Policy centre
International transfer schedule
Last updated: 29 August 2026
The locations, transfer roles and UK safeguards that must support restricted transfers of Customer Personal Data.
Incomplete launch schedule — no claim of completed transfer compliance is made
Required entry for each provider
- Provider and contracted legal entity.
- Service purpose and personal-data categories.
- Primary hosting, backup, support and remote-access countries.
- Whether the customer or Brakan initiates the restricted transfer.
- Applicable UK adequacy regulation or appropriate safeguard.
- UK IDTA or UK Addendum version and execution details where required.
- Transfer-risk assessment or data-protection test owner, date and outcome.
- Supplementary technical, contractual and organisational safeguards.
- Onward-transfer restrictions, review date and change-notice mechanism.
Current position
Railway, Supabase, Resend, Cloudflare and any future Open Banking or tax provider must be verified against this schedule before commercial launch. Provider marketing pages or a UK/EU region selector alone are not sufficient evidence of every processing, support or onward-transfer location.
Changes
Brakan shall update this schedule and the Subprocessor List before an intended transfer change takes effect, provide the contractual notice required for a subprocessor change, and complete any required transfer assessment and documentation. It shall not materially reduce agreed safeguards without a lawful basis and appropriate notice.