What this is
This page summarises how we assess transfers of personal data to our processors, in line with Articles 44 to 49 of the GDPR and the Schrems II ruling. It is the UK/EU transfer assessment; transfers relevant to the United States and India (DPDP Act) are addressed in our Privacy Notice. It accompanies our Privacy Notice and our internal Data Protection Impact Assessment.
If you have questions about international transfers, write to support@myfinmaps.com.
Scope, necessity and proportionality
MyFinMaps processes the personal and financial data you enter to deliver the service, together with limited security and usage signals. We collect only what we need (email is mandatory; a mobile number is optional), we do not solicit special-category data, and we delete data on a published retention schedule.
How we protect transferred data
Every processor we use is covered by the EU Standard Contractual Clauses together with the UK Addendum, or by the UK International Data Transfer Agreement. In each case the safeguard takes effect automatically under the provider's own data processing terms rather than requiring a separately negotiated document. These are supported by supplementary measures: encryption in transit (TLS), encryption at rest, and application-layer encryption of identifier data such as your mobile number and policy/account numbers.
We host our database, rate-limiting cache, and serverless functions in the United Kingdom (London) and send transactional email through a provider in the European Union (Ireland). We do not treat that hosting location as settling the question: the companies behind those services are, in most cases, incorporated in the United States, so we apply a transfer safeguard to all of them rather than only to those serving us from outside the UK and EU. We also minimise what each processor receives; for example, our hosting and email providers do not receive your encrypted portfolio store.
Per-processor transfer assessment
| Processor | Purpose | Data they receive | Region | Transfer |
|---|---|---|---|---|
| PostgreSQL host (Neon - Databricks, Inc.) | Primary application database | All application PII (users, holdings, cash-flow, audit/event logs) | AWS eu-west-2 (London) | EU SCCs + UK Addendum (Databricks DPA §8.1, Annex B) |
| Vercel, Inc. | Hosting, CDN, serverless functions, logs | Request metadata, IP, logs, all traffic | lhr1 (London) | EU SCCs + UK IDTA (Vercel DPA Sch. 3 & 5) |
| Cloudflare Turnstile (Cloudflare, Inc.) | Anti-bot CAPTCHA | IP address, challenge token | Global | EU SCCs + UK Addendum (Cloudflare DPA v6.4 cl. 6.2) |
| Upstash Redis (Upstash, Inc.) | Rate limiting, login lockout, short-lived tokens | IP, hashed email identifier (lockout) | AWS eu-west-2 (London) | EU SCCs + UK Addendum (Upstash DPA Annex 2 §2.1–2.2) |
| Resend (Plus Five Five, Inc.) | Transactional email | Recipient email, email body | Ireland (eu-west-1) | EU SCCs + UK Addendum (Resend DPA §6.3.9, §6.4) |
Residual risk and review
The processors that hold your personal data are hosted in the United Kingdom and the European Union, but most are US-incorporated companies, so we assess each as a potential cross-border transfer regardless of its region. For each we have considered the risk of government access and concluded that the combination of the safeguards described above, encryption, and how little any single processor receives keeps residual risk at an acceptable level. Two examples of that minimisation: our anti-bot provider sees only your IP address and a challenge token, and our rate-limiting provider holds no email address at all - it receives only a one-way cryptographic identifier that cannot be turned back into your address. We review this assessment at least annually and whenever a processor, region, or data category changes.
This is a public summary. Our full DPIA and Transfer Impact Assessment, including outstanding actions, is maintained internally and available to supervisory authorities on request.