Annex D International transfer safeguards
Terms and Notices — Sellforte Solutions Oy — 2026-09
EU/rest of the world (excluding the US)
Annex D International transfer safeguards
D1 Transfer structure
The Customer authorizes international processing within Annex C. Sellforte relies on applicable adequacy decisions, including a valid EU–US Data Privacy Framework certification for the relevant recipient, or the European Commission's Standard Contractual Clauses in Decision (EU) 2021/914, with required supplementary measures. Information about the applicable safeguards is available on request.
D2 Restricted onward transfers
For a restricted transfer from Sellforte to a supplier or Affiliate, the SCCs bind Sellforte and the recipient through their processing agreement. Module Three applies where Sellforte is processor and the recipient is subprocessor; Module Two applies where the actual exporter is controller and the importer is processor. A controller-to-controller transfer uses the appropriate controller arrangement. The SCCs prevail over conflicting contractual terms, and their data-subject rights remain enforceable.
The official SCC text is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng. Supplier agreements may make permitted selections under the SCCs without reducing protection required by this DPA.
D3 Intragroup safeguards
Sellforte's intragroup agreement with Sellforte, Inc. incorporates the SCCs for Oy Customer Personal Data under Module Three. Clause 7 (Docking) applies; Clause 9(a) uses general written authorization with 30 days' notice or a shorter period permitted by this DPA; the optional independent dispute-resolution provision in Clause 11 does not apply. The competent supervisory authority under Clause 13 is the Finnish Data Protection Ombudsman. Finnish law and Finnish courts apply under Clauses 17 and 18. Schedules 1–3 to the intragroup agreement identify the parties, processing, safeguards, and authorized subprocessors and complete the SCC annexes.
Sellforte assesses the relevant destination laws and practices, applies necessary supplementary safeguards, and follows the SCC requirements for government requests. If a transfer can no longer lawfully continue, Sellforte implements a valid alternative or suspends the transfer and requires return or deletion as applicable. Copies of the relevant safeguards are available on request, with lawful redactions to protect confidential information.
D4 UK and Swiss requirements
Where UK GDPR applies to a restricted transfer, Sellforte ensures that the ICO's mandatory International Data Transfer Addendum or another valid UK transfer mechanism binds the relevant exporter and importer. For Swiss transfers, the applicable SCCs are supplemented for the Swiss Federal Act on Data Protection, Swiss data-subject rights, and the competent Swiss authority. These instruments prevail over conflicting terms to the extent required by law. A valid adequacy decision may instead support the transfer within its scope.
