Legal

Data Transfer Addendum

Last updated: 2026-08-18

1. Transfer Package and Scope

This Data Transfer Addendum ("Transfer Addendum") is between Tessora LLC, a Wyoming limited liability company at 30 N Gould St Ste N, Sheridan, WY 82801 US ("Tessora" or "Data Importer"), and the Business Customer identified in the completed Organization Transfer Record ("Customer" or "Data Exporter"). It supplements the Data Processing Agreement ("DPA") for the managed Notavia service.

This Transfer Addendum is a completed transfer package, not a statement that every movement of data is a restricted transfer. It contains:

  1. the unmodified standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs"), with Module Two and Module Three selected as applicable and every option and annex completed below;
  2. the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 ("UK Addendum"), with Tables 1 through 4 completed below; and
  3. supplementary contractual safeguards that add protection without varying the EU SCCs or UK Addendum.

The official EU SCC text forms Part Three of this Transfer Addendum. The selected module is determined by Section 3 for each transfer. The parties may retrieve the official text from the European Commission SCC page and the current UK mandatory clauses from the ICO international transfer resources. The detailed selections, parties, descriptions, safeguards, and subprocessors in this document complete those official texts; the parties do not rely on either link alone to form their agreement.

This Transfer Addendum applies only to Customer Personal Data under the DPA. Tessora's separate controller processing, opt-in worldwide website PostHog analytics, and organization-keyed server-side product analytics are not Customer transfers under this package. Tessora-selected subprocessors are addressed in Annex III. A connected provider selected by Customer is not made Tessora's subprocessor by this Transfer Addendum.

No billing country, organization USD or EUR preference, actual transaction currency, website currency preference, or German hosting location selects a legal regime. These are operational facts, not a legal-region selector. The Service remains worldwide B2B; this Transfer Addendum creates no country allow-list or EEA or UK exclusion.

2. Formation, Attachment, Evidence, and Hierarchy

2.1 Completed Organization Transfer Record

An Authorized User binds Customer at organization level only through an affirmative acceptance event that creates an immutable Organization Transfer Record containing all of the following:

  • Customer's legal or registered business name, any trading name used for the Service, full business address, stable organization identifier, contact-role name, and contact email;
  • whether Customer acts as controller, processor, or both for the transferred data and, if it acts as processor, confirmation that its controller authorized Tessora as subprocessor;
  • the transfers document slug and the version accepted, the DPA version, the Terms version, the selected EU SCC Module Two and/or Module Three, and UK Addendum applicability;
  • the official EU SCC decision and UK Addendum versions identified in Section 1;
  • the complete text presented or an immutable copy and cryptographic hash from which the accepted DPA, this Transfer Addendum, its annexes, and the official mandatory clauses can be reconstructed;
  • the Authorized User's stable identifier and account email, acceptance timestamp, attestation, surface, and affirmative action; and
  • IP address and user agent if retained for contract evidence.

The record supplies Customer's party fields wherever this document says "Customer as identified in the Organization Transfer Record." Those words are a deterministic reference to the accepted record, not a blank. This Transfer Addendum does not become effective if the record omits a required party field, role, selected module, version, or reconstructable instrument. A link view, continued use, preselected control, or acceptance in a personal capacity is insufficient.

Tessora accepts through publication of this identified version and the role-based act of its authorized Owner approving it. The Data Importer's signature and date in Annex I.A are the role-based approval and the effective timestamp in the Organization Transfer Record; no personal name is required or published.

A signed Order Details document may instead bind the parties only if it contains the same complete Organization Transfer Record and expressly attaches the complete identified instruments. Material revisions require new affirmative organization-level acceptance before they govern existing transfers, unless mandatory law requires an earlier change and permits another method. Customers must remain able to retrieve the exact effective package and their acceptance record for the relationship's duration and while protected residual data remains.

The application writes a single append-only Organization Transfer Record carrying every party field, role, module selection, UK applicability, competent-authority identification, instrument version, official mandatory-clause identifier, account email, attestation, surface, affirmative action, and timestamp listed above, and it stores the full token-resolved text of each accepted instrument alongside its hash rather than the hash alone, so the accepted package remains reconstructable after the document is revised. It treats any change to this document's version, the DPA version, or either frozen schedule version as material and calls for a new affirmative organization-level acceptance at the transfer surface, which is a requirement on that surface rather than a block on the rest of the Service.

This Transfer Addendum is nevertheless still not represented as electronically executed, and that has not changed. What stands in the way is not the implementation — the record, its storage and the reacceptance detection are running in the image the production service currently serves. It is simply that no organization has ever completed a record, so the resulting evidence does not exist.

2.2 Attachment and precedence

This Transfer Addendum is attached to and forms part of the DPA for covered restricted transfers. In a conflict concerning a covered transfer, the following order applies:

  1. the mandatory clauses of the UK Addendum for a UK Restricted Transfer;
  2. the applicable unmodified EU SCC module for an EEA Restricted Transfer;
  3. this Transfer Addendum's additional safeguards, provided they do not contradict the mandatory clauses;
  4. the DPA;
  5. mutually signed Order Details for the detail they expressly govern; and
  6. the Terms of Service.

Nothing in the DPA, Order Details, Terms, or a liability provision limits a data subject's rights or a party's obligations under the mandatory clauses.

3. Route and Module Selection

RouteExporter and importerRestricted-transfer treatmentInstrument
EEA Customer controller discloses or makes Customer Personal Data available to Tessora in the United States, including US administrative or support access to German-hosted dataCustomer controller exports; Tessora imports as processorCovered where Chapter V applies; Tessora imports as processor and its own importer processing is not treated as subject to GDPR Article 3EU SCC Module Two
EEA Customer processor discloses or makes Customer Personal Data available to Tessora in the United States for Customer's controllerCustomer processor exports; Tessora imports as subprocessorCovered on the same basis, with Tessora importing as subprocessorEU SCC Module Three
UK Customer controller discloses or makes Customer Personal Data available to Tessora in the United States, including remote accessCustomer controller exports; Tessora imports as processorUK Restricted Transfer unless an applicable UK adequacy regulation or other lawful exception covers the routeUK Addendum modifying EU SCC Module Two
UK Customer processor discloses or makes Customer Personal Data available to Tessora in the United States for Customer's controllerCustomer processor exports; Tessora imports as subprocessorUK Restricted Transfer on the same basisUK Addendum modifying EU SCC Module Three
Tessora sends Customer Personal Data onward to a Tessora-selected subprocessorTessora acts as processor or subprocessor; vendor acts as subprocessorThe DPA, Annex III, and an executed Tessora-vendor Article 28 and Chapter V mechanism must cover the onward routeNot executed by Customer's acceptance alone; an internal vendor-verification evidence gate applies
Customer directs transmission to its own connected email, SMS, collaboration, webhook, identity, or other providerCustomer remains the selecting controller or processor; provider is Customer's recipient, processor, or subprocessor according to Customer's contractCustomer must determine and execute its provider route; Tessora carries out the documented instructionNot a Tessora-selected subprocessor route and not bound by this package
Customer directs delivery to a worldwide RecipientCustomer determines the communication; Tessora processes and transmits under instructionDirect delivery to the individual Recipient is not treated here as a controller-to-processor import. Any provider in the path is assessed separatelyDPA plus the applicable provider route
Customer Personal Data remains hosted by the verified German Hetzner entity with no third-country disclosure or remote accessCustomer/Tessora roles remain as stated in the DPA; German host is a processor in the EEA chainStorage in Germany alone is not a third-country transferArticle 28 terms; no Chapter V tool solely for the German storage

Module Two and Module Three are the instruments the parties use for the routes in the table above, and this package treats them as applicable to them. The reasoning is stated rather than assumed, because the point is contested. The EU SCCs adopted by Decision 2021/914 are available where the importer's relevant processing does not itself fall within GDPR territorial scope. For the transfers this package covers, Tessora imports Customer Personal Data as processor or subprocessor: the Customer decides which Recipients to contact and why, and it is the Customer — not Tessora — that offers goods or services to those individuals. Tessora's own importer processing is therefore not considered to be caught by Article 3(2), and Decision 2021/914 is not being misapplied to it.

Two limits go with that position and neither is hidden. No qualified counsel has reviewed it, as with everything else in this set. And it is a determination about Tessora's processing as importer, not a general ruling: a Customer whose own analysis reaches a different conclusion for its particular processing should say so, and the parties will use a then-valid Article 46 safeguard designed for that circumstance or seek competent supervisory-authority approval before the transfer. If the Commission publishes the announced additional clauses for importers that are subject to GDPR, this package will adopt them. This scope question is not decided by Customer nationality, billing country, currency, or hosting location.

Article 49 derogations are exceptional and are not the recurring operational mechanism for the Service. Neither a data subject's general Service use nor Customer's acceptance of this package is treated as explicit Article 49 consent.

4. EU SCC Selections

The following selections apply without altering the official EU SCC text:

EU SCC itemCompleted selection
ModulesModule Two when Customer is controller; Module Three when Customer is processor. If both roles apply, each module governs the data for that role. Modules One and Four are not selected for Customer Personal Data under the DPA.
Clause 7 dockingIncluded. An additional Customer affiliate may dock only by completing its own Organization Transfer Record, obtaining all required party consents, and becoming a party to the applicable module.
Clause 9(a)Option 2, general written authorization. The specified notice period is 14 days before the new or replacement subprocessor is authorized to process Customer Personal Data.
Clause 11The optional independent dispute-resolution wording is not included.
Clause 13Applies as written. The authority is completed in Annex I.C rather than fixed by billing or currency.
Clause 17Option 1. The clauses are governed by the law of Ireland. Ireland permits third-party beneficiary rights.
Clause 18(b)The parties select the courts of Ireland, with proceedings brought before the competent courts in Dublin where territorial venue may validly be selected.
Annex I.ACompleted in Section 6.
Annex I.BCompleted in Section 7.
Annex I.CCompleted in Section 8.
Annex IICompleted in Section 9.
Annex IIICompleted in Section 10.

5. UK Addendum Tables

Table 1 — Parties and start date

FieldCompleted information
Start dateThe effective timestamp in the completed Organization Transfer Record
ExporterCustomer as identified by legal name, full address, organization identifier, contact role, and contact email in the Organization Transfer Record
Exporter key contactThe Customer contact role and email in that record; the contact may receive notices and exercise termination rights
Exporter signatureCustomer's affirmative organization-level electronic acceptance recorded under Section 2.1
ImporterTessora LLC, 30 N Gould St Ste N, Sheridan, WY 82801 US
Importer key contactPrivacy Operations Owner, support@saas-infrastructure.com
Importer signatureRole-based Owner approval of the version identified in the Organization Transfer Record, plus the effective timestamp recorded there

Table 2 — Selected SCCs, modules, and clauses

The Approved EU SCCs are the Annex to Commission Implementing Decision (EU) 2021/914 dated 4 June 2021. Module Two applies to Customer-controller transfers and Module Three applies to Customer-processor transfers. Clause 7 applies; Clause 9 Option 2 applies with 14 days' notice; Clause 11's optional wording does not apply. The Clause 17 and 18 selections are replaced for UK Restricted Transfers by the UK mandatory clauses.

Table 3 — Appendix information

The parties information is Section 6; the transfer description is Section 7; the competent authority rule is Section 8 as adapted by the UK mandatory clauses; the technical and organisational measures are Section 9; and the subprocessor information is Section 10. These sections are the completed Appendix Information for the UK Addendum.

Table 4 — Ending the Addendum when the approved form changes

Neither party may end the UK Addendum solely under Section 19 of the UK mandatory clauses when the ICO issues a revised approved addendum. The parties must instead update the package as required to preserve a valid UK safeguard, subject to any mandatory right that cannot be excluded.

Part 2 consists of the mandatory clauses of the Approved Addendum, being template Addendum B.1.0 issued by the ICO and laid before Parliament under section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those mandatory clauses. The parties agree to be bound by those mandatory clauses, completed by Tables 1 through 4 above. For UK Restricted Transfers, references to the EU SCCs are read with the mandatory amendments, including UK law, ICO supervision, and England and Wales courts as specified there.

6. Annex I.A — List of Parties

Data exporter

  • Name and address: Customer as identified by legal name and full business address in the completed Organization Transfer Record.
  • Contact: Customer contact role and email identified in that record.
  • Activities relevant to the transfer: Customer configures and uses the Service to send and manage communications, Recipient preferences and suppressions, delivery and Recipient events, Customer-selected tracking, workflows, exports, deletions, and connected-provider routing.
  • Role: Controller for Module Two; processor for Module Three. If Customer uses both roles, the record identifies both and each module applies to its corresponding data.
  • Signature and date: The affirmative electronic acceptance and timestamp in the Organization Transfer Record.

Data importer

  • Name: Tessora LLC
  • Address: 30 N Gould St Ste N, Sheridan, WY 82801 US
  • Contact: Privacy Operations Owner, support@saas-infrastructure.com
  • Activities relevant to the transfer: Providing, securing, supporting, and maintaining the managed Notavia notification service under Customer's documented instructions, including the operations in Annex I.B.
  • Role: Processor for Module Two; subprocessor for Module Three.
  • Signature and date: Role-based Owner approval of this identified version and the effective timestamp in the Organization Transfer Record.

No DPO has been appointed. No EU or UK representative has been appointed. These statements identify unresolved governance risks and do not assert an exception or compliance.

7. Annex I.B — Description of Transfer

Required fieldCompleted description
Data subjectsRecipients and contacts selected by Customer; Customer personnel or other individuals in content, templates, attributes, workflows, support material, or connected-provider configuration; and Authorized Users only where their data appears in processor-side instructions or Customer content
Personal dataRecipient email, phone, external identifier, display name, locale, timezone, and Customer attributes; message, template, workflow, variable, attachment, sender and reply-to content; preferences, suppressions, verification and inbox state; delivery, bounce, complaint, delay, open, click, provider and Recipient events; timestamps, machine classification, user agent, click destination, counters and provider identifiers; encrypted provider credentials and integration configuration; rights, export, deletion, tenant, audit, diagnostic and incident records tied to Customer processing
Sensitive dataNo sensitive or Article 9 data is intended. Customer may submit it only under a lawful, necessary, expressly documented instruction with an Article 9 or equivalent condition and risk-appropriate safeguards. No general authorization arises from this package. The Service is not a dedicated sensitive-data service.
FrequencyContinuous or event-driven while enabled features are used; administrative processing when Customer, a Recipient, a provider, support, security, rights, export, deletion, or incident event initiates it
NatureReceive, record, organize, structure, store, retrieve, consult, render, adapt, combine within the tenant, transmit, route, deliver, observe, classify machine activity, restrict, suppress, export, correct, erase, back up, restore, secure, and support
PurposesProvide Customer-directed notification orchestration; honor preferences and suppressions; provide Recipient inbox features; route through selected channels and providers; measure delivery and, when instructed, opens and clicks; investigate delivery, abuse, and incidents; fulfill rights, export and deletion instructions; and maintain Service security and availability
RetentionFor the DPA term and then until return or deletion under DPA Section 11. Current notification defaults are 1 day for Free, 1 day for Starter, 7 days for Growth, 30 days for Pro, 30 days for Scale, and no finite default for an OEM or custom plan; an organization override replaces the plan value, and the extended-retention add-on raises a finite effective value to at least 90 days. Trial status carries no separate value; the organization's current plan supplies it. Current audit defaults are 365 days for security, configuration and billing, 180 days for lifecycle, and 90 days for data access. Backup operation and ageing are described in DPA Section 11.3; restoration into production and deletion replay remain open.
Processor transfersFor Module Three, Customer's controller is the controller described in Customer's Organization Transfer Record and documented instruction. Subject matter, nature, duration and purpose are the same as above and must remain within that controller's authorization.

Primary application and database hosting is intended in Germany. US administrative or support access by Tessora is nevertheless treated as access in the United States for transfer analysis. Worldwide Recipient delivery and Customer-selected providers do not change Customer's module by currency or geography; each disclosure route is assessed on its actual parties and destination.

8. Annex I.C — Competent Supervisory Authority

For an exporter established in an EEA Member State, the competent supervisory authority is the authority responsible for that exporter under GDPR Article 55. For an exporter not established in the EEA but subject to GDPR under Article 3(2) and required to appoint an Article 27 representative, it is the authority for the Member State where that representative is established. If the exporter is not required to appoint a representative, it is the authority of an EEA Member State where relevant data subjects are located. The completed Organization Transfer Record must identify the resulting authority by official name and Member State before an EEA transfer begins. This rule completes Annex I.C without using billing country or currency as a proxy.

For a UK Restricted Transfer, the competent regulator is the Information Commissioner's Office under the UK mandatory clauses.

9. Annex II — Technical and Organisational Measures

The binding baseline is DPA Schedule 2, version 2026-08-15.1, supplemented by these transfer-specific measures:

  • public managed-Service traffic uses TLS terminated at the production edge, with certificate issuance verified from an independent machine over public DNS; outbound managed mail uses opportunistic STARTTLS with configured and verified sender authentication, so encryption on every hop to a Recipient is not represented; Customer-selected connected-provider routes use their configured secure transports, and verification of those routes remains required;
  • connected-provider credentials are encrypted at application field level, secrets are supplied through deployment configuration, and role and tenant checks restrict ordinary access;
  • US administrative and support access is limited to authorized operational need under confidentiality, uses the secured administrative path, and must be removed when no longer required;
  • Customer controls Recipients, content, templates, attributes, preferences, suppressions, tracking settings, connected-provider selection, exports after download, and Authorized User access;
  • Tessora minimizes disclosures, uses organization and request identifiers where possible, separates Customer Personal Data from opt-in website analytics and organization-keyed server analytics, and does not intentionally send Recipient content or identifiers to those analytics routes;
  • queued delivery, retry, idempotency, suppression, health, export, deletion, audit, retention and backup tooling support availability and lifecycle controls within the limitations disclosed in the DPA;
  • Tessora reviews government demands for validity, seeks clarification and narrowing, challenges demands where reasonable legal grounds exist, redirects the requester to Customer where appropriate, discloses only what binding law requires, documents the response, and notifies Customer before or after the demand when legally permitted;
  • Tessora will notify Customer if it can no longer comply with the mandatory clauses and will suspend the affected transfer or processing when required by them; and
  • the parties will reassess the transfer after a law, practice, provider, destination, access model, encryption or key-control, purpose, data-category, security, incident, or official-guidance change.

The measures have material limits. Tessora does not claim blanket application-layer encryption of database fields, volumes, logs, or backups. Hetzner states that encryption at rest for customer-managed cloud servers and backups is the customer's responsibility. Tessora necessarily can access plaintext Recipient content to provide instructed processing, and Tessora or a selected provider controls keys needed for that processing. Customer does not exclusively control all keys, and encryption does not make compelled US access technically impossible. Direct administrative reads are not comprehensively represented as product audit events. Production transport, backup scheduling, off-site backup immutability, restore rehearsal into a scratch database, and log and alert destinations are now evidenced on the deployment and recorded in DPA Schedule 2 version 2026-08-15.1. The off-site storage jurisdiction is not among them: the bucket was created with a European location hint, that hint is best-effort and is not a residency guarantee, no storage jurisdiction is contractually verified, and the credentials the production host holds cannot read the bucket's own settings. Encryption at rest and production key control, privileged-access review, restore into production, deletion replay after restoration, vulnerability coverage beyond the dependency gate, and the off-site storage jurisdiction remain open. No Tessora certification, independent audit, or independent penetration test is claimed.

10. Annex III — Subprocessors

This annex uses the frozen Subprocessor List version 2026-08-18.1 that DPA Schedule 3 incorporates. Tessora's internal vendor-verification programme must verify every legal entity, executed agreement, product, account, location, subprocessor chain, security material and transfer mechanism before launch.

ProviderSpecific processing and Customer Personal Data scopeIntended location and roleOnward-transfer status
Amazon Web Services, Inc. — Amazon SESManaged email delivery: Recipient email, message content and attachments, sender and delivery metadata, provider events and identifiersProcessing region is eu-central-1 (Frankfurt), confirmed by the granted per-region production access and the feedback MX records, so message content and Recipient addresses are not stored outside the European Union on this route. The contracting entity is a United States company, so the route is still assessed as a restricted transfer on entity and government-access grounds rather than on storage location. Tessora-selected subprocessor when managed sending is enabled.AWS publishes a DPA with Modules Two and Three, UK terms, supplementary measures and government-request commitments. Tessora's exact account acceptance, entity, executed terms and route remain unverified.
Hetzner Online GmbHPrimary application, database, logs and Customer Personal Data hosted on Customer-managed infrastructureIntended Germany, EEA; Tessora-selected infrastructure subprocessorGerman storage alone needs no Chapter V tool. The exact product location, executed Article 28 DPA, support route, subcontractors, encryption configuration and production evidence are unverified.
Cloudflare, Inc.R2 backup objects only if configured; authoritative DNS is a separate operational route unless it receives Customer Personal Data. No anti-bot challenge service and no Cloudflare asset CDN is in use on any surfaceGlobal/United States vendor with product-dependent processingCloudflare publishes a DPA, SCCs, UK terms, subprocessor list and access-request commitments. R2 use, location, key control, retention, exact entity, accepted terms and whether Customer Personal Data traverses other Cloudflare products remain open gates.
PostHog, Inc.No Customer Personal Data is intended. Opt-in website analytics and the separate organization-keyed five-event server analytics route are Tessora controller processingIntended EU project with possible US entity/support/onward accessNot authorized by this annex to receive Recipient content or identifiers. Exact project region, DPA, entity, subprocessor chain and transfer terms remain open gates.
Paddle entities identified in the applicable Paddle agreementBilling-country, transaction and buyer data in Paddle's Merchant of Record role; no Customer Personal Data is intendedUK, EEA, United States and vendor-dependent locations; role requires vendor verification and may be independent controllerNot authorized by this annex to receive Recipient content. Paddle's exact contracting entity, data-sharing terms, onward routes and current role remain open gates.
Volentio JSD Limited (jsDelivr)No longer used. Until 15 August 2026, public site asset delivery received IP address, user agent and request metadata from two signed-in console pages; those assets are served from our own origin nowNot applicable while unused; the network was global and its routing was never under our controlNo Customer Personal Data was ever intended or sent. There was never a subscription or an executed agreement, which is why the dependency was removed. Reintroducing it would require an agreement, a location and subprocessor-chain review, and a change to the Subprocessor List first

Only a provider actually processing Customer Personal Data under Tessora's instructions is an Annex III subprocessor for that processing. Listing a controller or operational vendor for transparency does not change its legal role. Public vendor terms are evidence inputs, not proof that Tessora executed them. Tessora may not begin a new restricted onward transfer merely because a vendor publishes SCCs or claims a region.

Customer-selected SMTP, email API, SMS, Slack, Teams, Discord, webhook, identity or other providers are excluded from Annex III. Customer must identify its provider and contracting entity, determine its role and destination, complete any controller-to-processor or processor-to-subprocessor terms and transfer safeguard, assess government access and supplementary measures, and maintain change and deletion controls. Tessora will not represent Customer's provider contract as its own.

11. Supplementary Contractual Commitments

For covered transfers, Tessora will:

  • publish and preserve the accepted transfer version and provide a copy of the mandatory clauses and completed annexes on request, subject only to necessary redaction of another party's confidential information;
  • maintain the role split, purpose limitation, data minimization, Customer controls, security baseline, incident assistance, return/deletion, subprocessor notice and audit rights in the DPA;
  • not voluntarily provide bulk or indiscriminate access to Customer Personal Data to a public authority;
  • assess each demand, document the legal basis and scope, seek to redirect it to Customer, challenge it where reasonable grounds exist, minimize any compelled disclosure, and seek permission for notice where notice is prohibited;
  • publish or provide aggregate transparency information about demands when legally permitted and operationally available;
  • provide available information reasonably needed for Customer's transfer assessment and notify Customer of a material inability to comply; and
  • stop the affected transfer and, at Customer's choice, return or delete the affected data where the mandatory clauses require suspension or termination and no lawful alternative applies.

These commitments do not promise that Tessora will prevail against a lawful demand, that no government can access data, or that contractual and organizational measures alone cure every destination-law issue. The route-by-route internal assessment records residual risks, conditions and re-review triggers.

12. Review, Ownership, and Unresolved Conditions

The role-based Owner approved this transfer-package architecture and accepted unavailable qualified counsel as an unresolved launch risk. That acceptance is not legal review and does not satisfy an obligation to use a valid transfer safeguard. No DPO, EU representative, or UK representative has been appointed. No universal legal sufficiency, adequacy of the United States, vendor certification inherited by Tessora, executed vendor DPA, effective vendor SCC, exclusive Customer key control, or production deployment fact is claimed.

Five things remain open, and this Transfer Addendum states them as open rather than deferring the reader to work it cannot see: every vendor agreement and route is still to be verified and collected; the analytics and tracking behaviour described in the Privacy Notice and Cookie Policy carries the activation gates named there; deletion, retention, backup and restoration limits are stated in DPA Section 11 and are not all proved; production security and administrative-access controls carry the limits stated in Annex II and in DPA Schedule 2; and no qualified counsel has reviewed the Article 3 importer-scope issue, the Clause 17 and 18 selections, the UK package, the destination-law analysis, or the electronic-execution design. None of those is a promise of future work with a date attached. They are the conditions this package does not satisfy today, published so that a reader weighing it can see them.

VERSION MOVE 2026-08-15.7 -> 2026-08-16.1, CITATION-ONLY. Annex III's frozen Subprocessor List citation moved 2026-08-15.7 -> 2026-08-16.1 because the list moved to record that the UptimeRobot availability monitor is now live. NO TRANSFER FACT, ROUTE, MODULE, ANNEX SELECTION, MEASURE OR SAFEGUARD CHANGED. UptimeRobot is not a transfer route under this addendum in either version -- it is an account and site-data processor, and the monitor sends it no personal data at all: an unauthenticated status request carries no account context and no message data. Annex II's baseline is DPA Schedule 2, which did not move and is still 2026-08-15.1.

VERSION MOVE 2026-08-16.1 -> 2026-08-16.2, CITATION-ONLY. Annex III's frozen Subprocessor List citation moved because the list moved to record two further UptimeRobot monitors. NO TRANSFER FACT, ROUTE, MODULE, ANNEX SELECTION, MEASURE OR SAFEGUARD CHANGED, and the monitors still send the vendor no personal data: an unauthenticated status request carries no account context and no message data. Annex II's baseline is DPA Schedule 2, which did not move and is still 2026-08-15.1.

VERSION MOVE 2026-08-16.2 -> 2026-08-18.1, CITATION-ONLY. Annex III's frozen Subprocessor List citation moved because the list moved to record PostHog activation on both analytics routes on 2026-08-18. NO TRANSFER FACT, ROUTE, MODULE, ANNEX SELECTION, MEASURE OR SAFEGUARD CHANGED: PostHog is not a transfer route under this addendum in either version — both routes are Tessora controller activities carrying no Customer Personal Data, exactly as Annex III's PostHog row already states. Annex II's baseline is DPA Schedule 2, which did not move and is still 2026-08-15.1.