International Data Transfers
Last updated: 2026-09-14
This page summarizes how skink handles personal data that crosses borders. It supplements our Privacy Policy, GDPR page, and DPA, which govern in the event of any conflict.
Where processing may occur
skink and its sub-processors may process data in the United States, Germany, India, and other locations listed in our current [Subprocessor Register](/subprocessors). We keep that Register current — check it for the authoritative, up-to-date list of processing locations, rather than treating any specific country list on this page as exhaustive over time.
EU / EEA
Where personal data originating in the EEA is transferred to a location outside the EEA, we rely on the Standard Contractual Clauses adopted by the European Commission (2021 EU SCCs, Module Two: Controller to Processor, for the relationship between a customer and skink; Module Three: Processor to Processor, for any sub-processor we engage outside the EEA), together with a transfer risk assessment for each relevant destination. The executed Clauses are annexed to our DPA and available on request.
United Kingdom
For UK-originating personal data transferred outside the UK, we rely on the UK International Data Transfer Addendum to the EU SCCs (or the UK IDTA directly, as applicable), together with a UK transfer risk assessment.
Privacy contact
Privacy and data-protection inquiries can be directed to privacy@skink.dev.
Switzerland
For Swiss-originating personal data, we apply the Swiss Federal Data Protection and Information Commissioner's (FDPIC) recognized adaptations to the EU SCCs, addressing Swiss-specific requirements (including Swiss law as an alternative governing law option and FDPIC as a competent authority where applicable).
India
Transfers of data originating in India are governed by the Digital Personal Data Protection Act, 2023's restricted-country transfer model, as and when that provision takes effect: transfers are permitted except to a jurisdiction the Central Government specifically notifies as restricted. We review the notified list before enabling any new processing location. See our Privacy Policy, Section 5, for the current phased-commencement status of the DPDP framework generally.
United States and other jurisdictions
Where a US state privacy law (or a similar law in another jurisdiction) imposes processor/service- provider contract requirements on cross-border processing, our DPA is designed to support those requirements for the customers and processing they apply to.
What we don't publish here
This page describes the countries and contractual mechanisms involved, not our infrastructure topology. We don't publish which processing location is primary, secondary, or a failover target, or other architectural detail — that information isn't necessary to assess the legal basis for a transfer, and publishing it would work against the security purposes of not disclosing our architecture. Enterprise customers with a specific due-diligence need can request more detail under appropriate confidentiality arrangements at security@skink.dev.
Contact
Questions about this page: privacy@skink.dev.