Transfer annex
Cross-border transfers under the GDPR — the EU Standard Contractual Clauses (Module Two, controller to processor), incorporated and completed. An annex to the Operator agreement.
What this annex does
The Operator agreement records that the Operator processes personal information on the Organisation's behalf. When the Organisation is established in the European Economic Area, or is otherwise subject to the GDPR, giving the Operator that information is also a transfer to a country without an EU adequacy decision — South Africa — and Article 46 of the GDPR asks for a written safeguard. This annex is that safeguard.
It incorporates the European Commission's Standard Contractual Clauses and completes the choices they leave open, so signing the Operator agreement with this annex attached signs the Clauses too. Nothing here amends them: where this annex or the Operator agreement provides less protection than the Clauses, the Clauses prevail — as the Clauses themselves require.
The Clauses, incorporated
The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 form part of the Operator agreement, in Module Two (transfer from controller to processor), with the Organisation as data exporter and the Operator as data importer. Their full text is the Commission's own, published at the address at the end of this document — referenced rather than retyped, so nothing here can drift from what the Commission adopted. The choices the Clauses leave to the parties are made as follows:
- Clause 7 (the docking clause) is not used.
- Clause 9(a): Option 2 — general written authorisation for sub-processors. The agreed list is Annex III below, and the Operator gives at least 30 days' notice of any addition or replacement, during which the Organisation may object.
- Clause 11(a): the optional independent dispute-resolution body is not used.
- Clause 13 and Annex I.C: the competent supervisory authority is the authority of the Organisation's own Member State of establishment, named in Annex I.C.
- Clause 17: the Clauses are governed by the law of Ireland.
- Clause 18(b): disputes arising from the Clauses are resolved before the courts of Ireland.
Local laws and government access — clauses 14 and 15
The Clauses ask both parties to satisfy themselves that the law where the importer sits does not prevent it honouring them. What the Organisation's assessment can rely on: the records are held in South Africa under the Protection of Personal Information Act — a GDPR-family law with an independent regulator, enforceable rights of access, correction and deletion, and its own cross-border rules. To date the Operator has never received a request from any authority for access to any organisation's records. If one ever arrives, clause 15 applies as written: the Operator notifies the Organisation where the law allows, challenges an unlawful request, and hands over the minimum the law compels.
Switzerland
For a transfer subject to Switzerland's Federal Act on Data Protection rather than the GDPR, the same Clauses apply with the standard Swiss adaptations: references to the GDPR are read as references to the FADP for those transfers, the competent supervisory authority is the Federal Data Protection and Information Commissioner, references to Member State law are read as references to Swiss law, and people in Switzerland may enforce their rights there. Everything else in this annex applies unchanged.
Annex I.A — the parties
admin made simple Pty Ltd, trading as admin made simple
(Data importer — the processor)
- Registered name
- admin made simple Pty Ltd
- Registration number
- 2022/835591/07
- Address
- 10 Remhoogte Road, Somerset West, 7130, South Africa
- Telephone
- +27 76 439 8222
- michael@adminmadesimple.co.za
Activities relevant to the transfer: running the Organisation’s workspace on the platform — storage, serving, invoicing, messaging, and the rest of what the Operator agreement describes.
and the organisation named in the Operator agreement
(Data exporter — the controller)
Activities relevant to the transfer: using the platform to hold and work with records about the people the Organisation serves — for an exam centre, running its Cambridge series.
Annex I.B — the transfer described
- Categories of data subjects: exam candidates — most of them children — and their parents or guardians; the Organisation's own staff; and, where the Organisation uses the wider workspace, the clients whose records it keeps there.
- Categories of personal data: names, dates of birth, identity or passport numbers, contact details, entries, timetables and results, invoice and payment references, and whatever else the Organisation itself puts into its workspace. Card numbers are never transferred — the payment provider collects those on its own pages.
- Special categories: a medical report supporting an access arrangement, only where the Organisation records a concession that needs one. Restrictions applied, as clause 8.6 asks: held in the Organisation's own exam file, never listed anywhere public, readable only by the Organisation's signed-in staff, and asked for only where a concession requires it.
- Frequency: continuous, for as long as the Organisation uses the platform.
- Nature and purpose: storage and processing to run the Organisation's own workspace and nothing of the Operator's — no advertising, no training of anything, no other organisation.
- Retention: until the Organisation deletes it or the Operator agreement ends; deletion on instruction is immediate and complete, as the agreement records.
- Onward transfers to sub-processors: only those in Annex III, for the same purpose, under contracts holding them to these obligations.
Annex I.C — competent supervisory authority
The supervisory authority of the Organisation’s own Member State of establishment. The Organisation writes it in — for an Irish school the Data Protection Commission, for a French one the CNIL, and so on.
Annex II — technical and organisational measures
The measures below are the standing behaviour of the platform's code, not a policy aspiration; the Operator agreement's confidentiality and security clauses apply on top of them.
- One access rule, applied on the Operator's servers on every read: what a person may see is decided per request, and there is no client-side path around it.
- Server-side scoping: a family, client or portal user is shown only their own rows, filtered before anything reaches their device.
- Encryption in transit (TLS) and at rest, as provided by Google Cloud, where the records are held — the Johannesburg region (africa-south1).
- Separate identity spaces: a portal or public account cannot reach staff or administrative routes, by construction rather than by a check.
- No direct database writes from any client: every write passes through the Operator's servers, and the database itself refuses anything else.
- Credentials, tokens and connected-account secrets are readable by no client at all, including their owner.
- Card details never touch the platform: the payment provider collects them on its own pages, and the platform stores references only.
- Deletion on the Organisation's instruction is immediate and complete, including data brought in from connected accounts.
- The Operator's own access is limited to running and supporting the service, and operator-console reads are recorded in an audit trail kept outside the organisation it concerns.
- Breach notification as the Operator agreement records: the Organisation is told as soon as practicable, with what is known.
Annex III — sub-processors
Engaged under clause 9(a), Option 2 — general written authorisation, with 30 days' notice of changes. The list, with what each does and where:
- Google (Google Cloud and Firebase) — database, authentication and file storage. Records rest in the Johannesburg region (africa-south1); authentication and content delivery run on Google's global infrastructure.
- Vercel — serves the application; requests are processed on its infrastructure, in Cape Town, South Africa.
- Paystack — card payments. The payer's card details go to Paystack directly; the platform holds references only.
- Resend — outbound email: receipts, timetables, notices.
- Meta Platforms — WhatsApp delivery, where the Organisation sends WhatsApp messages.
- Anthropic (United States) — the AI features, only where the Organisation uses them; nothing in an exam entry, invoice, timetable or reminder involves AI. Where the platform offers a choice of AI country, the choice is disclosed before anybody makes it, and the Organisation's administrators may restrict it for everybody.
How this annex is signed
This annex is executed by signing the Operator agreement with it attached — the signature blocks there sign the Clauses too. Complete Annex I.A and I.C alongside the agreement’s own party details. Signed copies go to michael@adminmadesimple.co.za; an Organisation whose compliance file needs the Clauses’ full text countersigned as a standalone document can ask for exactly that.
The Clauses’ authentic text, in every EU language: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
Signed copies go to michael@adminmadesimple.co.za — we counter-sign and return yours. An organisation with its own version of this document can send that instead, and we will sign it.