This Transfer Impact Assessment (TIA) summary evaluates cross-border data flows from the European Economic Area (EEA), United Kingdom (UK), and Switzerland to MarketMind AI, Inc. in the United States, in accordance with GDPR Article 46 and EDPB Recommendations 01/2020.
Last updated: August 2026
EU/UK Enterprise Customers (Data Controllers or Processors).
MarketMind AI, Inc. (United States — Data Processor).
Customer Prompts, Contextual Vector Data, Generated Outputs, User Auth Metadata (WorkOS SSO), and System Logs.
Google Cloud Platform (GCP) US Multi-Region (Cloud Run compute, Cloud SQL pgvector storage, Pub/Sub messaging, Vertex AI inference engine).
EU-U.S. Data Privacy Framework (DPF), UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF.
EU Standard Contractual Clauses (SCCs — Module 2: Controller-to-Processor; Module 3: Processor-to-Processor) integrated into the MarketMind AI Data Processing Addendum (DPA), alongside the UK International Data Transfer Addendum (IDTA).
Foreign Intelligence Surveillance Act (FISA) Section 702, Executive Order 12333, and Executive Order 14086.
EO 14086 restricts U.S. signals intelligence activities to necessity and proportionality parameters and establishes the Data Protection Review Court (DPRC). This framework provides binding, enforceable remedies for European data subjects, satisfying "essentially equivalent" protection standards.
The implementation of DPF certification, fallback SCCs, strict logical data segregation, zero model training, and strong encryption measures ensures that personal data transferred to MarketMind AI receives a level of protection essentially equivalent to that guaranteed within the EU/EEA.
This TIA summary is provided for informational purposes and does not constitute legal advice. Final transfer impact assessments should be reviewed and validated by qualified legal counsel in the relevant jurisdiction. This document does not constitute a binding certification.
Questions about data transfers? Contact us at legal@marketmindai.cloud