Skip to main content

Data Transfer Impact Assessment

Version 2026-08-16 · Effective 2026-08-16

What this is

This page summarises how we assess transfers of personal data to our processors, in line with Articles 44 to 49 of the GDPR and the Schrems II ruling. It is the UK/EU transfer assessment; transfers relevant to the United States and India (DPDP Act) are addressed in our Privacy Notice. It accompanies our Privacy Notice and our internal Data Protection Impact Assessment.

If you have questions about international transfers, write to support@myfinmaps.com.

Scope, necessity and proportionality

MyFinMaps processes the personal and financial data you enter to deliver the service, together with limited security and usage signals. We collect only what we need (email is mandatory; a mobile number is optional), we do not solicit special-category data, and we delete data on a published retention schedule.

How we protect transferred data

Every processor we use is covered by the EU Standard Contractual Clauses together with the UK Addendum, or by the UK International Data Transfer Agreement. In each case the safeguard takes effect automatically under the provider's own data processing terms rather than requiring a separately negotiated document. These are supported by supplementary measures: encryption in transit (TLS), encryption at rest, and application-layer encryption of identifier data such as your mobile number and policy/account numbers.

We host our database, rate-limiting cache, and serverless functions in the United Kingdom (London) and send transactional email through a provider in the European Union (Ireland). We do not treat that hosting location as settling the question: the companies behind those services are, in most cases, incorporated in the United States, so we apply a transfer safeguard to all of them rather than only to those serving us from outside the UK and EU. We also minimise what each processor receives; for example, our hosting and email providers do not receive your encrypted portfolio store.

Per-processor transfer assessment

ProcessorPurposeData they receiveRegionTransfer
PostgreSQL host (Neon - Databricks, Inc.)Primary application databaseAll application PII (users, holdings, cash-flow, audit/event logs)AWS eu-west-2 (London)EU SCCs + UK Addendum (Databricks DPA §8.1, Annex B)
Vercel, Inc.Hosting, CDN, serverless functions, logsRequest metadata, IP, logs, all trafficlhr1 (London)EU SCCs + UK IDTA (Vercel DPA Sch. 3 & 5)
Cloudflare Turnstile (Cloudflare, Inc.)Anti-bot CAPTCHAIP address, challenge tokenGlobalEU SCCs + UK Addendum (Cloudflare DPA v6.4 cl. 6.2)
Upstash Redis (Upstash, Inc.)Rate limiting, login lockout, short-lived tokensIP, hashed email identifier (lockout)AWS eu-west-2 (London)EU SCCs + UK Addendum (Upstash DPA Annex 2 §2.1–2.2)
Resend (Plus Five Five, Inc.)Transactional emailRecipient email, email bodyIreland (eu-west-1)EU SCCs + UK Addendum (Resend DPA §6.3.9, §6.4)

Residual risk and review

The processors that hold your personal data are hosted in the United Kingdom and the European Union, but most are US-incorporated companies, so we assess each as a potential cross-border transfer regardless of its region. For each we have considered the risk of government access and concluded that the combination of the safeguards described above, encryption, and how little any single processor receives keeps residual risk at an acceptable level. Two examples of that minimisation: our anti-bot provider sees only your IP address and a challenge token, and our rate-limiting provider holds no email address at all - it receives only a one-way cryptographic identifier that cannot be turned back into your address. We review this assessment at least annually and whenever a processor, region, or data category changes.

This is a public summary. Our full DPIA and Transfer Impact Assessment, including outstanding actions, is maintained internally and available to supervisory authorities on request.