This assessment covers transfers of personal data from a client established in the European Economic Area, the United Kingdom or Switzerland (the data exporter) to NeateWorks in the United States (the data importer), and NeateWorks' onward transfers to the subprocessors on its subprocessor list. NeateWorks provides it to help the client carry out its own transfer impact assessment under Clause 14 of the Standard Contractual Clauses. It is NeateWorks' assessment, not legal advice, and it does not replace the client's own.
The data, data subjects, purposes and frequency are those in the description of processing (Annex I).
Transfers to NeateWorks rely on the EU Standard Contractual Clauses, Module Two (controller to processor), which the Master Services Agreement incorporates, with the UK International Data Transfer Addendum and the Swiss adaptations. NeateWorks does not rely on its own Data Privacy Framework certification.
Onward transfers to subprocessors rely on each subprocessor's data processing terms, which incorporate the Standard Contractual Clauses. Most are also listed under the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023), with its UK extension and Swiss counterpart. Check each listing at dataprivacyframework.gov. The EU General Court upheld the adequacy decision in Latombe v Commission (T-553/23, 3 September 2025), and an appeal to the Court of Justice may be pending.
FISA Section 702 (50 U.S.C. § 1881a) lets the U.S. government compel an "electronic communication service provider" to help it acquire the communications of non-U.S. persons reasonably believed to be outside the United States, for foreign-intelligence purposes. That term is defined broadly and covers remote computing services. In 2024 the Reforming Intelligence and Securing America Act widened it further and reauthorized the program. Check whether the program has been reauthorized again or changed since.
Executive Order 12333 governs intelligence collection outside FISA, such as interception of data in transit. It gives no power to compel a company like NeateWorks to hand over data.
Executive Order 14086 (2022) limits signals intelligence to what is necessary and proportionate to defined objectives. It also gives individuals in qualifying states, which include the EU and EEA, the United Kingdom and Switzerland, a redress route ending at the Data Protection Review Court. These safeguards apply to all transfers to the United States, whichever transfer tool is used.
Law-enforcement access (for example under the Stored Communications Act and the CLOUD Act) requires legal process such as a warrant or subpoena, which the provider can challenge.
NeateWorks is a small Colorado software and consulting company. Because it hosts systems for clients, it may fall within the definition of an electronic communication service provider. So may each of its U.S. subprocessors.
The data NeateWorks processes is ordinary business data: customer and user accounts, bookings, messages, files and payment references for small and mid-sized businesses. Special categories of data are excluded by contract. NeateWorks considers this data of low interest to foreign-intelligence collection, but the client should apply its own view of its data and its users.
Google, Microsoft (GitHub), Stripe and Anthropic publish transparency reports and policies on government requests, including commitments to challenge overbroad requests. Consult each provider's current report.
Under Clause 15 of the Standard Contractual Clauses, NeateWorks will notify the client of any legally binding request for its personal data where the law allows, will challenge a request it considers unlawful, and will disclose only the minimum the request requires.
HTTPS on all traffic to and from every app, which protects against interception in transit of the kind Executive Order 12333 allows.
Encryption at rest on all Google Cloud storage, plus field-level encryption of stored third-party credentials.
Data kept in a single U.S. region, us-central1, so the client knows where it is.
Strict access control, short-lived credentials, hashed tokens, credential redaction in logs, and an audit trail, as set out in the security measures.
Minimization: special categories are excluded, logs are kept 30 days, and backups 30 days.
Limits the client should weigh: Google manages the encryption keys for data at rest, so a cloud provider compelled under U.S. law could technically access data in the clear. AI features use Vertex AI's global endpoint, whose processing location is not pinned, and the application log bucket is a Google global service.
Taking into account the categories of data, the redress and proportionality safeguards of Executive Order 14086, and the measures above, NeateWorks' assessment is that U.S. law and practice do not prevent it from meeting its obligations under the Standard Contractual Clauses for the processing it carries out. The client should confirm this against its own data and data subjects, following the European Data Protection Board's Recommendations 01/2020.
NeateWorks reviews this assessment at least once a year, and whenever its subprocessors, hosting locations or the relevant law change.