SPOCK

TRUST CENTER

Transfer Impact Assessments

Prepared by: Seleya Labs Inc. (operator of Spock) · Review cycle: annually, or on vendor or legal change · Referenced by DPA §13.1

This document records Spock’s assessment of transfers of personal data from the EEA/UK (and, under POPIA s. 72, from South Africa) to processors in the United States, following the six-step methodology of EDPB Recommendations 01/2020 (post Schrems II).

Not in scope (no third-country transfer): Hetzner and DigitalOcean (Germany); Daytona (EU); ZenRows S.L. (Spain); the self-hosted Spock model and embeddings (Spock-managed EU infrastructure).

Seleya Labs Inc. itself: Seleya is US-incorporated, but Customer Content is stored and processed in the EU. Remote administrative access by Seleya personnel is limited, logged, and bound by the DPA; that access is covered by the Step 3 analysis and Step 4 measures below.


Step 1 — Transfers mapped

VendorData transferredTriggerFrequency
OpenAIPrompts, files, and context in requestsUser selects an OpenAI modelPer request
AnthropicSameUser selects an Anthropic modelPer request
Google (Gemini API / Vertex AI)Same; plus images for generation and voice notes for transcriptionUser selects a Google model / uses those featuresPer request
xAISame (routed via a Spock-operated US relay)User selects an xAI modelPer request
Fireworks AISameUser selects a hosted open-source modelPer request
StripeBilling contact, subscription data (Stripe is independent controller for card data)Paid subscriptionOngoing
SerperWeb search query stringsUser/agent invokes web searchPer request
Slack (Salesforce)Support requests, response reports, error alerts: user email, name, workspace names, submitted textSupport/report/error eventsEvent-driven
Meta (WhatsApp Business Platform)WhatsApp phone numbers and message contentCustomer connects the WhatsApp channelPer message
CloudflareRecipient email addresses and transactional email contentEmail deliveryPer email

Step 2 — Transfer mechanism

The operative transfer mechanism for every vendor above is the EU Standard Contractual Clauses (2021/914) (with the UK International Data Transfer Addendum and Swiss adaptation as applicable), entered into through each vendor’s data processing agreement. For transfers from South Africa, the parties rely on POPIA s. 72(1)(b): the SCCs and vendor DPAs constitute binding agreements providing an adequate level of protection.

Several vendors — including Google, Meta, Salesforce (Slack), Stripe, and Cloudflare — additionally hold certifications under the EU–US Data Privacy Framework, whose adequacy decision provides a further, independent layer of protection. Spock deliberately relies on the SCCs as the operative mechanism for all vendors so that the validity of any individual transfer does not depend on a vendor’s DPF listing or on the continued validity of the DPF adequacy decision.

The relevant US surveillance authorities are FISA §702 (compelled disclosure by “electronic communication service providers”), EO 12333 (in-transit collection), and the CLOUD Act (law-enforcement process).

Assessment: for these transfers — transient processing data, short retention, encrypted in transit, with no bulk storage of EU personal data in the US other than Slack support threads and Stripe billing records — there is no substantiated reason to believe any listed vendor cannot comply with the SCCs in practice.

Step 4 — Supplementary measures applied

Step 5 — Conclusion

For each vendor listed, taking into account the nature of the data, the per-request and transient character of the AI transfers, the short retention periods, the EO 14086 safeguards, the additional DPF certifications where held, and the supplementary measures above, Spock concludes that transferred personal data receives essentially equivalent protection, and that the transfers may proceed. Customers with heightened requirements can eliminate US AI transfers entirely by using the Spock model.

Step 6 — Monitoring

The privacy officer (Louis-Neil Korsten) reviews this assessment annually — including vendor transparency reports and certification status — and additionally upon: invalidation of the DPF adequacy decision, material change in US law, a relevant vendor security incident, or any sub-processor change. Version history is maintained with this document.


Per-vendor notes