Privacy
Data transfer frameworks
Last updated 21 June 2026
The legal frameworks Ordnary uses to transfer personal data internationally.
We host our services primarily in the European Union. Sometimes we do transfer personal data outside the European Economic Area (EEA), for example to a subprocessor or to a Google Cloud region used for Gemini processing, as described in our Privacy Policy. This page describes the legal frameworks we use for that.
European Commission Standard Contractual Clauses
For transfers to countries without a European Commission adequacy decision, we use the Standard Contractual Clauses (SCCs) adopted by the European Commission. These clauses contractually require the receiving party to protect personal data at a level equivalent to protection within the EEA.
Supplementary technical and organizational measures
Alongside the Standard Contractual Clauses, we apply supplementary measures where necessary, such as encryption in transit and at rest, strict access controls, and contractual limits on government requests. Which supplementary measures apply depends on the destination and the nature of the data.
Adequacy decisions
For transfers to countries the European Commission has determined provide an adequate level of protection, no additional transfer mechanism is required. We monitor this list of adequacy decisions and adjust our transfer practices accordingly.
Transfers to the United Kingdom
For transfers from the United Kingdom, we use the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or another mechanism approved by the UK ICO.
More information
For an overview of which subprocessors may process data outside the EEA, see our Subprocessors page. Questions about data transfers? Contact privacy@ordnary.com.
