Legal
International Data Transfers Notice
This Notice explains how Infotech Solutions handles transfers of personal data outside the European Economic Area (EEA) in connection with Tamanor, in accordance with Chapter V of the GDPR.
Last updated: 17 July 2026
1. Our approach
We keep personal data within the EEA wherever practical and select EEA regions for hosting where our providers offer them. Some sub-processors are established in, or process data from, third countries (in particular the United States). For every such transfer we ensure an appropriate transfer mechanism is in place before data flows.
2. Transfer mechanisms we rely on
- Adequacy decisions (Art. 45). Where the European Commission has decided a country or framework offers adequate protection, we rely on it. For transfers to the United States, we rely on the EU–US Data Privacy Framework (DPF) where the recipient is certified under it. (The DPF adequacy decision of 10 July 2023 remains in force; it is subject to ongoing review and litigation, which we monitor.)
- Standard Contractual Clauses (Art. 46(2)(c)). Where adequacy does not apply, we use the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the appropriate modules, as our primary safeguard and fallback.
- Transfer Impact Assessment (TIA). Alongside SCCs, we assess the destination country's laws and, where needed, apply supplementary measures (e.g. encryption, minimisation, access controls) to ensure protection essentially equivalent to the EU.
- Derogations (Art. 49). Only in limited, occasional cases and where no other mechanism applies (e.g. explicit consent, or necessity for a contract).
3. Where transfers may occur
Transfers may occur to providers listed in our Subprocessor List, notably for hosting, e-mail delivery, payment processing, rate-limiting, optional AI classification, and consent-gated website analytics/marketing. The relevant safeguard for each is indicated there.
4. Redundancy by design
For US transfers we generally maintain both an adequacy basis (DPF, where the recipient is certified) and SCCs, so that data flows can continue lawfully even if one mechanism is affected by legal developments.
5. Your rights and copies of safeguards
You may request information about the transfers relevant to you and a copy of the relevant safeguards (e.g. the SCCs, with commercially confidential terms redacted) by contacting info@tamanor.com.
6. Updates
We update this Notice as adequacy decisions, providers or legal circumstances change. The effective date appears above.