Legal - International transfers
International Transfers
Effective from Version 1.2
1. Why we transfer personal data internationally
Some of our processors (the providers who store, process, or transmit personal data on our behalf) are based outside the UK and the European Economic Area. Where we transfer personal data outside those areas, we rely on one or more of the legal mechanisms set out in UK GDPR Articles 44-49 and EU GDPR Articles 44-49.
2. The mechanisms we use
- UK adequacy decisions - for countries the UK has assessed as offering essentially-equivalent data protection (Articles 45 UK GDPR). The list is maintained by the ICO and currently includes the EEA, Switzerland, the Channel Islands, Andorra, Argentina, Canada (commercial organisations under PIPEDA), Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, the Republic of Korea, and Uruguay.
- UK International Data Transfer Agreement (IDTA) - for transfers to countries without an adequacy decision. The IDTA is the UK's standalone transfer agreement, kept available as a fallback for any processor whose terms do not already incorporate the EU SCCs with the UK Addendum (all our current processors' terms do).
- UK Addendum to the EU Standard Contractual Clauses (SCCs) - used in parallel with the EU SCCs for processors operating across the UK and EU.
- EU SCCs (2021 modules) - for transfers from the EEA to countries outside the EEA. We use the controller-to-processor module with our processors.
- EU-US Data Privacy Framework (DPF) and its UK Extension (the UK-US "Data Bridge") - for US providers that hold an active DPF certification covering the relevant services, this operates as an adequacy-based route; we still keep SCCs / the UK Addendum in place contractually as a fallback.
3. Our processors and their transfer mechanisms
Snapshot of our internal processor register, which is the source of truth.
| Processor | Purpose | Where processing happens | Mechanism |
|---|---|---|---|
| Microsoft Azure | Hosting: app runtime, databases, file storage, key vault, our self-hosted meetings servers | United Kingdom (UK South; geo-redundant database backups in UK West) | No restricted transfer for hosting - data stays in the UK. Microsoft DPA (UK Addendum + EU SCCs) covers any support access. |
| Microsoft Azure AI | AI model inference (assistant model, transcription, realtime voice) in our own subscription | United States (assistant model) or United Kingdom, depending on the model deployment; our stored data remains in the UK | UK-US Data Bridge (Microsoft is EU-US DPF certified incl. the UK Extension); Microsoft DPA UK Addendum + EU SCCs as the contractual fallback; no training on your data, abuse-monitoring retention capped at 30 days |
| Google Cloud (Gemini Enterprise Agent Platform, formerly Vertex AI) | AI image and video generation (briefs + consented source photos) | United States / global endpoints (no UK region for these models) | Google Cloud DPA: UK Addendum + EU SCCs; Google is EU-US DPF certified incl. the UK Extension |
| Stripe (Stripe Payments UK, Ltd + Stripe Payments Europe, Limited; US affiliate Stripe, LLC) | Payments | United Kingdom / Ireland / United States | UK processing is domestic; for the rest, UK Addendum + EU SCCs (Stripe's standard processor terms incorporate them); Stripe is DPF-certified |
| Resend (Plus Five Five, Inc.) | Email delivery | United States | EU SCCs (Module 2) + UK Addendum, incorporated in Resend's DPA; Resend is DPF-certified incl. the UK Extension |
| Google (Sign-in & Calendar) / Google Workspace | OAuth sign-in, optional Calendar integration; internal staff tooling | United States | UK Addendum + EU SCCs; Google is DPF-certified incl. the UK Extension |
| Google Analytics | Aggregate analytics - only after you consent in the cookies banner | United States | UK Addendum + EU SCCs; consent-based, IP anonymised |
| OpenStreetMap Foundation (Nominatim) | Resolving typed location text to coordinates | United Kingdom / EEA | No restricted transfer (UK / adequacy-covered EEA) |
| LinkedIn / Meta (Instagram, Threads) / WordPress.com / Wix / Webflow / Circle | Social integrations you connect - data flows only as you authorise | United States (varies; Wix also Israel - UK adequacy) | Not our processors: data moves to your own account on the platform only on your instruction (UK GDPR Article 49(1)(b) - necessary for the service you asked for) and is then governed by that platform's own terms and privacy policy |
The platforms in the last row are not processors acting on our behalf: they are independent services you choose to connect, and your data moves to them only on your instruction (see section 5 of the Privacy Policy; for PHI, its section 16). They are included here so the full journey of your data is visible in one place.
4. Additional safeguards we apply
- Everything we store is encrypted at rest in our UK systems (AES-256 at the platform layer, plus application-level AES-256-GCM envelope encryption - whose keys live in Azure Key Vault in the UK - for files, credentials and sensitive fields). A third-country processor receives only the transient, minimum fields needed for its task - never our encryption keys and never database access.
- TLS in transit everywhere; a two-year HSTS policy (includeSubDomains, preload-ready) in production.
- Minimum-necessary fields shared with each processor - e.g. Stripe receives your email address and name for subscription billing (card details go directly to Stripe's own checkout page) but never your date of birth or profile data; Resend receives only the recipient address and the message content.
- A written Data Processing Agreement (UK GDPR Article 28) is in place with every processor - incorporated in its service terms or signed separately - with dates and document references recorded in our internal processor register.
- We rely on adequacy-based routes wherever a provider offers one (the UK-US Data Bridge for our US providers), keep the SCCs / UK Addendum in place as the contractual fallback, and review our processors' transfer arrangements at least annually.
- These transfer safeguards sit on top of the full security programme in section 8 of the Privacy Policy (field-level encryption, multi-factor authentication, tamper-evident audit logs, least-privilege access, dependency-vulnerability monitoring), which applies wherever the data is processed.
5. Your rights regarding transfers
You can request a copy of the SCCs / IDTA / Addendum we rely on for any specific processor by emailing privacy@partnerme.net. We will provide a copy with any commercially sensitive information redacted, within one month (UK GDPR Article 12(3)).
