Annex D International transfer safeguards
Terms and Notices — Sellforte Solutions Oy — 2026-09
EU/rest of the world (excluding the US). The contracting entity in the Order Form determines the applicable terms.
Annex D International transfer safeguards
Version 2026-09-22
D1 Transfer structure
International processing is limited to Annex C and DPA Section 13 (International transfers). Transfers outside the EEA rely on an applicable adequacy decision or valid safeguards. Reliance on the EU-US Data Privacy Framework requires current recipient certification covering the data. Otherwise, Sellforte uses the SCCs in Decision (EU) 2021/914 where applicable, with required assessments and supplementary measures. These requirements also cover remote access and onward transfers.
D2 Restricted onward transfers
Where SCCs are required, they bind the relevant exporter and importer before access. Module Three applies to processor-to-subprocessor transfers; other transfers use the module or mechanism appropriate to the actual roles. The completed SCC annexes identify the parties and competent authority, describe the data, purposes, frequency and retention, and specify security measures and required subprocessor information. The SCCs prevail over conflicting terms and preserve enforceable data-subject rights.
The official SCC text is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng. The relevant processing agreement incorporates it with the required selections and completed annexes. This Annex does not replace those binding arrangements. Copies are available on request, with lawful confidentiality redactions.
D3 Intragroup safeguards
Sellforte's intragroup agreement with Sellforte, Inc. incorporates Module Three for Customer Personal Data processed on Oy's behalf. Clause 7 (Docking) applies; Clause 9(a) uses general written authorization with 30 days' prior notice. Earlier access requires specific written authorization under DPA Section 7.2 and must be permitted by the transfer terms. The optional Clause 11 dispute-resolution provision does not apply. The Finnish Data Protection Ombudsman is the competent authority under Clause 13; Finnish law and courts apply under Clauses 17 and 18. Completed schedules identify the parties, processing, security measures, and authorized subprocessors. EU-to-UK Affiliate transfers rely on an applicable adequacy decision or other valid safeguard.
Sellforte assesses destination laws and practices before restricted transfers, applies necessary supplementary safeguards, and reviews relevant changes. A foreign authority's request does not itself authorize disclosure: applicable GDPR requirements, including Article 48, and transfer terms must be met. Sellforte follows applicable duties to assess and, where required, challenge requests, limit disclosure, and notify the Customer unless prohibited by law. If lawful protection cannot be maintained, Sellforte suspends the transfer and arranges a valid alternative or required return or deletion.
D4 UK and Swiss requirements
Restricted transfers governed by UK GDPR use a valid UK mechanism, including the ICO's UK Addendum or International Data Transfer Agreement where applicable, with completed information and selections. Swiss transfers use a valid mechanism with the required Swiss adaptations. An applicable adequacy decision may instead support the transfer within its scope. Mandatory transfer terms prevail over conflicting Agreement terms.
