Skip to main content
IM

Ibex Medical Analytics

GDPR evidence

ibex-ai.comAnalyticsLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Ibex Medical Analytics and GDPR

CertReports found no public GDPR evidence for Ibex Medical Analytics as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
7 Nov 2024
Expires or valid through
27 Oct 2026
Scope
Ibex Medical Analytics Inc. provides a diagnostic platform primarily for healthcare providers (HCPs) to analyze pathology slides and receive diagnostic insights. Typically, the data provided to Ibex is de-identified, with only the slide image shared, absent of direct patient identifiers. In certain cases, additional metadata or related data may accompany the slide. After analysis, Ibex generates a diagnostic report and subsequently deletes the raw data. Data Subjects and Types of Data Processed • Product Users: Customers and their employees who interact with the platform. For these users, Ibex processes basic information necessary for access and usage, including name, email, login credentials (e.g., password), IP address, and related access details. • Patients (customers of Ibex’ Customers): Patients of the HCPs, who’se pathological samples are the ultimate target of Ibex's diagnostic support. Data processed includes Whole Slide Images (WSI) of pathology samples. These images are generally de-identified and devoid of direct identifiers apart from the pathology slide itself, used solely for diagnostic analysis (as explained above, under the GDPR pseudonymised data). The row slides are being deleted shortly after the completion of the analysis. Data Transfers and Storage Locations Ibex operates globally, with headquarters in Israel (Ibex Ltd.) and the U.S. (Ibex Inc.), serving customers including HCPs in the EU, UK, and Switzerland. Typically, each customer’s data is stored within a designated cloud environment via AWS, with EU, UK, and Swiss customers commonly selecting AWS data centers within the EEA. Although some non-EU customers may involve EU residents as patients, this is not typical. However, Ibex Inc. operates from the U.S., where U.S.-based employees provide support, maintenance, and development services. In performing these services, Ibex Inc. employees may access and process data of EU residents, necessitating transfer of personal data to the U.S. Third-Party Data Sharing and Compliance As part of operations, data transferred to the U.S. is shared only as necessary with Ibex Inc. U.S. employees and trusted processors (e.g., AWS, also DPF-certified). The company seeks DPF certification to ensure compliance with EU-U.S., UK, and Swiss data protection principles, recognizing the regulatory requirements of these jurisdictions.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Ibex Medical Analytics Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 25b10d531b
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Ibex Medical Analytics GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Analytics category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Analytics vendor has GDPR evidence in the index yet.