How are data transfers to third countries secured?
amaise provides dedicated data zones for the EU, CH, and US. Customer data remains strictly within the assigned region:
EU data zone: Core data processing (documents, database, AI) takes place in the EU/Switzerland. Data never leaves the EU.
CH data zone: Swiss customer data is stored and processed exclusively in Switzerland (AWS Zurich, Azure OpenAI Switzerland North).
US data zone: Core data processing takes place in the USA. Data never leaves the USA.
US-based supporting services do not process customer document content:
Auth0/Okta — User login data and authentication events
Sentry — Error reports (automatically PII-scrubbed)
Snyk — Dependency analysis (no source code, no customer data)
Mixpanel — Product analytics (no customer data, no PII)
Twilio — SMS delivery for MFA (transactional)
All transfers to the USA are secured by GDPR Standard Contractual Clauses (SCCs) and the respective vendor DPAs. For every US transfer, a Transfer Impact Assessment (TIA) according to Schrems II has been conducted and documented. The TIA documentation is available to customers upon request.
The USA is not on the Swiss FDPIC adequacy list — therefore, SCCs and supplementary measures (TIA) are required.