Legal · Effective September 26, 2026
Standard Contractual Clauses
Where personal data protected by EU, UK or Swiss law is transferred to a country without an adequacy decision in connection with CaptivaHQ, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, the “SCCs”). This page explains how they apply. They are incorporated into our Data Processing Agreement by reference.
1. When the SCCs apply
Customer records stay in the Customer's regional cell. Transfers happen mainly where a US-based provider processes EU data — for AI inference, email delivery or billing — or where an EU customer's data is supported from the United States. Where the recipient is certified under the EU-US Data Privacy Framework, that framework is relied on first; the SCCs apply otherwise, and as a fallback if the framework is invalidated.
2. Modules
| Module | Transfer | When it is used |
|---|---|---|
| Module 1 | Controller to controller | Account, billing and website data UTS handles as a controller, where it is transferred from the EEA. |
| Module 2 | Controller to processor | An EEA Customer (controller) transferring Customer Personal Data to UTS as processor. |
| Module 3 | Processor to processor | A Customer acting as processor for its own client, or UTS transferring to its sub-processors. |
| Module 4 | Processor to controller | UTS returning data to a Customer established outside the EEA. |
3. Elections under the SCCs
- Clause 7 (docking clause): included.
- Clause 9 (sub-processors): Option 2, general written authorisation, with 30 days' notice of changes as set out in the DPA.
- Clause 11 (redress): the optional independent dispute-resolution language is not included.
- Clause 13 (supervision): the supervisory authority of the Member State where the data exporter is established, or where its EU representative is appointed.
- Clauses 17 and 18 (governing law and forum): the law and courts of Ireland.
- Annex I (parties and description of transfer): Annex 1 of the DPA, with the Customer as data exporter and UTS as data importer.
- Annex II (technical and organisational measures): the Security overview.
- Annex III (sub-processors): the sub-processors page.
4. United Kingdom
For personal data subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (version B1.0) applies. Table 1–3 information is as set out above and in the DPA; for Table 4, either party may end the Addendum as permitted by its Section 19.
5. Switzerland
For personal data subject to the Swiss Federal Act on Data Protection, the SCCs apply with these changes: the Federal Data Protection and Information Commissioner is the competent supervisory authority; references to the GDPR are read as references to the FADP; and the term “Member State” does not prevent Swiss data subjects from suing in their place of habitual residence.
6. Transfer impact assessment and government access
We have assessed the laws of the destination countries and supplement the SCCs with encryption in transit and at rest, access controls, and data minimisation. If we receive a government request for Customer Personal Data, we will challenge it where there are reasonable grounds, disclose only the minimum required, and notify the Customer unless the law forbids it.
7. Getting a signed copy
The SCCs take effect through the DPA without a separate signature. If your regulator or procurement team needs an executed copy with the annexes completed, email [email protected].
Published for CaptivaHQ by United Technology Services Inc. · All documents: captivahq.com/legal. Questions: [email protected].