Legal
International transfers
Last updated: September 2026
Related: Privacy · DPA · Subprocessors
This page is a public notice of where personal data may go. It is not executed Standard Contractual Clauses, not EU–US Data Privacy Framework certification, and not a transfer impact assessment.
On this page
01Status of this document
Publishing this page does not execute SCCs, certify DPF participation, or bind either party. Transfer tools stay with counsel until a signed DPA (or order form that incorporates one) is in place. See the unsigned DPA template.
02US subprocessors
Controllers and MinuteOne may transfer personal data to subprocessors in the United States, including Stripe, Deepgram, OpenRouter, Twilio, Sentry, and tenant-chosen CRMs. The current list is on /subprocessors. Which vendors apply depends on workspace configuration.
03EU-first hosting
EU-first hosting is recommended: API, database, recordings, and LiveKit on a DE VPS; recordings in eu-central-1 or Hetzner fsn1. That preference is not a claim that all subprocessors stay in the EEA.
04How to execute
Ask counsel which transfer tool (SCCs, DPF, or otherwise) applies. To request a signed DPA that can attach those clauses, use the contact form or the DPA template. This page is not a signature.