International Data Transfer Disclosure | Huma

International Data Transfer Disclosure

HDS Certification – Requirement 31 Compliance

Table of Contents

  1. Overview of International Transfers
  2. Legal Framework
  3. Transfer Details & Processor Information
  4. Risk Assessment (Requirement 30)
  5. Data Protection Safeguards
  6. Complete Transfer Matrix
  7. Data Subject Rights

1. Overview of International Transfers

Status: Huma does not hold SecNumCloud 3.2 certification. However, we maintain hosting infrastructure primarily within the European Economic Area (EEA) and implement strict controls for any limited transfers outside the EEA.

As a health data processor certified under the French Health Data Host (HDS) framework, Huma is required to publicly disclose all arrangements for transferring personal health data (Données de Santé à Caractère Personnel - DSCPs) outside the European Economic Area.

This page provides:

2. Legal Framework

HDS Requirement 31 & 30

Under the French Health Data Host (HDS) certification standard, Articles R1111-9 and R1111-15 of the French Code de la Santé Publique, hosts must:

Requirement 31: Publicly disclose all transfers of DSCPs outside the EEA, including the countries involved, the nature of access, and the measures implemented to ensure equivalent protection.

Requirement 30: Inform clients about non-European regulations under which unauthorized access could be imposed, and describe measures and residual risks.

GDPR Chapter V & Schrems II

All transfers are conducted in compliance with GDPR Article 45 (adequacy decisions) and Article 46 (appropriate safeguards), particularly Standard Contractual Clauses (SCCs).

Following the CJEU's Schrems II judgment (C-311/18), we have implemented supplementary technical and organizational safeguards to ensure the level of data protection is not undermined.

CNIL Adequacy List

For a list of countries ensuring an adequate level of data protection under GDPR Article 45, see the CNIL website.

3. Transfer Details & Sub-Processor Information

Huma engages the following sub-processors who may access or process personal health data:

Amazon Web Services (AWS) – Cloud Infrastructure

DocuSign – Electronic Signature Service

Google Cloud Platform (GCP) – Cloud Infrastructure

Intercom - Customer Communication & Support

Jira / Atlassian – Project & Issue Tracking

Mixpanel – Product Analytics

Pendo – Product Analytics & In-App Guidance

Twilio (Secure Communications Infrastructure)

4. Risk Assessment – Requirement 30

As required by HDS Requirement 30, we identify and assess the risks of unauthorized access to DSCPs under third-country legislation:

HIGH LEGISLATIVE RISK

MEDIUM LEGISLATIVE RISK

LOW LEGISLATIVE RISK

MEDIUM LEGISLATIVE RISK

HIGH LEGISLATIVE RISK

5. Data Protection Safeguards

Huma implements multiple layers of safeguards to ensure the level of data protection guaranteed by GDPR is not undermined, in line with the EDPB's Recommendations 01/2020 (post-Schrems II):

Technical Safeguards

Contractual Safeguards

Organizational Safeguards

Recourse & Remedies

6. Complete Transfer Matrix (Requirement 31)

The following table provides a comprehensive overview of all data transfer arrangements:

Sub-Processor Data Processing Activity Data Origin (From) Primary Location (To) Non-EEA Access Legal Basis Risk Level Safeguards
AWS Cloud infrastructure, storage, compute France, Portugal, Czech Republic, Sweden, UK Ireland & Frankfurt (EU) No – health data remains in EEA GDPR Article 46 (SCCs) Low TLS 1.2+, AES-256, SCCs, VPC isolation, CloudTrail, SOC 2 Type II
DocuSign Prescription document signature & approval France, Portugal, Czech Republic, Sweden, UK Ireland (EU) No – data remains in EU GDPR Article 46 (SCCs) Low TLS 1.2+, AES-256, SCCs, no onward transfer
GCP Cloud infrastructure, storage, managed databases France, Portugal, Czech Republic, Sweden, UK Belgium & Frankfurt (EU) No – health data remains in EEA GDPR Article 46 (SCCs) Low TLS 1.2+, AES-256, SCCs, VPC Service Controls, IAM, SOC 2 Type II
Intercom In-app messaging, support communications France, Portugal, Czech Republic, Sweden, UK Ireland (EU) / Limited US Yes – US limited support access GDPR Article 46 (SCCs + supplementary measures) Medium SCCs, DPA, UK IDTA, access controls, audit logs
Jira (Atlassian) Issue tracking, incident management France, Portugal, Czech Republic, Sweden, UK EU (Atlassian Cloud) / Limited non-EEA Yes – limited non-EEA access possible GDPR Article 46 (SCCs) Low–Medium SCCs, DPA, EU data residency, SSO/MFA/RBAC, data minimisation policy
Mixpanel Product analytics, usage tracking France, Portugal, Czech Republic, Sweden, UK United States Yes – primary processing in US GDPR Article 46 (SCCs + supplementary measures) Medium SCCs, DPA, pseudonymisation prior to transfer, no secondary use
Pendo In-app guidance, product analytics France, Portugal, Czech Republic, Sweden, UK United States Yes – primary processing in US GDPR Article 46 (SCCs + supplementary measures) Medium SCCs, DPA, pseudonymisation prior to transfer, contractual restrictions
Twilio Message delivery, communication routing France, Portugal, Czech Republic, Sweden, UK Ireland & Germany (EU) / Limited US Yes – US support & routing access GDPR Article 46 (SCCs + BCRs + supplementary measures) Medium SCCs, BCRs, UK IDTA, DPA, encryption, strict access controls

7. Data Subject Rights & Remedies

Under GDPR and HDS certification, data subjects (patients) retain full rights regarding their personal health data:

GDPR Data Subject Rights

How to Exercise Your Rights
To exercise any of the above rights, submit a written request to:

Huma Data Protection Officer (DPO)
Email: dpo@huma.ai
Address: Huma Ltd , 13th Floor, Millbank Tower, 21-24 Millbank, London, SW1P 4QP, United Kingdom.

Response time: 30 calendar days (extendable to 60 days for complex requests)

Right to Lodge a Complaint
If you believe your rights have been violated, you have the right to lodge a complaint with your national data protection authority:

For France:

Right to Judicial Remedy
You may seek judicial remedies in the courts of your country of residence for damages arising from unlawful processing or unauthorized access. Huma provides contractual indemnification for damages resulting from sub-processor breaches.

Right to Be Informed About Data Transfers
This page serves as your notice of international data transfers. Huma commits to:

Assessment of Adequacy: While Huma does not hold SecNumCloud 3.2 certification, we maintain equivalent data protection through:

Regulatory Authority: For inquiries regarding this disclosure or Huma's HDS compliance, contact the CNIL or your local data protection authority.

Last Updated: March 20, 2026
Version: 1.0 – HDS Compliance Edition
This page is reviewed and updated quarterly, or upon material change to data transfer arrangements.