Legal · Standard Contractual Clauses

Standard Contractual Clauses

The transfer mechanism for personal data of EU/UK visitors processed on our servers in India – the EU Standard Contractual Clauses, with the annexes that apply to the Entrifie service.

Annexes version 1.0Effective: 27 August 2026

DRAFT – requires legal review and execution before reliance

This page references the official EU clauses and outlines the annexes. The clauses are not modifiable; the annexes must be completed and executed per customer. This is not legal advice – consult qualified counsel.

Which clauses apply

For transfers of EU/EEA and UK personal data to Entrifie’s processing in India, we adopt the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 – specifically Module Two (Transfer Controller to Processor), the module for a controller exporting to a processor, which fits the SaaS arrangement between a customer (Controller) and Entrifie (Processor). For UK transfers, the clauses are read with the UK International Data Transfer Addendum. The clauses themselves are fixed EU text; only the annexes below are completed.

Roles of the parties

  • Data exporter: The customer (tenant) – Controller / Data Fiduciary.
  • Data importer: Entrifie – Processor / Data Processor.

This mirrors the allocation set out in the Data Processing Addendum.

Annex I – List of parties

Data exporter = the customer (Controller). Data importer = Entrifie (Processor). Includes contact details, the role of each party, and the competent supervisory authority. Completed at execution per tenant.

Annex II – Description of the transfer

Categories of data subjects (visitors, hosts, authorised personnel); categories of personal data (name, contact, company, host, purpose, timestamps, vehicle number, and visitor photos where enabled); frequency (continuous, per check-in); nature and purpose (visitor management and audit logging); retention (30–365 days, default 90).

Annex III – Technical and organisational measures

Security measures the importer applies: TLS in transit, AES-256 at rest, the primary datastore in India (asia-south1) with uploaded files currently held in the Google Cloud Asia multi-region, tenant isolation at the database-rule layer, role-based access, managed authentication, automated retention-bound deletion, and audit logging. Mirrors the DPA security section.

Full detail in the DPA security section and the DPIA.

Annex IV – Sub-processors

The authorised sub-processors and the transfers they perform, maintained at /legal/sub-processors. The importer notifies the exporter of additions or replacements with a reasonable objection period.

See the live list at entrifie.com/legal/sub-processors.

Official text

The authoritative, unmodified clauses are published by the European Commission:

Commission Implementing Decision (EU) 2021/914 (eur-lex.europa.eu)

Annexes version 1.0 · Related: DPA · DPIA · Sub-processors. Questions? support@entrifie.com.