Last Updated: 29-Oct-2025
1. Purpose
This Policy explains how Nihoner transfers, stores, and protects personal data across borders. It ensures compliance with applicable privacy laws, including the EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA (California), PIPEDA (Canada), APPI (Japan), and other global data protection frameworks.
2. Scope
This Policy applies to all users, customers, employees, contractors, and third parties whose personal data may be transferred internationally by Nihoner.
3. Legal Bases for Transfers Outside the EEA/UK
Where personal data is transferred outside the European Economic Area (EEA), Switzerland, or the United Kingdom, Nihoner ensures lawful transfer under one or more of the following mechanisms:
- Adequacy Decisions: Transfer to countries formally recognized by the European Commission/UK ICO as providing adequate protection.
- Standard Contractual Clauses (SCCs): Execution of EU Commission–approved SCCs or UK International Data Transfer Addendum, supplemented with technical and organizational safeguards.
- Binding Corporate Rules (BCRs): Where adopted by certain vendors.
- Explicit Consent: Where no other transfer mechanism applies and the data subject has provided informed consent.
4. Hosting & Third-Party Providers
Our infrastructure and services may be located in the EU, UK, U.S., and other regions. Providers may include, but are not limited to:
- Hosting & Infrastructure: Namehero LLC, Cloudflare, AWS, or equivalent EU-compliant hosts.
- Email & Communication Services: Transactional email processors and customer support platforms.
- Payment & Billing Processors: Secure, PCI-DSS-compliant gateways.
A full Third-Party Subprocessor List is maintained and updated regularly on our website.
5. Safeguards
To protect data during international transfer, Nihoner employs:
- Encryption in Transit and at Rest using industry-standard protocols.
- Access Controls & Role-Based Permissions ensuring only authorized staff may access data.
- Ongoing Monitoring & Logging of transfer activities.
- Annual Review & Risk Assessments of transfer mechanisms.
- Data Minimization ensuring only the strictly necessary data is transferred.
6. Transparency & Accountability
- Records of Processing: All cross-border transfers are documented in our Records of Processing Activities (RoPA).
- Vendor Contracts: All processors must sign Data Processing Agreements (DPAs) and adhere to our security standards.
- Government Requests: Nihoner challenges unlawful or disproportionate access requests and, where legally permitted, informs affected users.
7. Your Rights
Depending on your jurisdiction, you may have rights to:
- Request details of transfer mechanisms (e.g., SCCs, adequacy decision).
- Obtain a copy of applicable safeguards (subject to redactions for confidentiality).
- Object to transfers in certain circumstances.
- Withdraw consent where it forms the basis for transfer.
To exercise these rights, please contact us at [email protected].
8. Updates to This Policy
We may update this Policy to reflect changes in law, guidance, or our practices. The “Last Updated” date will always indicate the most recent revision.