International Transfer Information

Version 2.0 | Published: 7 September 2026

Beta policy update. Published 7 September 2026. Updated contractual terms apply to new registrations on express acceptance and to existing accounts from 8 October 2026 after notice and any required fresh acceptance. Existing rights are preserved. Corrected operator information and new safety/privacy controls apply as they are released; notices describe those controls and do not create consent by themselves. Read the complete update.

This page describes transfer considerations. It is not a completed Transfer Impact Assessment, approval of transfers or certification of compliance. Earlier statements of approved outcomes, low residual risk, EU-only Firebase storage and configured zero retention must not be relied on without supporting evidence.

1. Known paths

The Provider Register lists the relevant cloud, AI, media, email and monitoring services. Functions use US us-central1 and production Firestore uses US multi-region nam5. Point-in-time recovery retains up to seven days; scheduled backups are enabled. Media delivery and other services can use global infrastructure. A Singapore pilot does not mean Singapore-only processing.

2. Required assessment

Transfer assessments cover the operator, recipients, purposes, sensitive-data categories, destinations, onward providers, access, retention and deletion, together with applicable contracts, foreign access risks and technical, contractual and operational safeguards. Encryption in transit or at rest does not prevent a provider that needs to process plaintext from accessing it.

Singapore PDPA transfer requirements must be met. Where EU/UK rules apply, assess the relevant adequacy or contractual mechanism and any necessary supplementary measures. Assessments must reflect actual contracts and settings, including special-category health data and precise routes. Ask legal@socialgryd.com for applicable transfer information. No approval is implied by this notice.