Transfer Mechanisms
Last updated: October 1, 2026
This page is the Transfer Mechanism Site described in Section 7.2 of the Ragnerock Data Processing Addendum (the “DPA”). Where Data Protection Laws require a Transfer Mechanism for a transfer of Customer Personal Data to Ragnerock, Inc. (“Ragnerock”), or for Ragnerock’s Processing of Customer Personal Data, the applicable mechanism below is deemed signed by the Parties and incorporated into the DPA. A mechanism that doesn’t apply to a given transfer is not incorporated. Capitalized terms not defined here have the meanings given in the DPA.
1. EU Standard Contractual Clauses
This section applies to transfers of Customer Personal Data that are subject to the GDPR (Regulation (EU) 2016/679) to a country the European Commission has not found to provide an adequate level of protection.
The standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”) apply as follows:
- Modules. Module Two (controller to processor) applies where Customer is a controller. Module Three (processor to processor) applies where Customer is a processor.
- Parties. Customer is the data exporter and Ragnerock is the data importer.
- Clause 7. The optional docking clause applies.
- Clause 9. Option 2 (general written authorization) applies. The time period for prior notice of changes to Sub-processors is the period set out in Section 4.3 of the DPA.
- Clause 11. The optional language does not apply.
- Clause 13. The competent supervisory authority is determined under Clause 13(a), as set out in Annex I.C below.
- Clause 17. Option 1 applies. The EU SCCs are governed by the law of Ireland.
- Clause 18(b). Disputes are resolved before the courts of Ireland.
- Annexes. The annexes to the EU SCCs are completed as follows.
Annex I.A: List of parties
Data exporter: Customer, as identified in the Agreement or the applicable Order Form, using the contact details provided there or in Customer’s account. Activities relevant to the data transferred: use of the Ragnerock Offerings under the Agreement. Role: controller (Module Two) or processor (Module Three).
Data importer: Ragnerock, Inc., 20 N Wacker Drive, Suite 1000, Chicago, IL 60606, United States. Contact: privacy@ragnerock.com. Activities relevant to the data transferred: providing the Ragnerock Offerings under the Agreement. Role: processor.
Each Party is deemed to have signed this Annex I.A on the date the DPA takes effect between them.
Annex I.B: Description of the transfer
The categories of data subjects, categories of personal data, sensitive data, frequency of the transfer, nature and purpose of the Processing, and retention period are as set out in Section 3.5 of the DPA. Safeguards for sensitive data are the measures in the Security Addendum.
Transfers to Sub-processors are made for the subject matter, nature, and duration described in Section 4 of the DPA and on the Sub-processor list.
Annex I.C: Competent supervisory authority
The supervisory authority identified under Clause 13(a) of the EU SCCs.
Annex II: Technical and organizational measures
The measures described in the Ragnerock Security Addendum.
Annex III: List of sub-processors
The Sub-processors listed on the Sub-processor list, as updated under Section 4.3 of the DPA.
2. United Kingdom
This section applies to transfers of Customer Personal Data that are subject to the UK GDPR and the Data Protection Act 2018 to a country not covered by UK adequacy regulations.
The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0), issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 (the “UK Addendum”), applies to the EU SCCs as completed in Section 1, as follows:
- Table 1. The parties and their details are as set out in Annex I.A. The start date is the date the DPA takes effect between the Parties.
- Table 2. The Addendum EU SCCs are the EU SCCs, with the modules and options selected in Section 1.
- Table 3. The Appendix Information is as set out in Annexes I.A, I.B, II, and III in Section 1.
- Table 4. Either Party may end the UK Addendum as set out in Section 19 of the UK Addendum.
3. Switzerland
This section applies to transfers of Customer Personal Data that are subject to the Swiss Federal Act on Data Protection (the “FADP”) to a country the Swiss Federal Council has not recognized as providing an adequate level of protection. The EU SCCs apply as completed in Section 1, with these changes for those transfers:
- References to the GDPR are read as references to the FADP.
- The competent supervisory authority under Clause 13 is the Swiss Federal Data Protection and Information Commissioner.
- The term “Member State” in Clause 18(c) does not prevent data subjects in Switzerland from bringing claims in their place of habitual residence.
- The governing law and choice of forum in Section 1 continue to apply.
4. Changes to this page
As Section 7.2.2 of the DPA requires, we record a summary and the date of every change to this page below.