1. Transfer Mechanisms in Force
1.1 EEA → United States
Where a transfer requires a Chapter V safeguard, Koydo relies on the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs") or another lawful mechanism applicable to the specific service. The SCC modules used may include:
- Module 2 (Controller-to-Processor) — for transfers from Koydo (as controller) to a U.S. processor.
- Module 3 (Processor-to-Processor) — where applicable for sub-processor flows.
Koydo reviews transfer risk and supplementary measures for provider flows that carry personal data. A provider without current evidence for the required mechanism is not enabled for child or institutional personal data.
1.2 United Kingdom → United States
Where required, transfers from the United Kingdom rely on the UK Addendum to the EU SCCs (B1.0, 21 March 2022), the UK International Data Transfer Agreement, or another lawful mechanism applicable to the specific service.
Where executed separately with a particular processor, Koydo relies on the UK International Data Transfer Agreement (IDTA).
1.3 Switzerland → United States
Where required, transfers from Switzerland rely on the EU SCCs with the applicable Swiss FADP adaptations or another lawful mechanism available for the specific service.
Plain-language summary
2. Per-Processor Transfer Inventory
| Processor category | Current public posture |
|---|---|
| Core hosting, authentication, and storage | Koydo verifies the applicable provider data-processing and transfer terms before enabling the service for personal data. |
| OpenAI API services | DPA executed March 19, 2026. Endpoint-specific retention and transfer controls remain subject to the exact service and account configuration. |
| Anthropic API services | Commercial API traffic is limited by Koydo's provider controls. Child and institutional personal data remain disabled unless private contract and configuration evidence is current. |
| Google AI services | Product, billing tier, and account configuration determine the applicable data terms. Child and institutional personal data remain disabled unless those details are privately verified. |
| Text-to-speech and media-generation services | Child personal data is blocked. Approved Koydo-authored content may be processed where no user personal data is included. |
| Payments, subscriptions, analytics, and error monitoring | The applicable provider terms and transfer safeguards are reviewed privately for each enabled data flow. Age gates and data minimization apply as described in the Privacy Policy. |
Plain-language summary
3. Requesting Copies
Executed copies of any transfer mechanism (or a redacted summary where the underlying contract is confidential) can be obtained by emailing privacy@koydo.app with subject "Transfer Mechanism Request." Koydo will provide the document within 30 days.
Plain-language summary
4. EU and UK Article 27 Representatives — STATUS: PENDING APPOINTMENT
Koydo has not yet appointed a representative under GDPR Article 27 (EU) or UK GDPR Article 27 (UK). Pending appointment, EEA and UK data subjects may contact Koydo's Privacy Team at privacy@koydo.app for all data-protection inquiries, requests, and complaints.
EEA data subjects retain the right to lodge a complaint directly with the supervisory authority of their habitual residence; the European Data Protection Board maintains a list of national authorities at edpb.europa.eu.
UK data subjects retain the right to lodge a complaint directly with the Information Commissioner's Office at ico.org.uk.
Plain-language summary
5. Data Privacy Framework
Koydo is evaluating certification under the EU-US Data Privacy Framework and the UK Extension to the DPF. Certification status, when achieved, will be published here and at dataprivacyframework.gov.
Transfers v2026-07-11 — Effective July 11, 2026 — koydo.app/legal/transfers
Plain-language summary