International Transfer Information
This page describes transfer considerations. It is not a completed Transfer Impact Assessment, approval of transfers or certification of compliance. Earlier statements of approved outcomes, low residual risk, EU-only Firebase storage and configured zero retention must not be relied on without supporting evidence.
1. Known paths
The Provider Register lists the relevant cloud, AI, media, email and monitoring services. Functions use US us-central1 and production Firestore uses US multi-region nam5. Point-in-time recovery retains up to seven days; scheduled backups are enabled. Media delivery and other services can use global infrastructure. A Singapore pilot does not mean Singapore-only processing.
2. Required assessment
Transfer assessments cover the operator, recipients, purposes, sensitive-data categories, destinations, onward providers, access, retention and deletion, together with applicable contracts, foreign access risks and technical, contractual and operational safeguards. Encryption in transit or at rest does not prevent a provider that needs to process plaintext from accessing it.
Singapore PDPA transfer requirements must be met. Where EU/UK rules apply, assess the relevant adequacy or contractual mechanism and any necessary supplementary measures. Assessments must reflect actual contracts and settings, including special-category health data and precise routes. Ask legal@socialgryd.com for applicable transfer information. No approval is implied by this notice.
