One moment.
One moment.
Last updated: May 25, 2026
The Standard Contractual Clauses published by the European Commission in June 2021 are the primary legal mechanism for transferring personal data from the European Economic Area (EEA) to countries that do not have an EU adequacy decision.
HelmXP incorporates the 2021 SCCs verbatim into its data processing documentation for EU Hubs where data may be processed by a sub-processor outside the EEA.
HelmXP's primary infrastructure for EU Hubs is in Azure West Europe (Netherlands). Some HelmXP sub-processors — including Stripe (billing) and Sentry (error monitoring, configured with PII scrubbing) — operate in part outside the EEA.
The SCCs ensure those transfers are covered by a recognised legal basis under GDPR Article 46.
HelmXP uses Module Two of the 2021 SCCs (Controller-to-Processor), covering the relationship between your organisation as controller and HelmXP as processor.
The parties and governing law fields are completed with your Hub's registered entity name (as provided at signup) and the law of your EU member state.
If you accepted the DPA at signup and selected EU data residency, the SCCs are incorporated by reference. Your acceptance is logged in your Hub's legal record under Manage > Legal with template version, timestamp, and IP address.
Where HelmXP's sub-processors process EEA data, HelmXP ensures that the same or equivalent SCCs apply to those transfers. The current sub-processor list and transfer mechanisms are published on the Trust Center.