Documents · Data
Transfer Impact Assessment
Why two American names appear in the sub-processor list, and why no participant data reaches them.
In short
No participant data leaves the EEA in normal operation.
Two providers with US operations touch only a paying director's contact details.
Each transfer is covered by Standard Contractual Clauses plus the measures below.
1.Why this document exists
Since Schrems II a controller must assess, not assume, that a transfer outside the EEA is adequately protected. A school asking us for that assessment should not have to commission one, so ours is published.
2.What actually crosses a border
Recipient Data Participants involved Mechanism Stripe Paying director's name, organization, email, payment metadata None SCCs, module 2, plus Stripe's own EU entity Resend Recipient address and message body for directors and staff None SCCs, module 2 Apple (APNs) Device token and notification text, in transit Yes, in transit only Apple's terms and SCCs; no stored content Supabase (database and files) and Vercel (hosting) run in the EU, so nothing in the participant record crosses a border at rest.
3.The risk assessment
The question is whether US surveillance law could reach the transferred data in a way that undermines EU protection.
- 3.1Volume and nature: the transferred data is contact and billing detail for adults acting in a professional capacity, not children's records.
- 3.2Sensitivity: no special-category data, no location history, no content produced by a minor.
- 3.3Practical exposure: an order served on Stripe or Resend would reveal that an organization bought FND, not anything about its participants.
- 3.4Notification text sent through APNs may name an activity, so we keep it generic and never include a participant's full name or location.
4.Supplementary measures
- 4.1Data minimisation first: participant data is architecturally excluded from these systems rather than filtered out at runtime.
- 4.2TLS in transit to every provider, and encryption at rest at the EU providers.
- 4.3Contractual commitment from each provider to challenge overbroad requests and to notify where legally permitted.
- 4.4We tell the affected organization about any government request we receive unless we are legally forbidden to. See /security.
5.Conclusion and review
The transfers are limited, low in sensitivity and covered by SCCs together with the measures above; we consider them adequately protected. This assessment is reviewed whenever the sub-processor list changes, and at least once a year. Disagree with our reasoning? Write to privacy@findndo.app: a school's DPO spotting a gap here is doing us a favour.
Change log
v1.024 July 2026
- First published version.
Issued by
FND (Find 'n Do)
Belgium
Supervisory authority
Gegevensbeschermingsautoriteit / Autorité de protection des données
Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.
Write to us