International Data Transfers
Data transfers outside the EEA and the applicable safeguards
Personal data is processed, as a rule, within the European Economic Area (EEA). Certain third-party providers may involve transfers outside the EEA, subject to appropriate safeguards.
Identified transfers
| Context | Destination | Data involved | Safeguard |
|---|---|---|---|
| Monitoring & observability (New Relic, Sentry) | Possibly outside the EEA, depending on the plan | Generally no personal data — error/performance traces and the identifier of the account that generated the event | Standard contractual clauses / provider guarantees |
Monitoring services are not used to collect user content or personal data; they receive technical diagnostic information (error type, stack trace, environment, timestamp) and the account identifier associated with the event. Consultia will replace these services with EU-based alternatives once they become available.
No web analytics on the platform. The SaaS platform (appssm.ro) does not include any web analytics tool. The presentation website (ssm.ro) uses Plausible — cookieless analytics, hosted in the EU, with no personal data — therefore no transfer outside the EEA. We do not use Google Analytics or other analytics/marketing cookies.
Transfer safeguards
For any transfer outside the EEA, one of the safeguards provided by the GDPR applies: adequacy decisions, standard contractual clauses (SCC), or other appropriate mechanisms, as well as additional technical measures (encryption in transit).
Differs by model
Shared Model (SaaS): documents are stored in AWS S3 (configured region), and the database on Heroku. Enterprise Model (Dedicated): data residency can be established contractually through the choice of dedicated AWS regions. See Deployment Models.
Signing data
For electronic signatures, in the standard case only the document hash is transmitted to the qualified provider — the content does not leave the platform. If the provider used requires transmission of the entire document (not just the hash), the document content is transmitted to that provider. Communication takes place via HTTPS (mTLS or API token).