International Transfer Statement
This International Transfer Statement describes how MiseCentral LLC ("MiseCentral," "we," "us," or "our") transfers Personal Data across borders in connection with the Services. This statement supplements the Data Processing Agreement ("DPA") and is incorporated by reference into the Agreement where applicable.
1. Overview
1.1. MiseCentral is headquartered in the United States. Customer Data, including Personal Data, may be processed in the United States and in other countries where MiseCentral or its Subprocessors maintain facilities or personnel.
1.2. MiseCentral implements appropriate safeguards for international transfers as required under applicable Data Protection Laws, including the GDPR, UK GDPR, Swiss FADP, and comprehensive U.S. state privacy laws where relevant to transfer assessments.
2. Primary Processing Locations
2.1. Production hosting for the Services is primarily located in the United States through cloud infrastructure Subprocessors identified in the Subprocessor Policy.
2.2. Disaster recovery, support, and engineering operations may involve processing in the United States and other jurisdictions where MiseCentral personnel or Subprocessors operate.
2.3. Enterprise Order Forms may specify regional deployment options where available.
3. Transfer Mechanisms
3.1. Adequacy Decisions. Where the European Commission, UK Secretary of State, or Swiss authorities recognize a destination country as providing adequate protection, MiseCentral may rely on the applicable adequacy decision.
3.2. Standard Contractual Clauses. For transfers from the EEA, Switzerland, or the United Kingdom to countries without an adequacy decision, including the United States, MiseCentral relies on the EU Commission 2021 Standard Contractual Clauses (Module Two: Controller to Processor) incorporated by reference in Section 12 of the DPA.
3.3. UK Addendum. For transfers subject to UK GDPR, the UK International Data Transfer Addendum issued by the Information Commissioner's Office applies in combination with the Clauses. The parties select Option 2 (approved addendum with variations) as follows:
- Importer name: MiseCentral LLC
- Importer address: 8 The Green, Suite A, Dover, DE 19901, United States
- Key contact: privacy@misecentral.com
- Table 4 ending position: the parties agree that the Clauses and Addendum survive termination of the Agreement to the extent transfers continue or residual copies remain
- Appendix information: as described in Annex I and Annex II of the DPA
3.4. Swiss Transfers. For transfers from Switzerland, the Clauses apply with modifications required by the Swiss Federal Data Protection and Information Commissioner, including designation of Swiss law where applicable under official guidance.
3.5. Supplementary Measures. Where required by supervisory authority guidance or transfer impact assessments, MiseCentral implements supplementary technical and organizational measures, which may include encryption in transit and at rest, access controls, minimization, and contractual restrictions on government access requests.
4. Subprocessor Transfers
4.1. MiseCentral ensures that Subprocessors involved in international transfers are bound by appropriate transfer mechanisms through flow-down contractual clauses or equivalent protections.
4.2. The current Subprocessor list and locations appear in the Subprocessor Policy.
5. Government Access Requests
5.1. MiseCentral reviews law enforcement and governmental requests for Customer Data in accordance with applicable law. MiseCentral will challenge requests that appear overbroad or unlawful where permitted.
5.2. Unless prohibited by law, MiseCentral will redirect requests for Customer Data to Customer where appropriate and will notify Customer of compulsory disclosure requests affecting Customer's Personal Data when permitted.
5.3. MiseCentral publishes no voluntary public commitments regarding government access beyond its contractual and legal obligations; enterprise Customers may request additional transparency information through their Order Form where available.
6. Customer Responsibilities
6.1. Customer is responsible for determining whether international transfers are permitted for Customer's use case, providing required notices to data subjects, and obtaining necessary consents or approvals.
6.2. Customer represents that it has authority to authorize transfers to MiseCentral and Subprocessors as described in this statement and the DPA.
7. Changes in Law
7.1. If applicable transfer mechanisms are invalidated or materially changed, MiseCentral will notify Customer and cooperate in good faith to implement alternative lawful mechanisms.
8. Contact
MiseCentral LLC Attn: Privacy 8 The Green, Suite A Dover, DE 19901 United States privacy@misecentral.com
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.