Sintora Give Your Company One Brain
Trust Center

Trust Center

International transfers

We keep data within the European Economic Area by default. Where a transfer is necessary, it relies on a mechanism recognised under Chapter V GDPR — and below is which mechanism applies to whom.

Outside the EEA: 1 of 3. Every one of them is named in the table below.

Read next

Where the data goes

Transfers of personal data outside the EEA: recipient, direction and the Chapter V GDPR mechanism
RecipientDirectionChapter V GDPR mechanismWhere this is written down
Cloudflare, Inc.EEA → US / global edgeDPF or the Standard Contractual Clauses, where applicable Awaiting confirmation: whether the DPF certification is current and whether our contract carries the ClausesPrivacy Policy → International transfers

Not in the table, because there is no transfer — with what is still open for each:

  • Hetzner Online GmbHProcessing within the EEA Awaiting confirmation: which Hetzner location production runs in
  • Scaleway SASProcessing within the EEA Awaiting confirmation: which Scaleway region inference runs in

Also outside the table is our workflow automation: it is open-source software we deployed and operate ourselves, on the infrastructure of our hosting provider — and that provider is named on our sub-processor list.

The full list of recipients, including those with no transfer: sub-processors.

What we owe you around a transfer

The mechanism is half the answer. The other half is whether you can verify it and whether we will help you do so. The three points below are taken from the data processing agreement and the privacy policy rather than written for this page.

  • Transfer impact assessment

    On request we provide the information you reasonably need to carry out a transfer impact assessment, and we apply supplementary technical measures where the assessment calls for them.

    DPA → International transfers
  • The SCC terms people ask about

    Where the Standard Contractual Clauses apply, the docking clause is available, the governing law is Estonian, and the competent supervisory authority is the Estonian Data Protection Inspectorate.

    DPA → International transfers
  • A copy of the safeguards

    We send a copy of the safeguards applying to any transfer on request — write to info@sintora.ai.

    Privacy Policy → International transfers

What we are not claiming here

We do not claim that a Chapter V mechanism removes the risk. An adequacy decision is not perpetual — two have been struck down already. What is not yet checked for a given row is written in the table itself rather than restated here: a restatement goes stale on the day the row is confirmed. We have not commissioned or published a transfer impact assessment of our own; what we have is the information we give you for yours.

The transfers section of the DPA