This document is Neeto's Transfer Impact Assessment summary. It is written for Customers in the European Economic Area (EEA), the United Kingdom, and Switzerland who transfer personal data to Neeto and who are required to assess that transfer under applicable Data Protection Legislation. Capitalized terms used below that are not otherwise defined have the meanings given to them in the Agreement and the Data Processing Agreement ("DPA").
1. Purpose of this document #
Following the judgment of the Court of Justice of the European Union in Case C-311/18 ("Schrems II"), data exporters relying on the Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum must assess whether the laws and practices of the destination country could prevent the data importer from complying with those clauses, and identify supplementary measures where needed. The EEA version of this exercise is commonly called a Transfer Impact Assessment (TIA); the UK Information Commissioner's Office (ICO) calls it a Transfer Risk Assessment (TRA).
That assessment is the exporter's obligation — Yours as the data controller — but it depends on information only the importer can provide. This document provides that information for transfers to Neeto, so that You can complete Your own TIA or TRA without a bespoke questionnaire exchange. It also constitutes the TIA summary that Section 5 of Our DPA commits Neeto to making available.
2. Summary of transfers #
Parties and roles. You are the data controller and exporter. Neeto LLC, a company based in the United States, is the data processor and importer. Neeto processes Customer Personal Data only on Your documented instructions, as described in the DPA.
Categories of data and data subjects. The categories of Personal Data and data subjects are described in Section 1 of the DPA. In summary: identification and contact data of Your users, and any personal data contained in the content You or Your end users submit to the Services.
Hosting location. The Services are hosted on Amazon Web Services (AWS) in
the us-east-1 region in the United States, as described in Our
Security Policy.
Onward transfers. Neeto engages the subprocessors listed on Our Subprocessors page, which states each subprocessor's role, the data involved, its location, and when it is used. Onward transfers are governed by written agreements as described in Section 3 of the DPA.
Transfer mechanism. Transfers from You to Neeto are made under the EU SCCs (Module Two), the UK International Data Transfer Addendum, and the Swiss adaptation of the SCCs, each incorporated into the DPA as described in its Section 5. Neeto is not certified under the EU-US Data Privacy Framework; the transfer mechanism for Your data is the SCCs together with the applicable UK and Swiss instruments, which do not depend on the continued validity of any adequacy decision.
3. United States laws relevant to this assessment #
The laws most commonly examined in TIAs for transfers to the United States are:
FISA Section 702 (50 U.S.C. § 1881a) permits US intelligence agencies to compel certain "electronic communication service providers" to disclose communications of non-US persons located outside the United States. Directives under Section 702 have in practice been directed at providers of communications infrastructure and large-scale consumer communications services. Neeto provides business productivity software to organizations; We consider it unlikely that Neeto's Services would be of interest for foreign intelligence collection of this kind.
Executive Order 12333 governs US intelligence activities conducted outside the United States, including collection of data in transit. It does not compel companies to disclose data; the appropriate response is encryption, and all data in transit to and between Neeto systems is encrypted using HTTPS/TLS as described in Our Security Policy.
The CLOUD Act (18 U.S.C. § 2713) clarifies that US law enforcement may use existing legal process (such as warrants) to reach data held by US providers regardless of storage location. It applies to ordinary criminal legal process, is subject to judicial oversight, and is comparable to mutual legal assistance mechanisms that exist in most jurisdictions.
Neeto's practical experience. As of the last review date of this document, Neeto has never received a directive under FISA Section 702, a national security letter, or any other request from a US government authority seeking access to Customer Personal Data.
4. Safeguards under Executive Order 14086 #
In 2022 the United States adopted Executive Order 14086, which limits US signals-intelligence collection to what is necessary and proportionate to defined objectives and establishes a two-level redress mechanism, including the Data Protection Review Court (DPRC), available to individuals in the EEA, the United Kingdom, and Switzerland.
These safeguards form the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework, the United Kingdom's UK-US Data Bridge, and Switzerland's recognition of the Swiss-US Data Privacy Framework. As the European Data Protection Board confirmed in its information note of 18 July 2023, the safeguards of Executive Order 14086 apply to all data transferred to the United States regardless of the transfer mechanism used, and may be taken into account in a TIA for transfers based on the SCCs. The same reasoning applies to a UK TRA: the UK government's own assessment underlying the Data Bridge concluded that these US safeguards provide adequate protection for UK personal data.
In other words, although Neeto relies on the SCCs rather than the Data Privacy Framework, Your data benefits from the same US national-security safeguards and redress mechanisms that the EU, UK, and Swiss authorities have each independently assessed and accepted.
5. Supplementary measures #
In addition to the contractual commitments in the DPA, Neeto maintains the following measures, described more fully in Our Security Policy:
Technical measures. All data in transit is encrypted using HTTPS/TLS. Customer Data is encrypted at rest in AWS using AES-256 block-level storage encryption, and database backups are stored in encrypted Amazon S3 buckets using AES-256 server-side encryption.
Organizational measures. Production access is limited to authorized personnel with a business need, follows the principle of least privilege, is logged and monitored, and is removed when no longer needed. Neeto performs background checks for personnel who are granted access to production systems. All personnel with access to Personal Data are bound by confidentiality obligations as described in Section 2.4 of the DPA.
Contractual measures. The SCCs, the UK Addendum, and the Swiss adaptation are incorporated into the DPA. Neeto flows down equivalent data protection obligations to subprocessors, notifies Customers of subprocessor changes with an opportunity to object, supports audits as described in Section 2.7 of the DPA, and notifies Customers of Security Breaches as described in Section 2.8 of the DPA.
6. Government requests for Customer Personal Data #
If Neeto receives a request from any government authority for Customer Personal Data, Neeto will:
- redirect the requesting authority to seek the data directly from the Customer, wherever possible;
- notify the affected Customer promptly, unless legally prohibited from doing so, and where prohibited, use reasonable efforts to obtain a waiver of the prohibition;
- review the request for legal validity and challenge it if there are reasonable grounds to consider it unlawful or overbroad, including seeking interim relief where appropriate;
- disclose only the minimum data required to comply with a valid and binding request; and
- never disclose Customer Personal Data to any authority voluntarily, in bulk, or through any form of backdoor or direct access to Neeto's systems.
7. Notes for EEA Customers #
This document follows the six-step approach in the European Data Protection Board's Recommendations 01/2020: the transfer is described in Section 2, the transfer tool is the SCCs incorporated into the DPA, the assessment of US law and practice is in Sections 3 and 4, and the supplementary measures are in Sections 5 and 6. Neeto will re-evaluate this assessment as described in Section 10.
8. Notes for UK Customers #
For a TRA using the ICO's TRA tool, this document provides the information relevant to the destination-country questions: the categories of data and their sensitivity are described in Section 2 and in Section 1 of the DPA, the relevant US laws and Neeto's practical exposure to them are described in Section 3, and the safeguards and redress mechanisms available to UK data subjects — including under the UK-US Data Bridge assessment — are described in Section 4. Transfers are made under the UK International Data Transfer Addendum as incorporated into Section 5 of the DPA.
9. Notes for Swiss Customers #
For transfers subject to the Swiss Federal Act on Data Protection (FADP), the SCCs apply as adapted for Switzerland as described in Section 5 of the DPA, with the Federal Data Protection and Information Commissioner (FDPIC) as the competent supervisory authority. The safeguards described in Section 4, including the redress mechanism, extend to individuals in Switzerland.
10. Conclusion and review #
Taking into account the nature of the data processed, Neeto's practical experience with government requests, the safeguards of Executive Order 14086 as recognized by the EU, UK, and Swiss authorities, and the technical, organizational, and contractual measures described above, Neeto's assessment is that the laws and practices of the United States do not prevent Neeto from complying with its obligations under the SCCs, the UK Addendum, or the Swiss adaptation, and that the residual risk to data subjects is low.
Neeto reviews this document at least annually and upon any material change in relevant law or in Neeto's processing operations, and will update it as needed. This document was last reviewed in July 2026.
If You have questions about this document or need additional information to complete Your assessment, contact Us at [email protected].