Subprocessor List
Version v1.0-temp · Effective 12 July 2026
Last updated 12 July 2026
Version: v1.0-temp · Last updated: 13 July 2026 · Effective: from the date this version is published at cbtflow.com/legal/subprocessors
Digita1 OÜ (trading as CBT Flow) uses the service providers below to operate CBT Flow. Where a provider processes Practice-controlled personal data on our behalf, it is a sub-processor for that processing under the Data Processing Agreement (DPA). The Practice authorises the sub-processors listed in the version of this register incorporated when it accepts the DPA.
Roles are determined purpose by purpose: a provider can be a sub-processor for one service and an independent controller for another, and some recipients listed further below are not sub-processors at all.
Sub-processors of Practice Personal Data
| Provider | Service | Purpose | Data / data subjects | Primary location | Transfer route |
|---|---|---|---|---|---|
| Supabase, Inc. | Hosted database, authentication and file storage | Core application infrastructure storing therapist workspace and Client app records | Practice users and clients: clinical records (special-category health data), account, authentication, file and technical data | Hosted in the EEA — Ireland region (on Amazon Web Services infrastructure) | EEA hosting; UK–EEA adequacy arrangements. Remote support or administrative access from outside the UK/EEA is safeguarded by the Standard Contractual Clauses with the UK Addendum in the provider's data-processing terms |
| Amazon Web Services (onward provider under Supabase) | Cloud infrastructure underlying the Supabase services above | Compute and storage for the database, authentication and file services | As for Supabase above | Ireland region (eu-west-1) | As recorded in Supabase's sub-processor disclosure, which forms part of its data-processing terms |
| Vercel Inc. | Web application hosting and delivery | Serving the CBT Flow web applications and delivering application traffic | Users of the web applications: request and traffic data passing through the delivery infrastructure | US-headquartered provider; delivery through a global edge network | Standard Contractual Clauses with the UK Addendum in the provider's data-processing terms |
| Google Ireland Limited (Firebase Cloud Messaging) | Push-notification delivery | Delivering Client app and workspace push notifications | Device push tokens, app/account identifiers and notification payloads (payload content is designed to limit sensitive detail) | EEA contracting entity; processing may occur in other countries under Google's data-processing terms | Google's data-processing terms, including the Standard Contractual Clauses with the UK Addendum where applicable |
| Resend, Inc. | Transactional email | Sending invitations, account and service notices from the cbtflow.com domain | Recipient names/addresses, message content and delivery metadata (service emails are designed not to contain clinical content) | US-headquartered provider | Standard Contractual Clauses with the UK Addendum in the provider's data-processing terms |
Payment and other independent recipients
| Recipient | Service | Role |
|---|---|---|
| Stripe | Subscription billing for CBT Flow plans; Stripe Connect Express connected accounts; client therapy payment processing, refunds and disputes | Stripe acts as an independent controller for substantial parts of payment processing — identity/know-your-customer verification, payment-network obligations, fraud prevention and its own legal compliance — under its own terms and privacy notice. Where Stripe processes limited data solely on CBT Flow's documented instructions, it does so under Stripe's data-processing terms. The Stripe contracting entity for a Practice's connected account is stated in the Stripe Connected Account Agreement presented at onboarding |
Public-site analytics and advertising recipients
These tools operate only on the public marketing website, only with consent, and never receive clinical or client data. They are not sub-processors of Practice Personal Data and are listed here for transparency.
| Provider/tool | Scope | Status |
|---|---|---|
| Google Tag Manager | Public marketing site tag delivery under consent controls | Active on the public site; fires non-essential tags only after consent |
| Google Analytics 4 | Aggregate public-site usage measurement | Runs only after analytics consent via the cookie bar |
| Google Ads Conversion Tracking | Public marketing conversion measurement | Disabled at the effective date; requires separate advertising consent and updated disclosure before any activation |
| Meta Pixel | Public marketing conversion measurement | Disabled at the effective date; requires separate advertising consent and updated disclosure before any activation |
See the Cookie Notice at cbtflow.com/legal/cookies for the consent model.
Changes to this register
- Notice: we give Practices at least 30 days' notice before a new or replacement sub-processor begins processing Practice Personal Data, by email to the account administrator and/or a prominent in-product notice. A change to this page alone is not notice.
- Objections: privacy@cbtflow.com, within the notice period, on reasonable data-protection grounds. The DPA describes the resolution and exit process.
- Emergency changes strictly necessary for service security or legal compliance are notified as soon as reasonably possible.
- Versions: this page shows its version and effective date; earlier versions are available on request via privacy@cbtflow.com, and the version each Practice authorised is preserved with its DPA acceptance record.