Subprocessor List
Last updatedSeptember 1, 2026
This is the public list of service providers (subprocessors) used by ORGO Inc. in providing the MYoACT motion-analysis service. This page is the authoritative current version.
This list serves as: (1) the list incorporated by reference through Annex III of the customer DPA (the general contractual authorisation covers the entries as of signature of, or electronic acceptance of, the Master Agreement); (2) information provided to data subjects under APPI Art.28(3); and (3) the per-vendor disclosure corresponding to the function-category descriptions in the published privacy notice and cross-border transfer statement. It does not include internal contract terms, pricing or negotiation conditions, internal identifiers, or infrastructure configuration details. Locations are stated at country/region level.
The main terms and abbreviations used in this list are as follows.
- Health-related data: data relating to the physical and mental condition of the persons analyzed (raw video, skeletal/pose data, analysis results, physical attributes and related metadata).
- Subprocessor: a provider to which we entrust processing necessary for the provision of the Service.
- APPI: the Act on the Protection of Personal Information of Japan.
- GDPR: the EU General Data Protection Regulation.
- HIPAA: the U.S. Health Insurance Portability and Accountability Act.
- ePHI: Protected Health Information under HIPAA in electronic form.
- DPA: a data processing agreement governing the handling of personal data.
- BAA: a Business Associate Agreement under HIPAA.
- SCC: the standard contractual clauses adopted by the European Commission.
- LLM: a Large Language Model.
- PCI-DSS AOC: an Attestation of Compliance with the Payment Card Industry Data Security Standard.
Service providers used as subprocessors
| Provider | Function | Primary location | Data categories | APPI Art.28 basis | Main safeguards |
|---|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure (hosting, authentication, database, storage, CDN/delivery) | Primary processing in Japan; delivery / edge security via a global network (incl. US, EU, Asia-Pacific) | Health-related data generally, credentials, logs | Continuous equivalent measures | DPA, SCC (EU transfers), BAA (where HIPAA applies) |
| RunPod, Inc. | Video analysis processing (AI inference) | Multiple countries/regions (US, Canada, EU, Asia-Pacific, etc.) | Videos under analysis, skeletal data, analysis results | Continuous equivalent measures | DPA, SCC, BAA (where HIPAA applies) |
| Amazon Bedrock (Anthropic models) | External LLM inference (AI assistant) | Japan | AI assistant inputs and outputs | Continuous equivalent measures | Cloud provider's DPA / BAA / subprocessor chain |
| Google LLC (Google Analytics 4, Google Tag Manager) | Web analytics, tag delivery | US | Service usage events (no health-related data) | Continuous equivalent measures | Google DPA, SCC |
| Google LLC (BigQuery) | Data warehouse | Japan | Analytics exports and derived data (no health-related data) | Continuous equivalent measures | Google DPA |
| Google LLC (Google Drive / Google Workspace) | Document sharing / file storage | US (incl. global processing) | Health-related data (videos), internal documents | Continuous equivalent measures | Google Workspace DPA, HIPAA BAA (where applicable) |
| Functional Software, Inc. (Sentry) | Error monitoring (application and API error and performance monitoring, session replay) | Provider in the US; data stored in the provider's EU region (Germany) | Technical information when an error occurs (error details, browser and device information, URL of the page viewed, IP address), MYoACT account ID, and recordings of on-screen activity where session replay is enabled | Continuous equivalent measures | Sentry DPA, SCC, data storage in the EU region |
| Zendesk, Inc. | Customer support | US | Support ticket content (operated so as not to include patient identifiers / health-related data) | Continuous equivalent measures | Zendesk DPA |
| Notion Labs, Inc. | Knowledge management | US | Internal knowledge / operational memos | Continuous equivalent measures | Notion DPA |
| Blastmail (Rakus Co., Ltd.) | Email delivery | Japan (domestic provider) | Recipient email addresses (no patient identifiers / health-related data) | Domestic delivery (treated as cross-border transfer if processing/backup outside Japan is identified) | Services agreement, supervision of the entrusted party (APPI Art.25) |
| Vananaz Technologies Inc. | Development, maintenance and operations subcontracting | Philippines | May access health-related data or ePHI in the course of support | Continuous equivalent measures | Services agreement (provisions corresponding to APPI Art.25 / GDPR Art.28 / a HIPAA Subcontractor BAA where HIPAA applies), SCC (for transfers of EEA-originating data). Information on the Philippine regime (Data Privacy Act 2012 (RA 10173) / National Privacy Commission) is provided on request |
| Meta Platforms, Inc. | Ad measurement | US | Cookies, IP addresses, browser identifiers, hashed contact identifiers (no health-related data, videos, images or numeric series) | Data subject consent | Meta Data Processing Terms, SCC |
| Google LLC (Google Ads) | Ad measurement | US | Cookies, ad click identifiers, IP addresses, browser identifiers (no health-related data, videos, images or numeric series) | Data subject consent | Google Ads data protection terms, SCC |
| LinkedIn Corporation (LinkedIn Insight Tag) | Ad measurement | US | Cookies, IP addresses, browser identifiers (no health-related data, videos, images or numeric series) | Data subject consent | LinkedIn advertising data protection terms, SCC |
| X Corp. (X Pixel) | Ad measurement | US | Cookies, IP addresses, browser identifiers (no health-related data, videos, images or numeric series) | Data subject consent | X advertising data protection terms, SCC |
| Stripe (Stripe Payments Europe, Ltd. or Stripe, Inc.) | Payment processing | Ireland or US | Payment amounts, billing details, payment identifiers, customer email (card numbers held by the payment provider) | Continuous equivalent measures | Stripe DPA, SCC, PCI-DSS AOC |
| Usercentrics A/S (Cookiebot) | Consent management (cookie consent banner on the Service's web application) | Denmark (EU). Consent records are stored and processed within the EU (Ireland, Netherlands). Banner delivery and edge processing involve a US CDN provider as the vendor's own subprocessor | Consent state, consent record identifier, consent timestamp, IP address, browser information (user agent, referrer), URL visited, language setting, coarse location (no health-related data, video, images or numeric series) | Outside the scope of APPI Art.28 (Usercentrics A/S, the recipient, is located in the EU, a country designated by the rules under that Article) | Usercentrics DPA (processing within the EU/EEA, prior authorisation of subprocessors with notice of changes, SCC where a transfer outside the EEA occurs), supervision of the entrusted party under APPI Art.25 |
Note: Meta, Google (Google Ads), LinkedIn, X, Stripe and Usercentrics are vendors for ORGO's own ad measurement, payment processing and consent management as controller, not subprocessors of customer health-related data; they are included for transparency.
Change notices
- When adding or replacing subprocessors, ORGO updates this list. Advance notice to contracted customers and objection handling follow the customer's DPA.
- The revision history of this list is recorded under "Revision history" at the end of this page.
Supplement
- For routes where the destination country cannot be identified, ORGO presents, in place of the country name: (i) that fact, (ii) the reason, and (iii) the destination country/region categories (US, EU, Asia-Pacific and other commercial regions) and safeguards applied, in accordance with PPC guidelines.
- Provision to a third party located in the EU or the UK falls outside the scope of APPI Art.28, because those countries are designated by the rules under that Article as excluded from "foreign country." ORGO nonetheless supervises such entrusted parties under APPI Art.25.
- Additional information on each provider's safeguards is provided to data subjects on request within a reasonable scope under APPI Art.28(3), via ORGO's contact point (support@myoact.com).
Last updated: September 1, 2026
Revision history
| Date | Changes |
|---|---|
| September 1, 2026 | Initial publication |