Skip to content

Legal

International transfers

Last updated: September 2026

Related: Privacy · DPA · Subprocessors

This page is a public notice of where personal data may go. It is not executed Standard Contractual Clauses, not EU–US Data Privacy Framework certification, and not a transfer impact assessment.

01Status of this document

Publishing this page does not execute SCCs, certify DPF participation, or bind either party. Transfer tools stay with counsel until a signed DPA (or order form that incorporates one) is in place. See the unsigned DPA template.

02US subprocessors

Controllers and MinuteOne may transfer personal data to subprocessors in the United States, including Stripe, Deepgram, OpenRouter, Twilio, Sentry, and tenant-chosen CRMs. The current list is on /subprocessors. Which vendors apply depends on workspace configuration.

03EU-first hosting

EU-first hosting is recommended: API, database, recordings, and LiveKit on a DE VPS; recordings in eu-central-1 or Hetzner fsn1. That preference is not a claim that all subprocessors stay in the EEA.

04How to execute

Ask counsel which transfer tool (SCCs, DPF, or otherwise) applies. To request a signed DPA that can attach those clauses, use the contact form or the DPA template. This page is not a signature.