Standard Contractual Clauses Addendum
For International Data Transfers from the EEA/EU to Third Countries
EU Commission Implementing Decision 2021/914 Module 2: Controller-to-Processor Transfers
Preamble
This Standard Contractual Clauses Addendum (“SCC Addendum”) forms part of the Data Processing Agreement between:
Data Exporter (Controller): [Data Exporter to complete] Data Importer (Processor): Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust
Purpose: This SCC Addendum implements the Standard Contractual Clauses approved by the European Commission for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (GDPR).
Effective Date: [Data Exporter to complete]
Legal Basis: EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
Incorporation of Standard Contractual Clauses
The Standard Contractual Clauses set out in the Annex to EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“SCCs”) are hereby incorporated by reference in their entirety and form an integral part of this Addendum.
The full text of the SCCs is available in the Official Journal of the European Union (OJ L 199, 7.6.2021, p. 31-61) and at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
Module Applied: Module 2 (Controller to Processor)
Scope: support data transferred through our support platform; downpipes out of scope
Maelstrom AI runs one ISMS over its downpipes platform and its internal support platform.
- downpipes, no-custody backup and disaster recovery for the Cloudflare data layer.
- Our support platform, Maelstrom’s internal support system.
This SCC Addendum concerns support data the data exporter sends to Maelstrom through our support platform, in connection with the data exporter’s use of downpipes. The transfer of personal data described in Annex I (contact data, message content, attachments, support bundles and technical metadata) arises from the support-platform flow.
downpipes is out of scope for this Addendum, because it triggers no transfer of personal data to Maelstrom through the product itself. It is no-custody: it runs in the customer’s own Cloudflare account, under the customer’s own keys, and through the product itself Maelstrom holds no customer keys, data or Cloudflare tokens. downpipes backup archives are sealed under customer-held keys using post-quantum hybrid encryption and written via a 3-2-1 fan-out to customer-controlled destinations. No customer personal data is received or processed by, or on behalf of, Maelstrom through the downpipes product itself. For this reason, the product triggers no third-country transfer for which Standard Contractual Clauses would be required. It adds no sub-processor to Annex III (see the Sub-Processors List).
The vendor-operated control-plane mints licence tokens and is fail-open. It receives a content-free advisory beacon only from engines whose operator turns it on. The static, signature-pinned update channel is pull-only, with no phone-home. Neither carries customer backup, log or infrastructure data, so neither introduces a transfer. The control-plane does hold licensee contact details, such as the organisation’s name and the names and email addresses of its named contacts (see the Sub-Processors List, Section 1.1).
Selected Options and Specifications
The following options have been selected within the SCCs:
| Clause | Option | Selection |
|---|---|---|
| Clause 7 (Docking Clause) | Optional | Not used. Additional parties must execute separate SCCs. |
| Clause 9(a) (Sub-Processor Authorisation) | Option 1 (specific) or Option 2 (general) | Option 2: General written authorisation. Data exporter authorises the sub-processors listed in Annex III. Data importer shall provide at least 30 days’ advance notice of changes. |
| Clause 11(a) (Redress. independent dispute resolution) | Optional | Not used. Data subjects may lodge complaints with the competent supervisory authority (Annex I.C) or bring proceedings before the competent courts. |
| Clause 13 (Supervision) | Identify competent supervisory authority | As identified in Annex I.C (determined by data exporter’s establishment). |
| Clause 17 (Governing Law) | EU/EEA Member State law | Ireland (default). May be varied by written agreement to another EU/EEA Member State law where the data exporter is established. Must allow for third-party beneficiary rights. |
| Clause 18 (Choice of Forum) | EU/EEA courts | Courts of the Member State specified in Clause 17. |
Note: Clause 17 defaults to Irish law. Where a data exporter is established in a different EU/EEA Member State, parties may agree in writing to substitute that Member State’s law, provided it permits third-party beneficiary rights for data subjects. The Clause 9(a) notice period is set at 30 days; data exporters with shorter contractual expectations should raise this at onboarding.
Annex I: List of Parties and Transfer Details
A. List of Parties
Data Exporter(s):
| Detail | Information |
|---|---|
| Name | [Data Exporter to complete] |
| Address | [Data Exporter to complete] |
| Contact Person | [Data Exporter to complete] |
| [Data Exporter to complete] | |
| Role | Controller |
| Activities relevant to transfer | Using downpipes, and sending Maelstrom support data through our support platform |
| Signature and date | __________________________ |
Data Importer(s):
| Detail | Information |
|---|---|
| Name | Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust |
| Address | PO Box 169, St Arnaud VIC 3478, Australia |
| Contact Person | ISMS Owner |
| support@maelstrom.au | |
| Role | Processor |
| Activities relevant to transfer | Operating our support platform; receiving, triaging and answering support requests, including attachments and support bundles the data exporter chooses to send |
| Signature and date | __________________________ |
B. Description of Transfer
Categories of Data Subjects:
- The data exporter’s personnel who submit support requests
- Any individual whose personal data the data exporter’s personnel include in a message, attachment, or support bundle
Categories of Personal Data Transferred:
| Category | Data Elements | Volume |
|---|---|---|
| Contact Data | Name, email address | Per support ticket |
| Message Content | Support conversation content, operator notes | Per support ticket |
| Attachments and Bundles | Attachments and support bundles, including through a one-time upload link | Per support ticket, where sent |
| Technical Metadata | Caller IP address, operator email address (technical log records) | Per support request |
IMPORTANT - Measures NOT Applied:
- The data importer does not apply masking or redaction to support data: message content and attachments are held as submitted (see Annex II).
- The data importer does not process special categories of personal data as a purpose of the support service; any such data present in Controller-supplied content is handled under the same security measures as other support data.
Sensitive Data (if applicable): The data importer does not seek or require special categories of personal data as defined in GDPR Article 9. Support data may incidentally contain such data if the data exporter includes it in a message, attachment, or bundle; the data exporter controls what it sends.
Frequency of Transfer:
- On-demand (per support request initiated by the data exporter’s personnel)
- Estimated volume: Variable, dependent on the data exporter’s support activity
Nature of Processing:
- Receipt and storage of support conversations, attachments and support bundles
- Ticket tracking and SLA management
- Anti-fraud processing (rate limiting) on the support portal
- Security monitoring and incident detection
Purpose(s) of Transfer:
- Diagnose and resolve issues the data exporter reports through our support platform
- Ensure service security and reliability
- Comply with the data exporter’s legal obligations
Retention Period:
- Closed tickets and attachments: 365 days after ticket close (automatic deletion)
- Support bundles: 30 days after upload, or on ticket close, whichever is sooner (automatic deletion)
- Technical log records: 90 days, then deleted automatically
- Daily export snapshots of ticket records: 30 days, then deleted automatically
- Encrypted backup copies of stored messages, attachments and support bundles: until the data importer prunes its backups. Maelstrom’s own downpipes deployment makes these copies in the data importer’s Cloudflare account. The deletion periods above do not apply to them
Sub-Processors:
- See Annex III for authorised sub-processors
C. Competent Supervisory Authority
Supervisory Authority:
[Data Exporter to complete. Select the applicable option below based on the data exporter’s establishment.]
Option 1 - If Data Exporter is in Ireland:
- Name. Data Protection Commission (DPC)
- Address. 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
- Website. https://dataprotection.ie
- Email. info@dataprotection.ie
Option 2 - If Data Exporter is in UK:
- Name. Information Commissioner’s Office (ICO)
- Address. Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
- Website. https://ico.org.uk
- Phone. 0303 123 1113
Option 3 - If Data Exporter is in Germany:
- Name. Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI)
- Address. Graurheindorfer Str. 153, 53117 Bonn, Germany
- Website. https://www.bfdi.bund.de
Option 4 - If Data Exporter is in France:
- Name. Commission Nationale de l’Informatique et des Libertés (CNIL)
- Address. 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Website. https://www.cnil.fr
Option 5 - Other EU/EEA Member State:
- [Data Exporter to complete. Specify supervisory authority based on data exporter’s location or establishment.]
- See EDPB list: https://edpb.europa.eu/about-edpb/board/members_en
Annex II: Technical and Organisational Measures (TOMs)
This Annex describes the technical and organisational measures implemented by the data importer to protect personal data transferred under the Clauses.
Reference: For details, see Data Processing Agreement Section 5 (Security Measures).
A. Technical Measures
1. Encryption
(a) Encryption in Transit:
- TLS 1.2 or higher for web and API traffic. Clients that support TLS 1.3 use it, with forward secrecy
- Inbound and outbound support email uses TLS when the other mail server supports it
- HSTS (HTTP Strict Transport Security) enforced
- HTTP requests are redirected to HTTPS
(b) Encryption at Rest:
- Encryption at rest for all data, provided by Cloudflare’s managed storage services
- Encrypted secrets management
2. Data Minimisation
(a) Retention Limits:
- Support data is retained only for the periods set out in Annex I.B
- Automatic deletion enforced by a daily retention sweep
(b) No Masking Applied:
- The data importer does not apply masking or redaction to support data: message content and attachments are held as submitted
- The data exporter controls what personal data it includes in a message, attachment, or bundle
3. Access Controls
(a) Authentication:
- Multi-factor authentication (MFA) required for all administrative access to production systems
- Cloudflare Access gates the support portal’s operator interface; no local password store exists for the support portal
- Authenticated service-to-service access for machine-to-machine support routes, rotated per the data importer’s key rotation policy
(b) Authorisation:
- Access to the systems that hold support data is limited to a single operator, the ISMS Owner
- An allowlist of these identities controls the operator role on the support platform
- Principle of least privilege enforced
(c) Access Reviews:
- Access rights reviewed when they change, and at least once a year (documentation available to data exporter upon request)
- Immediate access revocation upon personnel termination
- Each administrative request logged, with the operator’s identity, the path and the time
4. Network Security
(a) DDoS Protection:
- Cloudflare DDoS protection (500 Tbps network capacity)
- Automatic attack detection and mitigation
- Rate limits per source IP address and per ticket reference, each with a global limit
(b) Web Application Firewall (WAF):
- Cloudflare’s managed WAF rules
- Automatic blocking of requests that match those rules
(c) Intrusion Detection:
- Rate-limit denials and failed authentication logged as security events
- Cloudflare security alerts, for example about DDoS attacks, sent to the data importer by email
- No 24/7 security monitoring. The data importer reviews alerts during support hours (Monday to Friday, 9am to 5pm Melbourne time), and on a best-efforts basis outside them
5. Monitoring and Logging
(a) Security Event Logging:
- Security events logged as structured JSON
- Technical log records copied to a separate storage bucket, which deletes them after 90 days (Annex I.B)
(b) Audit Trails:
- Each administrative request logged, with the operator’s identity, the path and the time
- Support portal access logging (request and response metadata, including caller IP and operator email, per Annex I.B)
- Access to logs requires sign-in to the data importer’s Cloudflare account
(c) Automated Alerts:
- Cloudflare alert policies email the data importer about DDoS attacks, security findings and abuse reports
6. Vulnerability Management
(a) Automated Checks:
- The support platform’s repository defines a production dependency audit for each code change. The build service does not run it at present (see B.2(c))
- Weekly dependency update requests are configured for the repository
(b) Penetration Testing:
- Third-party penetration testing not yet performed; planned when commercially justified.
- Responsible disclosure programme (security@maelstrom.au)
- Findings remediated within the times in (c)
(c) Patch Management:
- Critical vulnerabilities patched within 2 Business Days after the data importer becomes aware of them
- High severity vulnerabilities patched within 7 days, and medium severity within 30 days
- Regular updates to dependencies and infrastructure
B. Organisational Measures
1. Access Management
(a) Personnel:
- A single operator, the ISMS Owner, holds the only operator access
- Every person with access to support data is bound by a confidentiality obligation, by contract or by law
- The ISMS Owner holds current professional security certifications
(b) Access Provisioning:
- Access is granted only through the operator allowlist and Cloudflare Access
- Access granted based on need-to-know
- Access rights reviewed when they change, and at least once a year
(c) Access Termination:
- Immediate revocation of all access upon personnel termination or role change
- Return of all company devices and credentials
2. Privacy by Design and Default
(a) Architectural Principles:
- No-custody first: downpipes keeps customer data in the customer’s own Cloudflare account
- Retention limits: the support platform deletes support data on the schedule in Annex I.B
(b) Design Documentation:
- Written design documents for new features of the support platform
(c) Secure Development Lifecycle (SDLC):
- A written security operations register for the support platform’s dependencies and outbound network calls
- The support platform’s repository defines checks for each change: type checking, tests, lint, repository security gates and a production dependency audit. The repository also defines a software bill of materials and signed build provenance for each build of the main branch. The build service does not run these checks at present
- No static or dynamic application security testing (SAST or DAST) runs on the support platform
3. Vendor and Sub-Processor Management
(a) Vendor Selection:
- Security assessment for all critical vendors and sub-processors
- Evaluation of certifications (ISO 27001, SOC 2 Type II)
- Review of Data Processing Agreements and security commitments
(b) Ongoing Monitoring:
- Review of each vendor’s security documentation at least once a year
- Monitoring of vendor security advisories and incident notifications
- Continuous assessment of sub-processor compliance (Cloudflare status monitoring)
(c) Contractual Protections:
- Data Processing Agreements with all sub-processors meeting GDPR Article 28(3) requirements
- Standard Contractual Clauses for international transfers
- Breach notification obligations (without undue delay to data importer)
- Audit rights
4. Incident Response and Business Continuity
(a) Incident Response:
- Incident response during support hours (Monday to Friday, 9am to 5pm Melbourne time), and on a best-efforts basis outside them
- Documented incident response playbooks for common scenarios
- Breach notification to data exporter without undue delay, and within any time limit that applicable law sets
(b) Post-Incident Review:
- Root cause analysis for all incidents
- Lessons learned documentation
- Remediation actions to prevent recurrence
- Restore drills of the support platform’s backups, with documented results
(c) Business Continuity:
- A daily export of ticket records to a separate storage bucket, kept for 30 days
- Encrypted backup copies of stored messages, attachments and support bundles, made by Maelstrom’s own downpipes deployment in the data importer’s Cloudflare account. They are kept until the data importer prunes its backups
- Disaster recovery plan with a defined RTO of 4 hours from the start of recovery, and an RPO of 24 hours. Recovery starts during support hours, or on a best-efforts basis outside them
- The support platform runs on Cloudflare Workers across Cloudflare’s network. Its ticket database is a Cloudflare Durable Object, which runs in one location at a time
5. Compliance and Governance
(a) Policies and Procedures:
- Information Security Policy (ISO 27001:2022 aligned)
- Data Retention Policy (documented retention periods and deletion procedures)
- Incident Response Policy
- Access Control Policy
- Cryptography Policy
- Acceptable Use Policy
(b) Certifications (Planned):
- ISO 27001:2022 - Information Security Management System (certification planned when commercially justified)
- ISO 27701:2019 - Privacy Information Management System (certification planned when commercially justified)
(c) Records of Processing Activities (ROPA):
- Maintained in accordance with GDPR Article 30(2)
- Available to supervisory authorities and data exporter upon request
- Reviewed and updated upon material changes
(d) Management Review:
- ISMS management review at least once a year
- Review of security metrics, incidents, audit findings
- Assessment of effectiveness of security measures
- Continuous improvement initiatives
C. Physical and Environmental Security
Note: Maelstrom AI operates on cloud infrastructure and does not maintain physical data centres. Cloudflare holds the support data. Amazon Web Services holds encrypted backup copies of Maelstrom’s own systems, and holds no support data. Physical security is the responsibility of those providers.
Cloudflare Physical Security (Sub-Processor):
- ISO 27001 certified data centres
- 24/7 security personnel and surveillance
- Biometric access controls and multi-factor authentication
- Environmental controls (fire suppression, climate control, power redundancy)
- Physical security audits (SOC 2 Type II coverage)
Maelstrom AI Workplace Security (Administrative):
- Maelstrom AI has no office that holds support data
- Device encryption for all laptops and workstations (full-disk encryption)
- Clean desk policy (no sensitive information left unattended)
- Secure disposal of paper documents (shredding)
- No personal data stored on local devices (cloud-based systems only)
D. Data Retention and Deletion
1. Retention Periods
| Data Category | Retention Period | Deletion Method |
|---|---|---|
| Closed tickets and attachments | 365 days after ticket close | Automatic deletion via daily retention sweep |
| Support bundles | 30 days after upload, or on ticket close, whichever is sooner | Automatic deletion via daily retention sweep |
| Technical log records | 90 days | Automatic deletion |
| Daily export snapshots of ticket records | 30 days | Automatic deletion |
| Encrypted backup copies of stored messages, attachments and support bundles | Until the data importer prunes its backups | Deleted when the backups are pruned |
2. Deletion Procedures
(a) Automated Deletion:
- A daily retention sweep enforces the ticket and bundle windows above
- Support-platform storage records are deleted once the applicable window is reached
(b) Manual Deletion (upon data subject request or contract termination):
- Deletion from active systems targeted within 2-5 Business Days (best-effort; no contractual SLA)
- Overwriting of storage media (for non-encrypted data, if applicable)
- Deletion certificate provided to data exporter
(c) Verification of Deletion:
- Deletion logs maintained (who deleted what, when)
- Attestation of deletion provided to data exporter
- Audit capability to verify deletion completion
E. Sub-Processor Security (Cloudflare)
Cloudflare Security Measures:
- Certifications. ISO/IEC 27001, SOC 2 Type II, PCI DSS Level 1, C5 (Germany)
- Encryption. AES-XTS disk encryption at rest (128-bit keys or longer), TLS in transit
- Access Controls. MFA, RBAC, least privilege
- Network Security. DDoS protection, WAF, intrusion detection
- Monitoring. 24/7 SOC, automated threat detection
- Incident Response. 24/7 incident response team, breach notification without undue delay
- Compliance. GDPR-compliant DPA, EU-US Data Privacy Framework participant
Cloudflare Data Processing Addendum:
- Available at: https://www.cloudflare.com/cloudflare-customer-dpa/
- Incorporates Standard Contractual Clauses (Module 2: Controller-to-Processor)
- Provides security commitments and data protection obligations
F. Measures to Ensure Data Minimisation
(a) Architectural Design:
- downpipes is no-custody: customer infrastructure data stays in the customer’s own Cloudflare account and never reaches the data importer through the product itself
- Support data processing is limited to what the data exporter chooses to send through our support platform (Annex I.B)
(b) Data Collection Review:
- Review of data collection practices upon material changes
- Assessment of whether each data element is still necessary
- Elimination of unnecessary data collection
(c) Privacy-Enhancing Measures:
- Defined, automatically enforced retention periods (Annex I.B)
- Access controls restricting who can reach support data
G. Measures to Ensure Data Quality
(a) Accuracy:
- The data subject or the data exporter’s personnel supply contact data (name, email address) directly
- Timestamps generated by system clocks (NTP-synchronised)
(b) Data Subject Control:
- A data subject may ask the data exporter to correct contact data or operator notes (Annex I.B)
- Message and attachment content, once submitted, is corrected by a follow-up message rather than altering the original
H. Accountability and Transparency
(a) Documentation:
- This Annex II documents all security measures
- security policies maintained in ISMS
- Records of Processing Activities (ROPA) available to supervisory authorities
(b) Reporting:
- Compliance summary on request (Enterprise DPA Section 12)
- Security summaries on request
- No transparency report is published. The data importer gives the number of government access requests (if any) on request
(c) Audits:
- Third-party penetration testing: not yet performed; planned when commercially justified.
- ISO 27001/27701 certification audits (aligned with ISO 27001:2022 and ISO 27701:2019, certification planned when commercially justified)
- Internal security audits, at least once a year
- Data exporter audit rights (see Standard DPA Section 8 or Enterprise DPA Section 9)
Annex III: List of Sub-Processors
Authorised Sub-Processors
The data importer has the data exporter’s general authorisation to engage the following sub-processors. The authorised sub-processors are those listed at https://maelstrom.au/trust/legal/sub-processors. That page is incorporated into this Annex by reference. Cloudflare, Inc. is the only sub-processor for the support data in Annex I, so it is detailed below.
The providers below are not sub-processors for the support data in Annex I:
- Amazon Web Services stores encrypted backup copies of Maelstrom’s own systems in Sydney, Australia. It holds no support data.
- Proton AG hosts Maelstrom’s company mailboxes, including support@maelstrom.au. The support platform does not use it. Mail sent to a maelstrom.au address, including notices and requests under the DPA, is stored in those mailboxes.
- Stripe, Xero and Airwallex handle Maelstrom’s own billing and payments for downpipes, as listed at downpipes.io/trust/sub-processors.
Sub-Processor 1: Cloudflare, Inc.
| Detail | Information |
|---|---|
| Name | Cloudflare, Inc. |
| Registered Address | 101 Townsend St, San Francisco, CA 94107, United States |
| Contact | privacyquestions@cloudflare.com |
| Website | https://www.cloudflare.com |
| Processing Location(s) | United States (primary), European Union (Ireland, Germany, France, Netherlands, etc.), United Kingdom, Asia-Pacific (Singapore, Japan, Australia), and other Cloudflare edge locations globally (300+ locations) |
| Nature of Processing | Hosting, storage, network security and content delivery for our support platform |
| Categories of Data | Contact data, message content, attachments, support bundles, operator notes, entitlement snapshot, technical metadata (caller IP, operator email), per Annex I.B |
| Duration | For the duration of the data importer’s contract with Cloudflare and the provision of Services to the data exporter |
| Transfer Mechanism | Standard Contractual Clauses (EU Commission Decision 2021/914, Module 2: Controller-to-Processor) |
| Data Processing Agreement | Cloudflare Data Processing Addendum: https://www.cloudflare.com/cloudflare-customer-dpa/ |
| Security Certifications | ISO/IEC 27001, SOC 2 Type II, PCI DSS Level 1 Service Provider, C5 (Cloud Computing Compliance Controls Catalogue - Germany) |
| EU-US Data Privacy Framework | Cloudflare is certified under the EU-US Data Privacy Framework (verify at: https://www.dataprivacyframework.gov/) |
| Additional Safeguards | Encryption at rest (Cloudflare-managed), TLS in transit, defined retention periods (Annex I.B), 24/7 SOC monitoring, DDoS protection |
Services Provided by Cloudflare:
- Cloudflare Durable Objects. Stateful compute (support data storage)
- Cloudflare R2. Object storage for raw support email, attachments and support bundles
- Technical log records. Caller IP address, operator email address
- Cloudflare Email Routing. Inbound support mail routing
- Cloudflare DDoS Protection. Network security and traffic filtering
- Cloudflare WAF. Web Application Firewall (OWASP Top 10 protection)
Data Residency: Cloudflare processes data at edge locations globally, within the data importer’s own Cloudflare account. Maelstrom AI does not currently offer region-restricted processing.
Future Sub-Processors
Notification Process:
- Data importer shall provide data exporter with at least 30 days’ advance notice of any intended addition or replacement of sub-processors (60 days for enterprise customers)
- Notice provided via email to designated contact and update to public sub-processor list at https://maelstrom.au/trust/legal/sub-processors
- Data exporter may object on reasonable grounds relating to data protection within 14 days of notice (30 days for enterprise)
- If objection cannot be resolved, data exporter may terminate affected Services or the entire contract
Current Sub-Processor List (Always Up-to-Date):
- Public list maintained at: https://maelstrom.au/trust/legal/sub-processors
- Data exporter may ask to be emailed when the list changes, by writing to support@maelstrom.au
Annex IV: Transfer Impact Assessment Summary (Optional)
Status: Completed by data importer (Maelstrom AI) on 2026-02-13; revised 2026-09-04 to reflect support-platform data scope
Purpose: Assess whether the law or practice of the country of destination (United States, via Cloudflare) impinges on the effectiveness of the Standard Contractual Clauses.
A. Assessment Methodology
(a) Legal Analysis: Review of US surveillance laws (FISA Section 702, Executive Order 12333, CLOUD Act) and their applicability to Maelstrom AI’s data processing
(b) Practical Assessment: Evaluation of actual risk based on:
- Nature and volume of data transferred
- Likelihood of government access requests
- Cloudflare’s legal and technical safeguards
- The retention periods and access controls applied to support data (Annex I.B, Annex II)
(c) Supplementary Measures: Identification of additional technical and organisational measures beyond SCCs
B. Key Findings
1. Nature of Data Transferred
| Risk Factor | Assessment | Risk Level |
|---|---|---|
| Defined Data Categories | Contact data, message content, attachments and support bundles the data exporter chooses to send; no masking is applied (Annex I.B, Annex II) | MEDIUM |
| Controller-Supplied Content | The data exporter controls what personal data it includes in a support request; the data importer does not solicit special categories of data | LOW-MEDIUM |
| Defined Retention | 365 days for closed tickets and attachments, 30 days for support bundles, automatically deleted. Encrypted backup copies are kept until the data importer prunes its backups (Annex I.B) | LOW |
| No Special Categories Sought | The data importer does not require GDPR Article 9 special category data as a purpose of the support service | LOW |
2. Legal Surface (United States)
(a) FISA Section 702:
- Targets non-US persons’ communications for foreign intelligence purposes
- Applicability to Maelstrom AI. LOW - Support data has no foreign intelligence value
- Cloudflare Safeguards. Legal challenges to overbroad requests, transparency reporting
(b) Executive Order 12333:
- Authorises foreign intelligence collection outside US
- Applicability to Maelstrom AI. LOW - Data processed within US infrastructure, not targeted extraterritorially
- Cloudflare Safeguards. Encryption in transit reduces interception risk
(c) CLOUD Act:
- Allows US law enforcement to compel disclosure of data regardless of storage location
- Applicability to Maelstrom AI. LOW - Support data is unlikely to be the subject of criminal investigations
- Safeguards. Data importer will challenge overbroad requests, notify data exporter
3. Practical Risk Assessment
| Factor | Assessment | Mitigation |
|---|---|---|
| Government Access Requests | ZERO requests received to date (as of 2026-09-04) | Immediate notification to data exporter if received |
| Likelihood of Future Requests | LOW - support data has no intelligence or law enforcement value | Challenge any requests as overbroad |
| Cloudflare’s Track Record | Strong legal advocacy, transparency reporting, minimal government access | Benefit from Cloudflare’s scale and resources |
| Data Sensitivity | MEDIUM - message content and attachments are held unmasked; access controls and retention limits reduce exposure | Access controls, defined retention (Annex I.B) |
4. Cloudflare-Specific Safeguards
(a) Legal Protections:
- Cloudflare has history of challenging government requests in court
- Transparency reports published twice a year (disclosing number of requests)
- Legal team with expertise in data protection and government access issues
(b) Technical Protections:
- Encryption at rest (Cloudflare-managed) and in transit (TLS)
- Access controls limit Cloudflare personnel access to customer data
- Audit logging of all access to customer data
(c) Organisational Protections:
- ISO 27001 and SOC 2 Type II certified
- Data Processing Addendum with strong contractual safeguards
- EU-US Data Privacy Framework certified (additional legal protection)
C. Supplementary Measures Implemented
Beyond Standard Contractual Clauses, the following supplementary measures reduce risk:
1. Technical Measures
(a) Access Restriction:
- Cloudflare Access gates the support portal’s administrative surface
- Reduces the number of people who can reach support data
(b) Encryption:
- TLS in transit (protects against network interception)
- Encryption at rest, provided by Cloudflare’s managed storage services
(c) Data Minimisation:
- The data importer collects support data only where the data exporter chooses to send it
- No masking is applied (Annex II); the data exporter is responsible for what it includes
(d) Defined Retention:
- 365 days for closed tickets and attachments, 30 days for support bundles (automatic deletion)
- Encrypted backup copies are kept until the data importer prunes its backups (Annex I.B)
- Limits the window of exposure to government access
2. Organisational Measures
(a) Notification Obligations:
- Data importer will notify data exporter within 24 hours of any government access request (unless legally prohibited)
- Data importer will document all efforts to challenge or seek waiver of prohibition on notification
(b) Legal Challenge:
- Data importer will challenge government requests that appear overbroad or lack legal basis
- Data importer will exhaust reasonable legal avenues to prevent disclosure
(c) Minimise Disclosure:
- If disclosure required, data importer will provide minimum data necessary to comply
- Data importer will seek to redirect request to data exporter (Controller is responsible for data)
(d) Request Figures:
- The data importer does not publish a transparency report
- It gives the data exporter the number of government requests (if any) on request
3. Contractual Measures
(a) Standard Contractual Clauses:
- Provides contractual safeguards for data transfer
- Gives data subjects and supervisory authorities enforcement rights
(b) Cloudflare DPA:
- Cloudflare bound by Data Processing Addendum incorporating SCCs
- Contractual obligation to notify data importer of government requests (where permitted by law)
(c) EU-US Data Privacy Framework:
- Cloudflare certified under DPF (additional legal safeguard)
- DPF provides redress mechanism for EU data subjects
D. Conclusion
Overall Risk Level: LOW to MEDIUM
Rationale:
- Support data is unmasked, so the assessment does not rely on pseudonymisation; it relies instead on access controls, defined retention, and the data exporter’s control over what it sends
- Support data has no national security, intelligence, or law enforcement value (unlikely to be targeted)
- Defined retention periods (365 days tickets, 30 days bundles) limit the exposure window
- Cloudflare’s legal and technical safeguards
- Zero government access requests received to date
Assessment: The Standard Contractual Clauses, combined with supplementary technical and organisational measures, provide adequate safeguards for the transfer of personal data from the EEA to the United States via Cloudflare infrastructure. The risk of government access is assessed as low; the overall risk level is low to medium. The data exporter controls the volume and sensitivity of personal data it sends through our support platform.
Monitoring: The data importer shall continuously monitor legal and factual developments in the United States and update this assessment if circumstances change (e.g., new surveillance laws, government access requests received, changes to Cloudflare’s safeguards).
Review Date: This assessment shall be reviewed annually or upon material changes to legal surface or processing activities.
Signature
BY SIGNING BELOW, the Parties confirm that they have read and understood the Standard Contractual Clauses and agree to be bound by them.
Data Exporter (Controller):
Signature: ________________________________
Name: ________________________________
Title: ________________________________
Date: ________________________________
Data Importer (Processor): Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust
Signature: ________________________________
Name: ________________________________
Title: ________________________________
Date: ________________________________
Document Information
Document Title: Standard Contractual Clauses Addendum Version: 2.7 Status: Active Template Date: 2026-02-13 Last Updated: 2026-09-29 Classification: Legal Template Owner: ISMS Owner
Change History:
- 2.7 (2026-09-29): Annex II, section 6(b) names security@maelstrom.au as the address for security reports.
- 2.6 (2026-09-29): Corrected a drafting error in Annex IV, section D: the Assessment states that the risk of government access is low and that the overall risk level is low to medium, which matches the Overall Risk Level.
- 2.5 (2026-09-29): Plain English rewrite. No change to any commitment, right or obligation.
- 2.4 (2026-09-25): Annex II states the measures in place. These include the single operator, TLS 1.2 or higher, the rate limits, the WAF, the checks defined for the support platform and the backups. Annex II drops JIT access, SAST and DAST, 24/7 monitoring, tamper-evident logs, availability zones, background checks, signed NDAs, threat modelling, DPIAs and quarterly reviews, which are not in place. Annex II B.4(a) sets breach notice without undue delay and within any legal time limit, in place of targets of 4 hours or 24 hours. Annex II A.6 patches critical vulnerabilities within 2 Business Days after awareness, in place of 48 hours. Annex II B.4(c) measures the 4-hour RTO from the start of recovery. Annex I.B and Annex II D list the 30-day export snapshots and the backup copies. Annex II A.1 limits TLS to web and API traffic, and states TLS for email. Annex III names the providers that are not sub-processors for support data. Annexes II and IV give government request figures on request, in place of a transparency report.
- 2.3 (2026-09-25): Factual corrections. Annexes II, III and IV state TLS for transport encryption, with no minimum version. Annex II names Amazon Web Services and states Cloudflare facts as its DPA and website give them. The advisory beacon is opt-in, and the control-plane holds licensee contact details. No change to obligations.
- 2.2 (2026-09-24): Technical log records are kept for 90 days (Annex I.B and Annex II).
- 2.1 (2026-09-24): Editorial update. No change to obligations.
- 2.0 (2026-09-04): Scope and sub-processor update.
- 1.1 (2026-06-19): Editorial update.
- 1.0 (2026-02-13): Initial SCC Addendum (Module 2: Controller-to-Processor), with Transfer Impact Assessment (Annex IV).
Legal Basis: EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021
Module: Module 2 (Controller-to-Processor transfers)
Purpose: Enable lawful transfer of personal data from EEA/EU to third countries (specifically United States via Cloudflare) in compliance with GDPR Chapter V.
Integration: This SCC Addendum is incorporated by reference into the Data Processing Agreement as Annex A. In case of conflict between the DPA and the SCCs, the SCCs prevail with respect to international data transfers.
DISCLAIMER: This document does not constitute legal advice. The Standard Contractual Clauses are based on EU Commission Decision 2021/914. Modifications to the core Clauses (Section I-IV) are not permitted except as explicitly allowed. Parties should consult with legal counsel to ensure correct completion of Annexes and compliance with GDPR requirements.
Compliance Mapping:
- GDPR Article 46 (Transfers subject to appropriate safeguards) ✓
- GDPR Chapter V (Transfers of personal data to third countries) ✓
- EU Commission Decision 2021/914 (Standard Contractual Clauses) ✓
- Schrems II decision (CJEU Case C-311/18) - Transfer Impact Assessment included ✓
END OF DOCUMENT