s internal supplier and control register contains dated evidence of role, purpose, data, data subjects, contract/DPA, all relevant processing countries and remote access, sub-suppliers, retention/erasure, security, transfer basis, technical configuration and exit.
Where a field is open, the default action is to keep the feature disabled, to restrict it to non-sensitive test data or to introduce a technical block. The public status must reflect actual operation.
3. Central infrastructure - Amazon Web Services
The contracting party is stated as Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, with the relevant AWS group entities under the applicable contractual framework. FlowDule holds an active AWS account and a contractual basis; the invoice documents the account relationship, but not on its own the DPA, the support chain, sub-suppliers or transfers.
| Service | Purpose and data | Most recently documented region | Status |
|---|---|---|---|
| RDS, ECS, ElastiCache, Secrets Manager and KMS | Database, API, cache, secrets and encryption; customer data may include journal/health data. KMS receives key material under the architecture. | Primarily eu-north-1 | Core production. |
| S3 | Files, attachments, images, audio and technical assets. | eu-central-1 and eu-north-1 under the most recent baseline | Active. |
| Cognito | Sign-in and user management: name, e-mail, telephone, credentials/tokens. | eu-central-1 under the most recent baseline | Active. |
| SES/SNS | E-mail and notification: contact details, recipient, metadata and message content. | eu-central-1/eu-north-1 under the most recent baseline | Active. Data-minimised content only. |
| CloudFront/CloudWatch | Global delivery as well as operational/security logs; IP, request and event data. | Global edge/EU origins and the selected log region | Active. Global edge delivery; logs are written in the chosen EU region. |
| Bedrock/Anthropic Claude via AWS | Generative documentation assistance; prompt, journal text and output. | EU inference profile | Released gradually. Requires separate activation per customer, and no AI output is stored without active human approval. |
| Transcribe, Textract and Translate | Speech, OCR and translation; audio, document images and text may be health data. | EU regions per the latest baseline | Requires separate activation and the customer’s instructions. |
4. Other sub-processors and processing suppliers
| Supplier/legal entity | Role, purpose and data | Countries/transfer | Current status |
|---|---|---|---|
| GatewayAPI / ONLINECITY.IO ApS, CVR 27364276, Denmark | Sub-processor for SMS; telephone number, sender and message text. | FlowDule has chosen the supplier’s EU setup with a planned move no later than 1 December 2026. | SMS is active and uses only neutral text without client, service or event names. |
| LiveKit Incorporated, USA | Video infrastructure; session ID, participant data, audio/video and possibly chat in transit. No recording, egress, agents or inference is used. | EU residency and support access are documented as part of the contractual basis. | The integration exists; clinical use is restricted until the contractual and regional documentation is in place. |
| 650 Industries, Inc. / Expo, USA | Push delivery; device token, platform, device name and notification. Onward delivery via Apple/Google. | USA/global delivery chain. | Push delivery has not yet been released. |
| Stripe Payments Europe, Limited / Stripe Technology Europe, Limited, Ireland | FlowDule subscriptions are processed separately on the platform account. The customer’s client payments are implemented in code as direct charges on the customer’s Stripe Express connected account; the customer is the merchant. Data: contact details, amount, status and transaction reference; no journal text. | Ireland; any support/onward chain per Stripe’s contractual basis. | Active. Separate signed platform/Connect webhooks and refunds with proportional reversal of the application fee have been implemented. |
| Cloudflare, Inc., USA - Turnstile | Bot protection; IP and browser signals. | Global network; transfer basis per the supplier’s contractual terms. | Loaded only on the forms that require bot protection (booking and the contact form). |
| Postcode.nl B.V., the Netherlands | Address suggestions in administration; clinic, location and event address fragments, not journal data. | The Netherlands. | Lookups go through FlowDule’s own proxy behind sign-in. |
5. Recipients that are not FlowDule’s sub-processors
| Service | Role and data | Status/action |
|---|---|---|
| Stripe in the customer’s client payment | The customer is normally the merchant/contracting party for its own Stripe account; Stripe may be the customer’s processor or may have its own statutory purposes. FlowDule is a technical intermediary. | The role and the contractual flow are shown in onboarding. The customer must have its own agreement and its own information. |
| CARTO/CartoDB | Map tiles may give the recipient the visitor’s IP and browser data; the party may have independent purposes. | Maps load only after the visitor’s active click (click-to-load), and attribution is shown. |
| Nominatim/OpenStreetMap Foundation | Geocoding/map calls may send the clinic address, IP and technical data to an external recipient. | Geocoding goes through FlowDule’s own proxy; the browser does not call the service directly. |
| Apple and Google in the push chain | The operating system’s push services receive the device token and the notification. Their precise role depends on the platform terms. | Push has not yet been released. |
| The European Central Bank | The public exchange rate feed is retrieved server-side without user data under the design described. | Processes no personal data about visitors. |
6. Third-country transfers
EU/EEA storage does not rule out a transfer through remote support, global edge, group access or sub-suppliers. A contractually agreed possibility of transfer is dealt with according to the specific scenario and cannot be disregarded merely because the likelihood is low.
For each transfer, FlowDule documents the exporter/importer, the data and data subjects, the purpose, the countries, the storage and remote access. The basis may be an adequacy decision, the EU-US Data Privacy Framework for the specifically certified entity, or correct EU Standard Contractual Clauses with a Transfer Impact Assessment and the necessary supplementary measures.
The customer’s instruction in the Data Processing Agreement’s Annex A must cover the foreseeable transfers. A general statement about ‘possible global processing’ is not sufficient as the sole documentation.
7. The AI supplier chain
Anthropic Claude is used only through Amazon Bedrock under the architecture described; FlowDule does not assume a direct processor relationship with Anthropic. The actual model, region profile, destinations and retention are documented per released feature.
AI output is a draft subject to active human approval. Diagnosis, triage, treatment decisions, access to services, model training on customer data and undisclosed reuse are not approved. An AI use case may only be activated once the customer has accepted it in Customer Annex A.
8. Changes, notice and objection
The customer gives general approval under the Data Processing Agreement to the sub-processors stated in the accepted version of this list. FlowDule gives at least 30 days’ notice before a planned addition or replacement of a direct sub-processor takes effect.
Before the deadline, the customer may raise a specific, objectively justified data protection objection via privacy@flowdule.com. If the parties cannot find a reasonable solution, the customer may terminate the affected service under the Data Processing Agreement. Changes further down the chain form part of FlowDule’s ongoing control and are communicated where the change materially affects the processing, the risk, the regions or the customer’s instruction.