The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
Turn data risk into confidence with Exterro's AI-driven platform for eDiscovery, digital forensics, data privacy, security &
For each regulation, how many of the requirements it places on your vendors Exterro’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
11 documents listed on Exterro’s trust centre
trustcenter.exterro.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where is customer data stored and processed?
“SendSafely hosts its infrastructure with multi-tenant, outsourced data center providers. They use Amazon Web Services (AWS) for their infrastructure. The physical and environmental security controls of these providers are audited for SOC 2 Type II and ISO 27001 compliance.”
as of 21 Sep 2026Source
International data transfers
How does SendSafely comply with GDPR for EU/UK data transfers?
“SendSafely implements appropriate safeguards for international data transfers: - For UK transfers: They use the UK International Data Transfer Addendum to the EU Standard Contractual Clauses - For EEA/Switzerland transfers: They implement the EU Standard Contractual Clauses - Module Two (Controller-to-Processor) applies when the customer is a controller - Module Three (Processor-to-Processor) applies when the cust...”
Regions named: EU, UK, Switzerlandas of 21 Sep 2026Source
Encryption
What encryption methods does SendSafely use?
“SendSafely uses the OpenPGP message format with 256-bit AES encryption. Their encryption process involves: - A 256-bit random secret value generated by their servers (Server Secret) - A 256-bit random secret value generated by your machine (Client Secret) - These values are combined to create the encryption key using OpenPGP's Iterated and Salted String-to-key specifier - All communications between SendSafely serv...”
as of 21 Sep 2026Source
Data retention and deletion
What is SendSafely's data retention policy?
“Personal data provided to SendSafely is retained only as long as necessary to provide the services. SendSafely performs backup copies for possible restoration requirements. Any data that is erased at the end of its retention period is erased using techniques that make it impossible to reconstruct, including backup copies after their retention period.”
as of 21 Sep 2026Source
Notice of subprocessor changes
How will customers be notified of future subprocessor changes?
“Exterro will notify customers of any future subprocessor changes through: - Direct email notifications to designated contacts - Updates to our subprocessor list in our Trust Center https://trustcenter.exterro.com”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.