Sub-processors and data recipients
Who helps deliver GLØDI, the role each provider has, and where data may be processed.
A living, versioned provider register
The register separates sub-processors from independent controllers and optional integrations. Only providers needed for activated features receive data.
Current register
Find a provider category
1. How to read the register
Sub-processor
A provider processing clinic-controlled personal data for GLØDI to deliver the platform. GLØDI enters into an Article 28 agreement and remains responsible to the clinic for the provider's performance.
Independent controller
A recipient determining its own purposes or statutory processing, such as regulated payment verification. The recipient's privacy terms apply to that processing.
Optional integration
A service the clinic chooses to activate or connect. Data is transferred only when the clinic selects the integration and has the required agreement or legal basis.
2. Core-platform sub-processors
Google Cloud
Application hosting, database, file storage, backups, and email infrastructure. The core application and database run in the Stockholm region and platform files are stored in Finland. Limited support and security access may occur from other countries under a valid transfer basis.
Cloudflare
DNS, network security, abuse protection, and delivery of public content. Processes IP address, request data, and limited technical identifiers through a global network.
Sentry
Error and performance monitoring. Processes technical events and limited account or request identifiers. GLØDI must filter clinical text and other unnecessary sensitive data.
Twilio
SMS delivery and status reporting. Processes phone number, message content, and delivery data. Processing may take place outside the EEA under a valid transfer basis.
3. AI and speech sub-processors
Google Cloud Speech-to-Text
Optional transcription when the clinic activates voice-assisted clinical records. Audio and transcription may contain health data and are processed only to provide the feature.
OpenAI
Active provider for optional AI features such as clinical-record assistance and text suggestions. Inputs may contain health data. API content is not used for general model training unless the clinic expressly opts into a separate arrangement. Temporary provider retention and processing location follow the business and data-processing agreements in force.
Anthropic
Supported alternative an administrator may select for certain AI features. It is used only after configuration and under equivalent contractual, security, and transfer requirements.
AI and speech features are not required for basic booking. The clinic may leave them disabled.
4. Payment recipients and optional integrations
Stripe and Vipps MobilePay
Payments, customer authentication, fraud controls, refunds, and settlement. They may be independent controllers for regulated payment processing and processors for limited technical services. They do not receive clinical records.
Fiken and Tripletex
Optional accounting integrations connected by the clinic. Sales, invoice, and settlement data is transferred under the clinic's choice and access authorisation.
Bring/Posten and other selected carriers
Name, contact, and delivery details are transferred where shipping is selected. The carrier also processes data under its own transport and legal obligations.
5. Changes, transfers, and objections
Advance notice
GLØDI notifies clinics at least 30 days before a new or replacement sub-processor receives clinic-controlled data. A shorter period is used only where required by a security, legal, or provider incident.
Reasoned objection
The clinic may object within the notice period on documented privacy or security grounds. The parties first seek risk-reducing measures or a reasonable alternative. If none is available, the clinic may terminate the affected feature without future charge.
Transfers outside the EEA
Access or processing outside the EEA takes place only under a valid GDPR Chapter V mechanism, such as an adequacy decision or Standard Contractual Clauses, plus required supplementary measures. A storage region alone is not decisive if remote access may occur from a third country.
The Data Processing Agreement governs use
Read the rules on authorisation, security, transfers, objections, and responsibility for sub-processors.
Read the Data Processing AgreementPrivacy Policy
How we process personal data — your rights, retention periods, cookies, and who we share data with — is covered in our privacy policy.
Read the privacy policyQuestions or objections?
Contact us for the contracting entity, processing location, transfer basis, or to raise a reasoned objection to a new sub-processor.
Email: [email protected]
We reply as soon as possible.