Data Transfer & International Data Transfer Policy

Effective 2026-08-31 · Version 1.0

1. Purpose

The Data Transfer & International Data Transfer Policy ("Data Transfer Policy") explains how ZynReach handles data transfers and data processing that may occur across borders or between different countries or geographic regions.

This Policy aims to:

  • Clarify the principles of international data transfer.
  • Protect Customer Data and Personal Data during transfer.
  • Identify the appropriate legal bases for data transfer.
  • Govern the use of service providers and third parties.
  • Set out the controls applicable to international transfer.
  • Support compliance with applicable legal and regulatory requirements.
  • Clarify the responsibilities of ZynReach and customers regarding the international transfer of data.

2. Scope of the Policy

This Policy applies to data processed by ZynReach in the context of:

This Policy does not apply to data that is not within ZynReach's control.

  • Website.
  • SaaS Platform.
  • APIs.
  • Customer Support.
  • Account Management.
  • Cloud Infrastructure.
  • Third-Party Services.
  • Sub-processors.
  • Business Operations.

3. Definition of Data

For the purposes of this Policy, "Data" may include:

Each type of data is handled according to its nature and the applicable legal and contractual obligations.

  • Personal Data.
  • Customer Data.
  • Account Data.
  • Business Data.
  • Usage Data.
  • Technical Data.
  • Support Data.
  • Security Logs.

4. Definition of Data Transfer

"Data Transfer" means any operation by which data is:

carried out in a country or region different from the country or region in which the data was collected, stored, or processed.

  • Transferred.
  • Made available.
  • Remotely accessed.
  • Stored.
  • Processed.

5. International Data Transfer

"International Data Transfer" means any transfer or provision of access to Personal Data across international borders, where this results in the data becoming subject to a different legal regime.

6. Data Transfer Principles

In its data transfer operations, ZynReach relies on the following principles:

  • Lawfulness.
  • Transparency.
  • Data minimization.
  • Purpose limitation.
  • Data protection.
  • Security.
  • Accountability.
  • Respect for the legal rights of individuals.

7. No Guarantee of Fixed Data Location

Unless otherwise agreed contractually, ZynReach does not guarantee that all data associated with a customer's account is stored or processed exclusively within a single country.

Data may be processed in different locations depending on:

  • Infrastructure.
  • Cloud Providers.
  • Sub-processors.
  • Operational requirements.
  • Business continuity.
  • Security.

8. Data Residency

Where ZynReach offers a Data Residency or Regional Hosting option for a particular product or plan, the scope of that option is governed by the Terms of Service, the applicable commercial agreement, and the published technical specifications.

The mere existence of a data center in a given country is not a guarantee that all processing will take place exclusively within that country.

9. Regional Hosting

Depending on the product, plan, and infrastructure, ZynReach may offer regional hosting options.

The applicable commercial agreement determines:

  • The region.
  • The scope of data.
  • Exceptions.
  • Sub-processors.
  • Support operations.
  • Backups.

10. Data Processing Locations

Data may be processed in:

depending on the nature of the service.

  • The country in which the customer is located.
  • The country in which the infrastructure is located.
  • A country in which a Sub-processor is located.
  • A country in which a support or operations team is located.

11. Lawful Basis

Where data protection laws requiring a lawful basis for data transfer apply, ZynReach seeks to use the appropriate lawful basis according to the nature of the processing and the location of the parties.

12. Contractual Necessity

Data transfer may be necessary for the performance of the contract or the provision of the services requested by the customer or user, where permitted by applicable law.

14. Legitimate Interests

Where permitted by applicable law, ZynReach may rely on Legitimate Interests to process or transfer certain data, taking into account a balancing of the relevant interests and rights.

16. Standard Contractual Clauses

Where GDPR requirements or similar regimes apply, ZynReach may rely on Standard Contractual Clauses ("SCCs") or another legally recognized contractual mechanism for international data transfer.

The appropriate version or contractual module is determined according to the nature of the parties and the processing involved.

17. Transfer Impact Assessment

Where required or appropriate, ZynReach may conduct a Transfer Impact Assessment ("TIA") to assess the risks of international transfer.

The assessment may cover:

  • The recipient country.
  • The legal system.
  • The nature of the data.
  • The purpose of the transfer.
  • The possibility of government access.
  • Security measures.
  • Additional safeguards.

18. Supplementary Measures

Where appropriate, additional measures may be applied to protect data during international transfer, such as:

  • Encryption.
  • Access Controls.
  • Authentication.
  • Pseudonymization.
  • Data Minimization.
  • Logging.
  • Monitoring.

19. Encryption in Transit

Where technically appropriate, ZynReach uses suitable encryption methods to protect data as it travels across networks.

20. Encryption at Rest

Stored data may be encrypted in accordance with the design of the infrastructure and the service.

21. Access Control

Access to internationally transferred data is restricted according to the principle of Least Privilege, based on role and need for access.

22. Authentication

ZynReach uses appropriate authentication mechanisms to protect the systems through which data can be accessed.

23. Logging

Access to, or activities relating to, data may be logged in accordance with security, operational, and legal requirements.

24. Monitoring

ZynReach uses appropriate monitoring mechanisms to detect abnormal or unauthorized activity.

25. Sub-processors

ZynReach may rely on Sub-processors to process data.

The use of Sub-processors is governed by the Sub-processor Policy and the relevant contractual agreements.

26. International Sub-processors

Some Sub-processors may be located outside the customer's country.

This may result in the transfer or provision of access to data across borders.

27. Sub-processor Due Diligence

ZynReach seeks to assess service providers who may handle data, proportionate to:

  • The nature of the service.
  • The type of data.
  • The risks involved.
  • The level of access.

28. Contractual Protection

ZynReach seeks to include appropriate obligations for Sub-processors regarding:

  • Confidentiality.
  • Security.
  • Data protection.
  • Use of data.
  • Incident notification.
  • Deletion of data where applicable.

29. Sub-processor List

ZynReach may publish or make available a list of Sub-processors in accordance with the mechanism specified in the Sub-processor Policy or the DPA.

30. Changes to Sub-processors

ZynReach may add or replace Sub-processors in accordance with the notification and objection procedures set out in the DPA or the relevant agreement.

31. Customer Objection

Where the DPA or the contract grants the customer the right to object to a new Sub-processor, that right is exercised in accordance with the timeframe and procedures set out in the contract.

32. Government Requests

ZynReach may receive legal requests from government or judicial authorities for data.

ZynReach responds only in accordance with applicable legal requirements.

34. Data Minimization for Government Requests

Where legally permitted, ZynReach seeks to limit the data disclosed to what is legally required.

35. Customer Notification

Where permitted by law, ZynReach may notify the customer of a government request relating to its data.

Notification is not possible where prohibited by law.

36. Emergency Disclosure

Data may be disclosed in emergency situations where permitted or required by law.

37. International Law Enforcement

Where a foreign law enforcement authority requests data, ZynReach assesses the request in accordance with applicable law and the relevant legal agreements.

38. Data Transfer to Affiliates

Data may be shared or transferred between group companies or affiliates of ZynReach where necessary to provide the services or operate the business, and in accordance with applicable law and contracts.

39. Internal Access Across Borders

Certain ZynReach employees or support or security teams may have remote access to data from a different country.

This access is subject to:

  • Authorization.
  • Access Control.
  • Security Policies.
  • Confidentiality.
  • Monitoring.

40. Customer Support

Providing technical or security support may require limited access to account information or data.

This is carried out in accordance with:

  • Appropriate permissions.
  • Business need.
  • The customer agreement.
  • Data protection policies.

41. Remote Access

Remote access to data from another country is considered a form of data transfer where applicable law applies to it.

42. Data Export

The customer may export its data in accordance with the platform's functionality and the agreement entered into with it.

The customer is responsible for handling the data after it has been exported to its own systems.

43. Customer-Initiated Transfers

Where the customer chooses to:

  • Integrate an external service.
  • Export data.
  • Share data.
  • Connect an external platform.

44. Third-Party Integrations

When an external integration is enabled, data may be transferred to the third party in accordance with the integration settings.

The customer must review the third party's privacy policy and terms.

45. APIs

Data may be transferred through APIs between ZynReach and the customer's systems or external systems.

These transfers are subject to appropriate authentication and security controls.

46. Data in Transit

ZynReach applies appropriate controls to protect data as it moves between systems.

47. Data at Rest

ZynReach applies appropriate controls to protect stored data in accordance with the architecture of the service.

48. Backup Transfers

Data may be backed up or replicated to other locations for the purposes of:

  • Disaster Recovery.
  • Business Continuity.
  • Availability.

49. Disaster Recovery Transfers

Disaster recovery operations may involve the use of infrastructure or backups located in another geographic region.

These operations are subject to appropriate security and privacy controls.

50. Data Replication

ZynReach may use Replication between different environments or regions to support:

  • Availability.
  • Resilience.
  • Disaster Recovery.

51. Data Residency Exceptions

Even where Data Residency applies, limited operational exceptions may exist relating to:

Reference must be made to the contract or the specific service to determine the scope of any data residency commitment.

  • Security.
  • Support.
  • Monitoring.
  • Backups.
  • Disaster Recovery.
  • Sub-processors.

52. Sensitive Data

Where the service permits the processing of sensitive data or special categories of data, additional requirements may apply to its transfer.

The customer must not enter sensitive data unless permitted under the service and the contract.

53. Special Categories

In cases where GDPR applies, ZynReach handles Special Categories of Personal Data in accordance with the relevant legal requirements.

54. Customer Responsibility

The customer remains responsible for:

  • Determining the data it enters into the platform.
  • Determining the lawful basis for processing.
  • Ensuring the lawfulness of data transfer.
  • Fulfilling its own obligations under data protection laws.

55. Controller / Processor Roles

The roles of the parties vary according to the nature of the processing.

ZynReach may act as:

The DPA and the Privacy Policy determine the appropriate role.

  • Data Processor.
  • Service Provider.
  • or Data Controller for certain of its own operational data.

56. Data Processing Agreement

Where ZynReach acts as Processor on behalf of the customer, data processing and transfer operations are governed by the Data Processing Agreement ("DPA") entered into between the parties.

57. Priority of DPA

In the event of a conflict between this Policy and an effective DPA, the provisions of the DPA prevail to the extent necessary to resolve the conflict.

58. GDPR

Where GDPR applies to a particular processing operation, ZynReach seeks to comply with the requirements relating to international data transfer to the extent they apply.

59. UK GDPR

Where the UK GDPR applies, ZynReach may rely on transfer mechanisms recognized under UK law.

60. Other Data Protection Laws

Transfer operations may be subject to other laws, such as:

ZynReach determines the appropriate mechanism according to the scope of the applicable law.

  • Local data protection laws.
  • Regional privacy laws.
  • Cross-border data transfer laws.

61. Cross-Border Compliance Assessment

ZynReach may assess international transfer requirements where necessary due to:

  • The customer's country.
  • The nature of the data.
  • The place of processing.
  • The Sub-processor.
  • The applicable law.

62. Transfer Mechanism

One of the available lawful transfer mechanisms may be used, depending on the circumstances:

  • Adequacy Decision.
  • Standard Contractual Clauses.
  • Approved Contractual Mechanism.
  • Binding Corporate Rules.
  • Consent.
  • Statutory Exception.
  • Another mechanism permitted by law.

63. Adequacy Decisions

Where the competent regulatory authority recognizes that a country or region provides an adequate level of protection, reliance may be placed on the adequacy decision to the extent permitted.

64. Standard Contractual Clauses

Where SCCs are the appropriate mechanism, they are incorporated into or attached to the relevant agreements in accordance with legal requirements.

65. Supplementary Security Measures

Additional measures may be applied where required or appropriate to reduce transfer risk.

66. Transfer Risk

ZynReach recognizes that international transfer may involve additional risks, including:

  • Differences in data protection laws.
  • Government authority requests.
  • Risks of unauthorized access.
  • Vendor risks.

67. Risk-Based Approach

ZynReach addresses international transfer risks using a risk-based approach.

68. Data Minimization

ZynReach seeks to limit data transfer to what is necessary to achieve the specified purpose.

69. Purpose Limitation

Transferred data should not be used for purposes incompatible with the purpose for which it was collected or processed.

70. Retention

Transferred data remains subject to the Data Retention & Deletion Policy and the applicable agreements.

71. Deletion

When the need for the data ends, or the retention period expires, it is deleted or destroyed in accordance with applicable policies and contracts.

72. International Deletion

Deletion may require removing data from:

in accordance with the applicable technical retention schedules.

  • Production.
  • Backups.
  • Replicas.
  • Disaster Recovery Environments.

73. Backup Limitations

Certain data may persist in backups for a limited period after being deleted from Production, due to the nature of backup systems.

These backups are handled in accordance with the specified retention cycle.

74. Security Incident

Where a Security Incident occurs that affects international data transfer, the Incident Response & Security Breach Notification Policy applies.

75. Breach Notification

Where a security incident results in a legal obligation to notify, ZynReach takes the required actions in accordance with applicable law and the relevant contracts.

76. International Incident Coordination

Certain incidents may require coordination between teams or entities located in different countries.

77. Documentation

Where applicable, ZynReach maintains records relating to international transfer operations and the relevant safeguard mechanisms.

78. Records of Processing

Where legal requirements apply, ZynReach may maintain appropriate processing records that include information relating to data transfer operations.

79. Audits

Eligible customers may request appropriate information or evidence regarding international data protection mechanisms in accordance with the DPA.

80. Audit Limitations

Audits are subject to:

  • Confidentiality.
  • Security.
  • Protection of other customers.
  • Non-disruption of services.
  • Reasonable costs where applicable.

81. Security Certifications

Where relevant independent certifications or audit reports are available, ZynReach may provide them in accordance with permitted access conditions.

82. Transparency

ZynReach seeks to provide appropriate information regarding:

to the extent permitted by security, confidentiality, and contractual requirements.

  • Processing locations.
  • Sub-processors.
  • Transfer mechanisms.

83. Infrastructure Changes

Changes to:

may result in changes to data processing locations.

Such changes are managed in accordance with appropriate change management procedures.

  • Cloud Architecture.
  • Sub-processors.
  • Data Centers.
  • Disaster Recovery.

84. Customer Notice

Where notice is contractually required, customers are notified in accordance with the terms of the agreement.

85. Objection Rights

Where the contract or the DPA grants the customer the right to object to a change affecting international transfer, the objection is handled in accordance with the procedures set out in the contract.

86. International Employee Access

Certain authorized employees or contractors may be able to access data from outside the customer's country.

This is subject to:

  • Access Control.
  • Confidentiality.
  • Authentication.
  • Monitoring.
  • Security Training.

87. Least Privilege

Access to international data is granted only to the extent necessary to perform the relevant function.

88. Confidentiality

Individuals with authorized access to data are required to maintain its confidentiality in accordance with applicable contracts and policies.

89. Personnel Security

ZynReach applies appropriate procedures to manage employee and contractor access to systems and data.

90. Encryption Keys

Encryption keys are protected in accordance with ZynReach's approved security controls.

91. Data Transfer Security

Data transfers must take place through channels and systems appropriate for security protection.

92. Unauthorized Transfer

Where an unauthorized data transfer is detected, it is treated as a Security Incident where applicable.

93. Customer Configuration

Certain products may allow customers to control:

The customer is responsible for using these options in a lawful and secure manner.

  • Integrations.
  • Data Exports.
  • User Access.
  • Regional Settings.

94. International Customers

International customers may use ZynReach in accordance with the regions and services available to them, subject to the relevant legal and technical restrictions.

95. Restricted Jurisdictions

ZynReach may restrict or prohibit certain services in specific countries or regions where this is:

  • Legally required.
  • Necessary for compliance.
  • Required for security reasons.

96. Sanctions and Export Controls

Certain services or technologies may be subject to sanctions laws or Export Controls.

ZynReach may take appropriate action to comply with applicable laws.

97. No Circumvention

ZynReach may not be used to circumvent:

  • Sanctions laws.
  • Export restrictions.
  • Data protection requirements.
  • Legal geographic restrictions.

98. Policy Changes

ZynReach may update this Policy as a result of:

  • Legal changes.
  • Regulatory changes.
  • Technical changes.
  • Changes to Sub-processors.
  • Changes to the business model.

99. Effective Version

The version currently published on ZynReach's official channels is the effective version, unless the customer's agreement provides otherwise.

100. Relationship with Other Documents

This Policy operates together with:

  • Privacy Policy.
  • Data Processing Agreement.
  • Sub-processor Policy.
  • Data Retention & Deletion Policy.
  • Security & Trust Policy.
  • Enterprise Security Addendum.
  • Incident Response & Security Breach Notification Policy.
  • Business Continuity & Disaster Recovery Policy.
  • Terms of Service.

101. Order of Precedence

In the event of a conflict, the order of precedence is, as applicable:

This order shall not be construed as a waiver of any legal right.

  • Mandatory applicable law.
  • The signed commercial agreement.
  • The DPA.
  • The SLA / Enterprise Addendum, depending on the subject of the conflict.
  • This Policy.
  • Other general policies.

103. No Absolute Guarantee

ZynReach does not guarantee that no international transfer will occur, or that data will not reach another country under all circumstances, unless there is an explicit contractual commitment to that effect.

104. No Absolute Data Residency Guarantee

No reference to a hosting region or country shall be considered a guarantee that every copy, processing activity, access, or backup will remain exclusively within that region, unless the contract or the product expressly provides otherwise.

106. Severability

If any provision of this Policy becomes invalid or unenforceable, the remaining provisions shall remain in effect to the maximum extent permitted by law.

107. No Waiver

ZynReach's failure to apply any provision of this Policy in a particular instance does not constitute a waiver of its right to apply it subsequently.

108. Contact

For inquiries relating to data protection and international data transfer:

Privacy / Legal Contact: The official email address designated for privacy and legal matters is specified on the Legal / Privacy page at zynreach.com.

109. Document Record

The following is this document's record information:

  • Document Name: Data Transfer & International Data Transfer Policy
  • Abbreviation: International Data Transfer Policy
  • Company: Zyntra Digital
  • Platform: ZynReach
  • Website: zynreach.com
  • Version: 1.0
  • Effective Date: August 31, 2026
  • Classification: Public / Legal / Privacy
  • Owner: Legal / Privacy / Compliance
  • Review: Periodic or upon a material change
  • Related Documents: Privacy Policy / DPA / Sub-processor Policy / Security & Trust Policy / Enterprise Security Addendum / Data Retention & Deletion Policy

110. Document Approval

Zyntra Digital / ZynReach

  • Name of Authorized Signatory
  • Job Title
  • Signature
  • Date

For privacy-related requests, contact us at privacy@zynreach.com.