Trust & Compliance
Sub-processor Directory
1. Scope and purpose
To deliver the Dicomly API and connectivity platform, we engage third-party infrastructure and service providers ("Sub-processors") to process personal data on our behalf in accordance with Article 28 of the General Data Protection Regulation (GDPR) and ourData Processing Agreement (DPA).
This directory is the authoritative, current registry of all third-party sub-processors engaged by Dicomly.
Critical privacy safeguard: Zero sub-processors receive, store, or have access to DICOM payload content or patient health data. DICOM imaging streams flow directly through real-time memory to your designated STOW-RS destination URL and are never persisted to disk, queues, caches, or third-party storage services.
2. Current sub-processors
The table below lists each third party engaged to process personal data, their corporate location, the specific purpose of processing, categories of personal data received, data center region, transfer safeguards, and engagement date:
| Sub-processor / Entity | Purpose | Personal Data Categories | Location / Data Center | Transfer Mechanism | Since |
|---|---|---|---|---|---|
| Amazon Web Services EMEA SARL 38 Avenue John F. Kennedy, L-1855 Luxembourg | Cloud infrastructure, compute execution, and network routing for API and control services. | Account credentials, configuration, endpoint identifiers, transmission volume, and network access metadata. Zero DICOM payloads or patient health records. | Frankfurt, Germany (AWS eu-central-1) | EU corporate entity; all data stored and processed strictly within the European Union. | September 2026 |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, USA | Authoritative DNS, Web Application Firewall (WAF), edge routing, and public website hosting. | Network metadata (IP addresses, request headers, timestamps) in transient edge memory for traffic inspection and abuse prevention. DICOM ingress bypasses Cloudflare entirely. | Global edge network; transit only | Standard Contractual Clauses (SCCs) alongside technical controls ensuring DICOM traffic never routes through Cloudflare. | September 2026 |
| Backblaze, Inc. 500 Ben Franklin Way, San Mateo, CA 94401, USA | Off-site disaster recovery storage for automated daily configuration and account system backups. | Encrypted ciphertext archives of account, billing, and endpoint metadata. Backups are encrypted before leaving Dicomly servers; Backblaze never possesses decryption keys. Never contains DICOM data. | Amsterdam, Netherlands (EU Region) | Standard Contractual Clauses (SCCs) and EU data storage, combined with client-side envelope encryption. | September 2026 |
| Stripe, Inc. 354 Oyster Point Blvd, South San Francisco, CA 94080, USA | Payment processing, credit card billing, invoicing, and tax calculation. | Cardholder payment information, customer billing address, and transaction records. Acts as an independent controller for payment processing; Dicomly never sees or stores full payment card numbers. | United States / Global | Standard Contractual Clauses (SCCs) and Data Privacy Framework. | September 2026 |
3. Advance change notification and objection rights
In accordance with Section 6 of our Data Processing Agreement and GDPR Article 28(2):
- ≥ 30 days advance notice: Dicomly will provide at least thirty (30) days advance written notice to all registered account owners before engaging any new or replacement sub-processor. Notice is delivered by electronic mail to the primary account address, and this directory is updated at the same time.
- 14-day objection window: The Customer has 14 days (fourteen calendar days) from receipt of the change notice to object in writing on reasonable data protection grounds.
- Resolution or termination: If an objection is raised, Dicomly will discuss the concern in good faith. If the parties cannot reach a mutually acceptable resolution within fourteen (14) days following the objection, the Customer may terminate the affected services without penalty prior to the new sub-processor commencing processing.
4. Due diligence and contractual safeguards
Before engaging any sub-processor, Dicomly conducts technical and legal security reviews. Every sub-processor is bound by a formal written agreement imposing data protection obligations no less protective than those in our Data Processing Agreement, including mandatory confidentiality, purpose limitation, security controls, and audit rights.
For questions about this directory, or to confirm which address we send change notices to, contact info@dicomly.io.