TRUST CENTER
Transfer Impact Assessments
Prepared by: Seleya Labs Inc. (operator of Spock) · Review cycle: annually, or on vendor or legal change · Referenced by DPA §13.1
This document records Spock’s assessment of transfers of personal data from the EEA/UK (and, under POPIA s. 72, from South Africa) to processors in the United States, following the six-step methodology of EDPB Recommendations 01/2020 (post Schrems II).
Not in scope (no third-country transfer): Hetzner and DigitalOcean (Germany); Daytona (EU); ZenRows S.L. (Spain); the self-hosted Spock model and embeddings (Spock-managed EU infrastructure).
Seleya Labs Inc. itself: Seleya is US-incorporated, but Customer Content is stored and processed in the EU. Remote administrative access by Seleya personnel is limited, logged, and bound by the DPA; that access is covered by the Step 3 analysis and Step 4 measures below.
Step 1 — Transfers mapped
| Vendor | Data transferred | Trigger | Frequency |
|---|---|---|---|
| OpenAI | Prompts, files, and context in requests | User selects an OpenAI model | Per request |
| Anthropic | Same | User selects an Anthropic model | Per request |
| Google (Gemini API / Vertex AI) | Same; plus images for generation and voice notes for transcription | User selects a Google model / uses those features | Per request |
| xAI | Same (routed via a Spock-operated US relay) | User selects an xAI model | Per request |
| Fireworks AI | Same | User selects a hosted open-source model | Per request |
| Stripe | Billing contact, subscription data (Stripe is independent controller for card data) | Paid subscription | Ongoing |
| Serper | Web search query strings | User/agent invokes web search | Per request |
| Slack (Salesforce) | Support requests, response reports, error alerts: user email, name, workspace names, submitted text | Support/report/error events | Event-driven |
| Meta (WhatsApp Business Platform) | WhatsApp phone numbers and message content | Customer connects the WhatsApp channel | Per message |
| Cloudflare | Recipient email addresses and transactional email content | Email delivery | Per email |
Step 2 — Transfer mechanism
The operative transfer mechanism for every vendor above is the EU Standard Contractual Clauses (2021/914) (with the UK International Data Transfer Addendum and Swiss adaptation as applicable), entered into through each vendor’s data processing agreement. For transfers from South Africa, the parties rely on POPIA s. 72(1)(b): the SCCs and vendor DPAs constitute binding agreements providing an adequate level of protection.
Several vendors — including Google, Meta, Salesforce (Slack), Stripe, and Cloudflare — additionally hold certifications under the EU–US Data Privacy Framework, whose adequacy decision provides a further, independent layer of protection. Spock deliberately relies on the SCCs as the operative mechanism for all vendors so that the validity of any individual transfer does not depend on a vendor’s DPF listing or on the continued validity of the DPF adequacy decision.
Step 3 — US legal framework assessment (common analysis)
The relevant US surveillance authorities are FISA §702 (compelled disclosure by “electronic communication service providers”), EO 12333 (in-transit collection), and the CLOUD Act (law-enforcement process).
- FISA §702: the larger providers in scope likely qualify as ECSPs and could in principle receive directives. However, the data Spock transfers is business content submitted for immediate processing, retained at AI providers for no more than 30 days and not indexed for user-level lookup — an impractical surveillance target compared to communications platforms. The vendors’ published transparency reports do not indicate §702 process against enterprise API traffic of this kind.
- EO 14086 safeguards (the basis of the DPF adequacy decision) — necessity and proportionality limits on signals intelligence and the Data Protection Review Court redress mechanism — apply to all EU-origin personal data handled by US companies, whether or not a given vendor is DPF-certified. This materially improves the position relative to the facts assessed in Schrems II, including for SCC-only vendors.
- CLOUD Act: applies to data in the vendors’ possession; mitigated by the short retention at AI vendors and vendor policies of redirecting law-enforcement requests to the customer.
Assessment: for these transfers — transient processing data, short retention, encrypted in transit, with no bulk storage of EU personal data in the US other than Slack support threads and Stripe billing records — there is no substantiated reason to believe any listed vendor cannot comply with the SCCs in practice.
Step 4 — Supplementary measures applied
- Technical: TLS 1.3 in transit; per-request (not bulk) transfers to AI vendors; contractual retention of no more than 30 days at AI vendors, with no training on transferred data; data minimisation — only the conversation context needed for the request is sent; AI vendors receive request content but not Spock account identity beyond the API account; an EU alternative (the Spock model) lets customers avoid the transfer entirely.
- Contractual: SCCs and DPAs with each vendor; no-training clauses; vendor obligations to challenge disproportionate government requests and to notify unless legally prohibited.
- Organisational: annual vendor review covering terms, transparency reports, and certification status; this TIA re-run on material change; customer notice and objection rights for new sub-processors (DPA §7.2).
Step 5 — Conclusion
For each vendor listed, taking into account the nature of the data, the per-request and transient character of the AI transfers, the short retention periods, the EO 14086 safeguards, the additional DPF certifications where held, and the supplementary measures above, Spock concludes that transferred personal data receives essentially equivalent protection, and that the transfers may proceed. Customers with heightened requirements can eliminate US AI transfers entirely by using the Spock model.
Step 6 — Monitoring
The privacy officer (Louis-Neil Korsten) reviews this assessment annually — including vendor transparency reports and certification status — and additionally upon: invalidation of the DPF adequacy decision, material change in US law, a relevant vendor security incident, or any sub-processor change. Version history is maintained with this document.
Per-vendor notes
- OpenAI / Anthropic / Google / xAI / Fireworks: API-tier terms apply — no training on API data; abuse-monitoring retention of no more than 30 days. xAI traffic egresses via a Spock-operated US relay used solely to route requests; the relay does not persist message content.
- Stripe: independent controller for payment data; PCI-DSS Level 1; billing records retained per tax law.
- Slack: persistent storage of support threads in Spock’s internal workspace — the only long-lived EU personal data at rest in the US in this map. Mitigation: content is limited to user-submitted support/report text and identifiers, and workspace access is restricted to Spock staff.
- Meta (WhatsApp): engaged only when a customer connects the channel; message content necessarily traverses Meta’s Business API; the Privacy Policy informs users that channel messages are not end-to-end encrypted to Spock.
- Serper: receives search query strings only; queries can incidentally contain personal data; no account identifiers are attached. Treated as a third-country transfer under SCCs irrespective of corporate seat.
- Cloudflare: transactional email only (verification, notifications); minimal personal data.