1. Overview & Scope
MarketFlow operates a global digital marketplace connecting buyers, sellers, and service providers across 190+ countries. To deliver our services, process transactions, and maintain platform security, personal data may be transferred across international borders. This document outlines how we lawfully, securely, and transparently manage those transfers in compliance with applicable data protection regulations, including the GDPR, UK GDPR, CCPA/CPRA, and other regional frameworks.
Key Principle: We only transfer personal data internationally when necessary to provide our services, and always with appropriate legal safeguards and technical protections in place.
2. Legal Basis & Compliance
International data transfers by MarketFlow are grounded in one or more of the following legal mechanisms, applied based on the origin and destination jurisdictions:
- Adequacy Decisions: Transfers to countries officially recognized by the European Commission, UK ICO, or relevant authorities as providing an adequate level of data protection.
- Standard Contractual Clauses (SCCs): For transfers to jurisdictions without adequacy status, we rely on the EU Commission Decision 2021/914 and UK International Data Transfer Agreements (IDTAs).
- Explicit Consent: Where required by law or user preference, we obtain clear, informed consent before cross-border processing.
- Legitimate Interests & Contractual Necessity: Transfers essential for order fulfillment, payment processing, fraud prevention, or platform operations.
We conduct Transfer Impact Assessments (TIAs) for high-risk destinations and review third-party processor agreements annually to ensure ongoing compliance.
3. Types of Data Transferred Internationally
We minimize cross-border data flows to only what is strictly necessary. The following categories may be transferred when required for service delivery:
| Data Category | Purpose of Transfer | Typical Destination |
|---|---|---|
| Account & Profile Data | Identity verification, account management | Cloud infrastructure (EU/US) |
| Transaction & Payment Data | Processing, fraud detection, payout settlement | Payment processors (Global) |
| Shipping & Delivery Information | Logistics coordination, customs clearance | Carrier networks (Region-specific) |
| Communication Records | Customer support, dispute resolution | Support centers (EU, US, India) |
| Device & Usage Analytics | Platform security, performance optimization | Analytics providers (US/EU) |
Special category data (e.g., health, biometric, political opinions) is not transferred internationally unless explicitly required by law and protected by enhanced safeguards.
4. Destination Jurisdictions
MarketFlow's primary data processing and storage locations include:
- European Economic Area (EEA): Ireland, Germany, Netherlands (primary cloud regions)
- United States: Virginia, Oregon (payment processing, AI moderation, analytics)
- United Kingdom: London (regional operations & support)
- Asia-Pacific: Singapore, Japan (seller onboarding, regional payment rails)
- Latin America: Brazil, Mexico (localized fulfillment & customer service)
All third-party service providers operating outside the EEA/UK are bound by MarketFlow's Data Processing Agreements (DPAs) and must comply with our security standards.
5. Safeguards & Transfer Mechanisms
To protect personal data during and after international transfer, MarketFlow implements the following technical and organizational measures:
- End-to-End Encryption: Data in transit uses TLS 1.3 or higher; data at rest uses AES-256 encryption.
- Data Residency Options: Enterprise and high-volume sellers can opt for regional data storage where technically feasible.
- Access Controls: Role-based access, multi-factor authentication, and strict least-privilege policies for cross-border staff.
- Audit & Monitoring: Continuous security monitoring, quarterly penetration testing, and annual SOC 2 Type II & ISO 27001 audits.
- Contractual Safeguards: SCCs/IDTAs, data processing addendums, and strict sub-processor notification requirements.
Government Access: Where destination countries lack strong legal protections against government surveillance, we implement supplementary measures including data pseudonymization, compartmentalization, and legal pushback provisions in vendor contracts.
6. Your Rights & Controls
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal data held by MarketFlow or its international processors.
- Object to or restrict cross-border processing where permitted by law.
- Request information about which countries your data is transferred to and for what purposes.
- Lodge a complaint with your local data protection authority.
You can manage your data preferences and transfer settings directly from your Account Privacy Dashboard. Changes may take up to 30 days to propagate across international systems.
7. Contact & Data Protection Officer
If you have questions about our international data transfer practices, wish to exercise your rights, or need a copy of our executed SCCs, please contact our Data Protection Office:
- Email: privacy@marketflow.com
- DPO Portal: marketflow.com/dpo-portal
- Mail: MarketFlow Data Protection Office, 1 MarketFlow Plaza, Dublin D02 X285, Ireland
We respond to legitimate requests within 30 days, as required by applicable privacy laws. No fee is charged for standard data subject requests.