Skip to main content

International Data Transfers

Gojiberry processes and stores personal data primarily within the European Union, with our main infrastructure hosted on AWS eu-west-3 in Paris, France.

Some subprocessors may process limited personal data outside the European Economic Area (EEA), including in the United States.

Details of which subprocessors are involved, and where they are located, are available in our Gojiberry Subprocessors List article.


How Are International Transfers Protected?

When personal data is transferred outside the EEA, Gojiberry applies appropriate safeguards in accordance with Chapter V of the GDPR. Depending on the subprocessor and destination country, this means one of the following:

  • Adequacy decisions — where the European Commission has recognized that a country, or a specific certification framework, ensures an adequate level of data protection. For subprocessors self-certified under the EU-U.S. Data Privacy Framework (DPF), transfers rely on the related adequacy decision (Commission Implementing Decision (EU) 2023/1795).

  • Standard Contractual Clauses (SCCs) adopted by the European Commission under Decision 2021/914/EU, for subprocessors not covered by an adequacy decision.

  • Where SCCs are used, Gojiberry assesses whether supplementary technical, organizational, or contractual measures are needed, consistent with EDPB Recommendations 01/2020, to ensure the safeguards are effective in practice.

  • Other transfer mechanisms recognized under applicable data protection law, where relevant.


Requesting More Information

Upon request, Gojiberry can provide additional information about the transfer mechanisms used for specific international transfers.

Please contact our Customer Support team or email [email protected] if you need more information.

Did this answer your question?