Legal

International Data Transfers FAQ

Plain-language information about Cogrion’s international data-transfer approach and customer-controlled deployment model.

Last Updated: 9 September 2026Version 1.0

This FAQ is provided for general information only. It does not constitute legal advice or create any independent contractual commitment, warranty, representation, service level, indemnity or remedy. Any binding obligations relating to international data transfers are governed by the applicable Agreement and Data Processing Addendum.

Customer is responsible for determining whether its deployment, providers, instructions and transfers comply with laws applicable to Customer.

Does Cogrion transfer Customer Data internationally?

It depends on the deployment and the support or provider choices in the applicable Order. Cogrion is designed so that the production data plane may operate in Customer’s designated cloud environment and region. Customer Data stored there remains subject to Customer’s cloud configuration and instructions. Limited account, support, diagnostic or security information may be processed from other locations where necessary to provide the Services and permitted by the Agreement and DPA.

Who selects the hosting region?

The applicable Order and Customer’s cloud configuration identify the deployment region. Cogrion does not relocate Customer-controlled production data to another region except on Customer’s instruction or as expressly stated in the Agreement.

What safeguards are used for restricted transfers?

Where required, Cogrion uses recognised contractual or legal mechanisms, which may include the European Commission Standard Contractual Clauses, the UK transfer addendum, contractual measures supporting Singapore’s transfer limitation obligation, or another valid mechanism. Supplementary technical and organisational measures are applied according to risk and the deployment model.

Does the DPA include the EU Standard Contractual Clauses?

Yes, to the extent required for a transfer governed by the GDPR, the applicable modules of the European Commission clauses adopted by Decision (EU) 2021/914 are incorporated as described in the DPA. Customer and Cogrion may execute additional transfer documentation where required.

How are government requests handled?

Cogrion assesses legally binding requests for validity, seeks to limit disclosure to what is legally required and, unless prohibited, notifies the affected customer. Cogrion may challenge a request where reasonable legal grounds exist.

Do Customer-selected LLM providers create separate transfers?

They may. When Customer selects or supplies an LLM provider, account, endpoint or region, Customer is responsible for assessing the provider’s data locations, transfer mechanisms, retention settings, country availability and legal restrictions. Cogrion’s technical ability to connect or route to a model is not a legal determination that the provider or transfer is permitted for Customer.

Are Customer-selected providers appointed by Cogrion?

No. A cloud provider, LLM provider, data source or integration selected, instructed, contracted or controlled by Customer is governed by Customer’s own arrangement and is not appointed by Cogrion merely because the Services connect to or interoperate with it.

Can customers request more information?

Customers may contact admin@cogrion.com for available information reasonably required for a transfer assessment, subject to confidentiality and security restrictions.

Questions about these terms may be directed to admin@cogrion.com. Privacy requests may be directed to admin@cogrion.com.