Data Transfer & International Data Transfer Policy
Effective 2026-08-31 · Version 1.0
1. Purpose
The Data Transfer & International Data Transfer Policy ("Data Transfer Policy") explains how ZynReach handles data transfers and data processing that may occur across borders or between different countries or geographic regions.
This Policy aims to:
- Clarify the principles of international data transfer.
- Protect Customer Data and Personal Data during transfer.
- Identify the appropriate legal bases for data transfer.
- Govern the use of service providers and third parties.
- Set out the controls applicable to international transfer.
- Support compliance with applicable legal and regulatory requirements.
- Clarify the responsibilities of ZynReach and customers regarding the international transfer of data.
2. Scope of the Policy
This Policy applies to data processed by ZynReach in the context of:
This Policy does not apply to data that is not within ZynReach's control.
- Website.
- SaaS Platform.
- APIs.
- Customer Support.
- Account Management.
- Cloud Infrastructure.
- Third-Party Services.
- Sub-processors.
- Business Operations.
3. Definition of Data
For the purposes of this Policy, "Data" may include:
Each type of data is handled according to its nature and the applicable legal and contractual obligations.
- Personal Data.
- Customer Data.
- Account Data.
- Business Data.
- Usage Data.
- Technical Data.
- Support Data.
- Security Logs.
4. Definition of Data Transfer
"Data Transfer" means any operation by which data is:
carried out in a country or region different from the country or region in which the data was collected, stored, or processed.
- Transferred.
- Made available.
- Remotely accessed.
- Stored.
- Processed.
5. International Data Transfer
"International Data Transfer" means any transfer or provision of access to Personal Data across international borders, where this results in the data becoming subject to a different legal regime.
6. Data Transfer Principles
In its data transfer operations, ZynReach relies on the following principles:
- Lawfulness.
- Transparency.
- Data minimization.
- Purpose limitation.
- Data protection.
- Security.
- Accountability.
- Respect for the legal rights of individuals.
7. No Guarantee of Fixed Data Location
Unless otherwise agreed contractually, ZynReach does not guarantee that all data associated with a customer's account is stored or processed exclusively within a single country.
Data may be processed in different locations depending on:
- Infrastructure.
- Cloud Providers.
- Sub-processors.
- Operational requirements.
- Business continuity.
- Security.
8. Data Residency
Where ZynReach offers a Data Residency or Regional Hosting option for a particular product or plan, the scope of that option is governed by the Terms of Service, the applicable commercial agreement, and the published technical specifications.
The mere existence of a data center in a given country is not a guarantee that all processing will take place exclusively within that country.
9. Regional Hosting
Depending on the product, plan, and infrastructure, ZynReach may offer regional hosting options.
The applicable commercial agreement determines:
- The region.
- The scope of data.
- Exceptions.
- Sub-processors.
- Support operations.
- Backups.
10. Data Processing Locations
Data may be processed in:
depending on the nature of the service.
- The country in which the customer is located.
- The country in which the infrastructure is located.
- A country in which a Sub-processor is located.
- A country in which a support or operations team is located.
11. Lawful Basis
Where data protection laws requiring a lawful basis for data transfer apply, ZynReach seeks to use the appropriate lawful basis according to the nature of the processing and the location of the parties.
12. Contractual Necessity
Data transfer may be necessary for the performance of the contract or the provision of the services requested by the customer or user, where permitted by applicable law.
13. Legal Obligations
Data may be transferred or made available where necessary to comply with a legal obligation applicable to ZynReach.
14. Legitimate Interests
Where permitted by applicable law, ZynReach may rely on Legitimate Interests to process or transfer certain data, taking into account a balancing of the relevant interests and rights.
15. Consent
Where the law requires explicit or specific consent for data transfer, ZynReach obtains such consent in accordance with the relevant legal requirements.
16. Standard Contractual Clauses
Where GDPR requirements or similar regimes apply, ZynReach may rely on Standard Contractual Clauses ("SCCs") or another legally recognized contractual mechanism for international data transfer.
The appropriate version or contractual module is determined according to the nature of the parties and the processing involved.
17. Transfer Impact Assessment
Where required or appropriate, ZynReach may conduct a Transfer Impact Assessment ("TIA") to assess the risks of international transfer.
The assessment may cover:
- The recipient country.
- The legal system.
- The nature of the data.
- The purpose of the transfer.
- The possibility of government access.
- Security measures.
- Additional safeguards.
18. Supplementary Measures
Where appropriate, additional measures may be applied to protect data during international transfer, such as:
- Encryption.
- Access Controls.
- Authentication.
- Pseudonymization.
- Data Minimization.
- Logging.
- Monitoring.
19. Encryption in Transit
Where technically appropriate, ZynReach uses suitable encryption methods to protect data as it travels across networks.
20. Encryption at Rest
Stored data may be encrypted in accordance with the design of the infrastructure and the service.
21. Access Control
Access to internationally transferred data is restricted according to the principle of Least Privilege, based on role and need for access.
22. Authentication
ZynReach uses appropriate authentication mechanisms to protect the systems through which data can be accessed.
23. Logging
Access to, or activities relating to, data may be logged in accordance with security, operational, and legal requirements.
24. Monitoring
ZynReach uses appropriate monitoring mechanisms to detect abnormal or unauthorized activity.
25. Sub-processors
ZynReach may rely on Sub-processors to process data.
The use of Sub-processors is governed by the Sub-processor Policy and the relevant contractual agreements.
26. International Sub-processors
Some Sub-processors may be located outside the customer's country.
This may result in the transfer or provision of access to data across borders.
27. Sub-processor Due Diligence
ZynReach seeks to assess service providers who may handle data, proportionate to:
- The nature of the service.
- The type of data.
- The risks involved.
- The level of access.
28. Contractual Protection
ZynReach seeks to include appropriate obligations for Sub-processors regarding:
- Confidentiality.
- Security.
- Data protection.
- Use of data.
- Incident notification.
- Deletion of data where applicable.
29. Sub-processor List
ZynReach may publish or make available a list of Sub-processors in accordance with the mechanism specified in the Sub-processor Policy or the DPA.
30. Changes to Sub-processors
ZynReach may add or replace Sub-processors in accordance with the notification and objection procedures set out in the DPA or the relevant agreement.
31. Customer Objection
Where the DPA or the contract grants the customer the right to object to a new Sub-processor, that right is exercised in accordance with the timeframe and procedures set out in the contract.
32. Government Requests
ZynReach may receive legal requests from government or judicial authorities for data.
ZynReach responds only in accordance with applicable legal requirements.
33. Legal Review of Requests
Where legally permitted, ZynReach may review legal requests to verify:
- Their validity.
- Their scope.
- The requesting authority's jurisdiction.
- The legal basis.
34. Data Minimization for Government Requests
Where legally permitted, ZynReach seeks to limit the data disclosed to what is legally required.
35. Customer Notification
Where permitted by law, ZynReach may notify the customer of a government request relating to its data.
Notification is not possible where prohibited by law.
36. Emergency Disclosure
Data may be disclosed in emergency situations where permitted or required by law.
37. International Law Enforcement
Where a foreign law enforcement authority requests data, ZynReach assesses the request in accordance with applicable law and the relevant legal agreements.
38. Data Transfer to Affiliates
Data may be shared or transferred between group companies or affiliates of ZynReach where necessary to provide the services or operate the business, and in accordance with applicable law and contracts.
39. Internal Access Across Borders
Certain ZynReach employees or support or security teams may have remote access to data from a different country.
This access is subject to:
- Authorization.
- Access Control.
- Security Policies.
- Confidentiality.
- Monitoring.
40. Customer Support
Providing technical or security support may require limited access to account information or data.
This is carried out in accordance with:
- Appropriate permissions.
- Business need.
- The customer agreement.
- Data protection policies.
41. Remote Access
Remote access to data from another country is considered a form of data transfer where applicable law applies to it.
42. Data Export
The customer may export its data in accordance with the platform's functionality and the agreement entered into with it.
The customer is responsible for handling the data after it has been exported to its own systems.
43. Customer-Initiated Transfers
Where the customer chooses to:
- Integrate an external service.
- Export data.
- Share data.
- Connect an external platform.
44. Third-Party Integrations
When an external integration is enabled, data may be transferred to the third party in accordance with the integration settings.
The customer must review the third party's privacy policy and terms.
45. APIs
Data may be transferred through APIs between ZynReach and the customer's systems or external systems.
These transfers are subject to appropriate authentication and security controls.
46. Data in Transit
ZynReach applies appropriate controls to protect data as it moves between systems.
47. Data at Rest
ZynReach applies appropriate controls to protect stored data in accordance with the architecture of the service.
48. Backup Transfers
Data may be backed up or replicated to other locations for the purposes of:
- Disaster Recovery.
- Business Continuity.
- Availability.
49. Disaster Recovery Transfers
Disaster recovery operations may involve the use of infrastructure or backups located in another geographic region.
These operations are subject to appropriate security and privacy controls.
50. Data Replication
ZynReach may use Replication between different environments or regions to support:
- Availability.
- Resilience.
- Disaster Recovery.
51. Data Residency Exceptions
Even where Data Residency applies, limited operational exceptions may exist relating to:
Reference must be made to the contract or the specific service to determine the scope of any data residency commitment.
- Security.
- Support.
- Monitoring.
- Backups.
- Disaster Recovery.
- Sub-processors.
52. Sensitive Data
Where the service permits the processing of sensitive data or special categories of data, additional requirements may apply to its transfer.
The customer must not enter sensitive data unless permitted under the service and the contract.
53. Special Categories
In cases where GDPR applies, ZynReach handles Special Categories of Personal Data in accordance with the relevant legal requirements.
54. Customer Responsibility
The customer remains responsible for:
- Determining the data it enters into the platform.
- Determining the lawful basis for processing.
- Ensuring the lawfulness of data transfer.
- Fulfilling its own obligations under data protection laws.
55. Controller / Processor Roles
The roles of the parties vary according to the nature of the processing.
ZynReach may act as:
The DPA and the Privacy Policy determine the appropriate role.
- Data Processor.
- Service Provider.
- or Data Controller for certain of its own operational data.
56. Data Processing Agreement
Where ZynReach acts as Processor on behalf of the customer, data processing and transfer operations are governed by the Data Processing Agreement ("DPA") entered into between the parties.
57. Priority of DPA
In the event of a conflict between this Policy and an effective DPA, the provisions of the DPA prevail to the extent necessary to resolve the conflict.
58. GDPR
Where GDPR applies to a particular processing operation, ZynReach seeks to comply with the requirements relating to international data transfer to the extent they apply.
59. UK GDPR
Where the UK GDPR applies, ZynReach may rely on transfer mechanisms recognized under UK law.
60. Other Data Protection Laws
Transfer operations may be subject to other laws, such as:
ZynReach determines the appropriate mechanism according to the scope of the applicable law.
- Local data protection laws.
- Regional privacy laws.
- Cross-border data transfer laws.
61. Cross-Border Compliance Assessment
ZynReach may assess international transfer requirements where necessary due to:
- The customer's country.
- The nature of the data.
- The place of processing.
- The Sub-processor.
- The applicable law.
62. Transfer Mechanism
One of the available lawful transfer mechanisms may be used, depending on the circumstances:
- Adequacy Decision.
- Standard Contractual Clauses.
- Approved Contractual Mechanism.
- Binding Corporate Rules.
- Consent.
- Statutory Exception.
- Another mechanism permitted by law.
63. Adequacy Decisions
Where the competent regulatory authority recognizes that a country or region provides an adequate level of protection, reliance may be placed on the adequacy decision to the extent permitted.
64. Standard Contractual Clauses
Where SCCs are the appropriate mechanism, they are incorporated into or attached to the relevant agreements in accordance with legal requirements.
65. Supplementary Security Measures
Additional measures may be applied where required or appropriate to reduce transfer risk.
66. Transfer Risk
ZynReach recognizes that international transfer may involve additional risks, including:
- Differences in data protection laws.
- Government authority requests.
- Risks of unauthorized access.
- Vendor risks.
67. Risk-Based Approach
ZynReach addresses international transfer risks using a risk-based approach.
68. Data Minimization
ZynReach seeks to limit data transfer to what is necessary to achieve the specified purpose.
69. Purpose Limitation
Transferred data should not be used for purposes incompatible with the purpose for which it was collected or processed.
70. Retention
Transferred data remains subject to the Data Retention & Deletion Policy and the applicable agreements.
71. Deletion
When the need for the data ends, or the retention period expires, it is deleted or destroyed in accordance with applicable policies and contracts.
72. International Deletion
Deletion may require removing data from:
in accordance with the applicable technical retention schedules.
- Production.
- Backups.
- Replicas.
- Disaster Recovery Environments.
73. Backup Limitations
Certain data may persist in backups for a limited period after being deleted from Production, due to the nature of backup systems.
These backups are handled in accordance with the specified retention cycle.
74. Security Incident
Where a Security Incident occurs that affects international data transfer, the Incident Response & Security Breach Notification Policy applies.
75. Breach Notification
Where a security incident results in a legal obligation to notify, ZynReach takes the required actions in accordance with applicable law and the relevant contracts.
76. International Incident Coordination
Certain incidents may require coordination between teams or entities located in different countries.
77. Documentation
Where applicable, ZynReach maintains records relating to international transfer operations and the relevant safeguard mechanisms.
78. Records of Processing
Where legal requirements apply, ZynReach may maintain appropriate processing records that include information relating to data transfer operations.
79. Audits
Eligible customers may request appropriate information or evidence regarding international data protection mechanisms in accordance with the DPA.
80. Audit Limitations
Audits are subject to:
- Confidentiality.
- Security.
- Protection of other customers.
- Non-disruption of services.
- Reasonable costs where applicable.
81. Security Certifications
Where relevant independent certifications or audit reports are available, ZynReach may provide them in accordance with permitted access conditions.
82. Transparency
ZynReach seeks to provide appropriate information regarding:
to the extent permitted by security, confidentiality, and contractual requirements.
- Processing locations.
- Sub-processors.
- Transfer mechanisms.
83. Infrastructure Changes
Changes to:
may result in changes to data processing locations.
Such changes are managed in accordance with appropriate change management procedures.
- Cloud Architecture.
- Sub-processors.
- Data Centers.
- Disaster Recovery.
84. Customer Notice
Where notice is contractually required, customers are notified in accordance with the terms of the agreement.
85. Objection Rights
Where the contract or the DPA grants the customer the right to object to a change affecting international transfer, the objection is handled in accordance with the procedures set out in the contract.
86. International Employee Access
Certain authorized employees or contractors may be able to access data from outside the customer's country.
This is subject to:
- Access Control.
- Confidentiality.
- Authentication.
- Monitoring.
- Security Training.
87. Least Privilege
Access to international data is granted only to the extent necessary to perform the relevant function.
88. Confidentiality
Individuals with authorized access to data are required to maintain its confidentiality in accordance with applicable contracts and policies.
89. Personnel Security
ZynReach applies appropriate procedures to manage employee and contractor access to systems and data.
90. Encryption Keys
Encryption keys are protected in accordance with ZynReach's approved security controls.
91. Data Transfer Security
Data transfers must take place through channels and systems appropriate for security protection.
93. Customer Configuration
Certain products may allow customers to control:
The customer is responsible for using these options in a lawful and secure manner.
- Integrations.
- Data Exports.
- User Access.
- Regional Settings.
94. International Customers
International customers may use ZynReach in accordance with the regions and services available to them, subject to the relevant legal and technical restrictions.
95. Restricted Jurisdictions
ZynReach may restrict or prohibit certain services in specific countries or regions where this is:
- Legally required.
- Necessary for compliance.
- Required for security reasons.
96. Sanctions and Export Controls
Certain services or technologies may be subject to sanctions laws or Export Controls.
ZynReach may take appropriate action to comply with applicable laws.
97. No Circumvention
ZynReach may not be used to circumvent:
- Sanctions laws.
- Export restrictions.
- Data protection requirements.
- Legal geographic restrictions.
98. Policy Changes
ZynReach may update this Policy as a result of:
- Legal changes.
- Regulatory changes.
- Technical changes.
- Changes to Sub-processors.
- Changes to the business model.
99. Effective Version
The version currently published on ZynReach's official channels is the effective version, unless the customer's agreement provides otherwise.
100. Relationship with Other Documents
This Policy operates together with:
- Privacy Policy.
- Data Processing Agreement.
- Sub-processor Policy.
- Data Retention & Deletion Policy.
- Security & Trust Policy.
- Enterprise Security Addendum.
- Incident Response & Security Breach Notification Policy.
- Business Continuity & Disaster Recovery Policy.
- Terms of Service.
101. Order of Precedence
In the event of a conflict, the order of precedence is, as applicable:
This order shall not be construed as a waiver of any legal right.
- Mandatory applicable law.
- The signed commercial agreement.
- The DPA.
- The SLA / Enterprise Addendum, depending on the subject of the conflict.
- This Policy.
- Other general policies.
102. Legal Disclaimer
This Policy does not constitute legal advice to the customer.
Each customer is responsible for assessing the requirements of the data protection laws applicable to its activities and to the data it processes through ZynReach.
103. No Absolute Guarantee
ZynReach does not guarantee that no international transfer will occur, or that data will not reach another country under all circumstances, unless there is an explicit contractual commitment to that effect.
104. No Absolute Data Residency Guarantee
No reference to a hosting region or country shall be considered a guarantee that every copy, processing activity, access, or backup will remain exclusively within that region, unless the contract or the product expressly provides otherwise.
105. Legal Compliance
ZynReach seeks to manage its international data transfer operations in a manner consistent with the laws and regulations applicable to its activities and to the processing concerned.
106. Severability
If any provision of this Policy becomes invalid or unenforceable, the remaining provisions shall remain in effect to the maximum extent permitted by law.
107. No Waiver
ZynReach's failure to apply any provision of this Policy in a particular instance does not constitute a waiver of its right to apply it subsequently.
108. Contact
For inquiries relating to data protection and international data transfer:
Privacy / Legal Contact: The official email address designated for privacy and legal matters is specified on the Legal / Privacy page at zynreach.com.
109. Document Record
The following is this document's record information:
- Document Name: Data Transfer & International Data Transfer Policy
- Abbreviation: International Data Transfer Policy
- Company: Zyntra Digital
- Platform: ZynReach
- Website: zynreach.com
- Version: 1.0
- Effective Date: August 31, 2026
- Classification: Public / Legal / Privacy
- Owner: Legal / Privacy / Compliance
- Review: Periodic or upon a material change
- Related Documents: Privacy Policy / DPA / Sub-processor Policy / Security & Trust Policy / Enterprise Security Addendum / Data Retention & Deletion Policy
110. Document Approval
Zyntra Digital / ZynReach
- Name of Authorized Signatory
- Job Title
- Signature
- Date
111. Legal Notice
This document sets out the general framework followed by ZynReach with respect to data transfer and the processing of data across international borders.
This document does not constitute a commitment that data will always remain within a specific country or geographic region, unless expressly agreed in a specific contract or service.
International data transfer operations are subject to applicable laws and regulations, in addition to the Privacy Policy, the DPA, and the relevant commercial agreements.
© 2026 Zyntra Digital. All Rights Reserved.
For privacy-related requests, contact us at privacy@zynreach.com.