International transfers and SCCs

Annex IV to the ohmyho.st DPA. Version: September 13, 2026.

When SCCs are needed

amerged B.V. is established in the Netherlands. An EEA customer's appointment of amerged B.V. as processor is governed by Article 28 GDPR and our DPA; it does not, by itself, require international-transfer SCCs between that customer and amerged B.V.

The service also uses US and global infrastructure. Transfers to, or access by, a separate recipient outside the EEA require a valid Chapter V GDPR basis where that chapter applies. An applicable adequacy decision can provide that basis. Reliance on the EU–US Data Privacy Framework requires a current, in-scope certification of the recipient; US location alone is not evidence of certification. Where adequacy does not cover the transfer, appropriate safeguards, ordinarily the applicable SCCs, are required before the transfer proceeds.

Applicable clauses and roles

The relevant EU international-transfer clauses are those in the Annex to Commission Implementing Decision (EU) 2021/914. Their operative text is used without rewriting it. A summary page or a provider's compliance badge does not replace the clauses or a completed transfer assessment.

For customer workload data, amerged generally acts as processor and the infrastructure recipient as subprocessor: Module Three applies where SCCs are the required mechanism. For account or business data for which amerged is controller and a non-EEA recipient is processor, Module Two applies where appropriate. The applicable provider agreement supplies the contracting importer, selected options and completed annexes for that engagement. AWS, Cloudflare and WorkOS publish contractual SCC arrangements in their data-processing terms; Neon’s published DPA also provides transfer clauses, whose applicability and module depend on the signed account agreement. These provider instruments govern the onward transfer rather than incorrectly identifying an EU customer as a direct exporter to every infrastructure supplier.

Transfer record and supplementary measures

For each restricted transfer, the operative record must identify the exporter/importer, subject matter, categories of data and people, purposes, frequency, retention, competent supervisory authority, applicable module/options and technical and organisational measures. Annex I of our DPA describes the workload, and Annex II describes our measures; supplier-specific annexes must also describe the recipient's actual processing.

The assessment must consider the destination's relevant laws and practices, the data, access needs and supplementary measures. Measures can include encrypted transit and storage, restricted credentials and access, data minimisation, separation of management credentials and handling of government requests. Encryption is not treated as preventing access by a recipient that needs plaintext to provide the service.

If the required level of protection cannot be maintained, the affected transfer must be suspended or an effective alternative put in place. Copies or information about applicable safeguards can be requested through the contact form, with necessary protections for confidential information. UK or Swiss data requires the applicable local transfer instrument where relevant, rather than assuming the EU text alone covers every jurisdiction.

Official SCC text · DPA · TOMs · Contact form

Get beta access

Register your interest in ohmyho.st.