---
title: "Neeto Transfer Impact Assessment (TIA)"
description: "Read Neeto Transfer Impact Assessment (TIA)."
canonical_url: "https://www.neeto.com/legal/transfer-impact-assessment"
markdown_url: "https://www.neeto.com/legal/transfer-impact-assessment.md"
---

# Neeto Transfer Impact Assessment (TIA)

Read Neeto Transfer Impact Assessment (TIA).

This document is Neeto's Transfer Impact Assessment summary. It is written for
Customers in the European Economic Area (EEA), the United Kingdom, and
Switzerland who transfer personal data to Neeto and who are required to assess
that transfer under applicable Data Protection Legislation. Capitalized terms
used below that are not otherwise defined have the meanings given to them in
the [Agreement](/legal/terms-of-service) and the
[Data Processing Agreement](/legal/data-processing-agreement) ("DPA").

## 1. Purpose of this document

Following the judgment of the Court of Justice of the European Union in Case
C-311/18 ("Schrems II"), data exporters relying on the Standard Contractual
Clauses (SCCs) or the UK International Data Transfer Addendum must assess
whether the laws and practices of the destination country could prevent the
data importer from complying with those clauses, and identify supplementary
measures where needed. The EEA version of this exercise is commonly called a
Transfer Impact Assessment (TIA); the UK Information Commissioner's Office
(ICO) calls it a Transfer Risk Assessment (TRA).

That assessment is the exporter's obligation — Yours as the data controller —
but it depends on information only the importer can provide. This document
provides that information for transfers to Neeto, so that You can complete Your
own TIA or TRA without a bespoke questionnaire exchange. It also constitutes
the TIA summary that Section 5 of Our DPA commits Neeto to making available.

## 2. Summary of transfers

**Parties and roles.** You are the data controller and exporter. Neeto LLC, a
company based in the United States, is the data processor and importer. Neeto
processes Customer Personal Data only on Your documented instructions, as
described in the DPA.

**Categories of data and data subjects.** The categories of Personal Data and
data subjects are described in Section 1 of the DPA. In summary: identification
and contact data of Your users, and any personal data contained in the content
You or Your end users submit to the Services.

**Hosting location.** The Services are hosted on Amazon Web Services (AWS) in
the `us-east-1` region in the United States, as described in Our
[Security Policy](/legal/security-policy).

**Onward transfers.** Neeto engages the subprocessors listed on Our
[Subprocessors](/legal/subprocessors) page, which states each subprocessor's
role, the data involved, its location, and when it is used. Onward transfers
are governed by written agreements as described in Section 3 of the DPA.

**Transfer mechanism.** Transfers from You to Neeto are made under the EU SCCs
(Module Two), the UK International Data Transfer Addendum, and the Swiss
adaptation of the SCCs, each incorporated into the DPA as described in its
Section 5. Neeto is not certified under the EU-US Data Privacy Framework; the
transfer mechanism for Your data is the SCCs together with the applicable UK
and Swiss instruments, which do not depend on the continued validity of any
adequacy decision.

## 3. United States laws relevant to this assessment

The laws most commonly examined in TIAs for transfers to the United States are:

**FISA Section 702** (50 U.S.C. § 1881a) permits US intelligence agencies to
compel certain "electronic communication service providers" to disclose
communications of non-US persons located outside the United States. Directives
under Section 702 have in practice been directed at providers of
communications infrastructure and large-scale consumer communications
services. Neeto provides business productivity software to organizations; We
consider it unlikely that Neeto's Services would be of interest for foreign
intelligence collection of this kind.

**Executive Order 12333** governs US intelligence activities conducted outside
the United States, including collection of data in transit. It does not compel
companies to disclose data; the appropriate response is encryption, and all
data in transit to and between Neeto systems is encrypted using HTTPS/TLS as
described in Our Security Policy.

**The CLOUD Act** (18 U.S.C. § 2713) clarifies that US law enforcement may use
existing legal process (such as warrants) to reach data held by US providers
regardless of storage location. It applies to ordinary criminal legal process,
is subject to judicial oversight, and is comparable to mutual legal assistance
mechanisms that exist in most jurisdictions.

**Neeto's practical experience.** As of the last review date of this document,
Neeto has never received a directive under FISA Section 702, a national
security letter, or any other request from a US government authority seeking
access to Customer Personal Data.

## 4. Safeguards under Executive Order 14086

In 2022 the United States adopted Executive Order 14086, which limits US
signals-intelligence collection to what is necessary and proportionate to
defined objectives and establishes a two-level redress mechanism, including
the Data Protection Review Court (DPRC), available to individuals in the EEA,
the United Kingdom, and Switzerland.

These safeguards form the basis of the European Commission's adequacy decision
for the EU-US Data Privacy Framework, the United Kingdom's UK-US Data Bridge,
and Switzerland's recognition of the Swiss-US Data Privacy Framework. As the
European Data Protection Board confirmed in its information note of 18 July
2023, the safeguards of Executive Order 14086 apply to all data transferred to
the United States regardless of the transfer mechanism used, and may be taken
into account in a TIA for transfers based on the SCCs. The same reasoning
applies to a UK TRA: the UK government's own assessment underlying the Data
Bridge concluded that these US safeguards provide adequate protection for UK
personal data.

In other words, although Neeto relies on the SCCs rather than the Data Privacy
Framework, Your data benefits from the same US national-security safeguards
and redress mechanisms that the EU, UK, and Swiss authorities have each
independently assessed and accepted.

## 5. Supplementary measures

In addition to the contractual commitments in the DPA, Neeto maintains the
following measures, described more fully in Our
[Security Policy](/legal/security-policy):

**Technical measures.** All data in transit is encrypted using HTTPS/TLS.
Customer Data is encrypted at rest in AWS using AES-256 block-level storage
encryption, and database backups are stored in encrypted Amazon S3 buckets
using AES-256 server-side encryption.

**Organizational measures.** Production access is limited to authorized
personnel with a business need, follows the principle of least privilege, is
logged and monitored, and is removed when no longer needed. Neeto performs
background checks for personnel who are granted access to production systems.
All personnel with access to Personal Data are bound by confidentiality
obligations as described in Section 2.4 of the DPA.

**Contractual measures.** The SCCs, the UK Addendum, and the Swiss adaptation
are incorporated into the DPA. Neeto flows down equivalent data protection
obligations to subprocessors, notifies Customers of subprocessor changes with
an opportunity to object, supports audits as described in Section 2.7 of the
DPA, and notifies Customers of Security Breaches as described in Section 2.8
of the DPA.

## 6. Government requests for Customer Personal Data

If Neeto receives a request from any government authority for Customer
Personal Data, Neeto will:

- redirect the requesting authority to seek the data directly from the
  Customer, wherever possible;
- notify the affected Customer promptly, unless legally prohibited from doing
  so, and where prohibited, use reasonable efforts to obtain a waiver of the
  prohibition;
- review the request for legal validity and challenge it if there are
  reasonable grounds to consider it unlawful or overbroad, including seeking
  interim relief where appropriate;
- disclose only the minimum data required to comply with a valid and binding
  request; and
- never disclose Customer Personal Data to any authority voluntarily, in bulk,
  or through any form of backdoor or direct access to Neeto's systems.

## 7. Notes for EEA Customers

This document follows the six-step approach in the European Data Protection
Board's Recommendations 01/2020: the transfer is described in Section 2, the
transfer tool is the SCCs incorporated into the DPA, the assessment of US law
and practice is in Sections 3 and 4, and the supplementary measures are in
Sections 5 and 6. Neeto will re-evaluate this assessment as described in
Section 10.

## 8. Notes for UK Customers

For a TRA using the ICO's TRA tool, this document provides the information
relevant to the destination-country questions: the categories of data and
their sensitivity are described in Section 2 and in Section 1 of the DPA, the
relevant US laws and Neeto's practical exposure to them are described in
Section 3, and the safeguards and redress mechanisms available to UK data
subjects — including under the UK-US Data Bridge assessment — are described in
Section 4. Transfers are made under the UK International Data Transfer
Addendum as incorporated into Section 5 of the DPA.

## 9. Notes for Swiss Customers

For transfers subject to the Swiss Federal Act on Data Protection (FADP), the
SCCs apply as adapted for Switzerland as described in Section 5 of the DPA,
with the Federal Data Protection and Information Commissioner (FDPIC) as the
competent supervisory authority. The safeguards described in Section 4,
including the redress mechanism, extend to individuals in Switzerland.

## 10. Conclusion and review

Taking into account the nature of the data processed, Neeto's practical
experience with government requests, the safeguards of Executive Order 14086
as recognized by the EU, UK, and Swiss authorities, and the technical,
organizational, and contractual measures described above, Neeto's assessment
is that the laws and practices of the United States do not prevent Neeto from
complying with its obligations under the SCCs, the UK Addendum, or the Swiss
adaptation, and that the residual risk to data subjects is low.

Neeto reviews this document at least annually and upon any material change in
relevant law or in Neeto's processing operations, and will update it as
needed. This document was last reviewed in July 2026.

If You have questions about this document or need additional information to
complete Your assessment, contact Us at legal@neeto.com.

## Links

- [Human page](https://www.neeto.com/legal/transfer-impact-assessment)
