Legal · GDPR

GDPR Transfer Pack.

Why international transfers happen, the mechanisms we rely on, and where your data may be processed.

Last updated · May 15, 2026

1 · Why international transfers happen

Rozper is headquartered in Hong Kong and operates a wholesale voice, UCaaS, and virtual-number platform that reaches 150+ countries. A global telecom network cannot stay inside a single jurisdiction — calls, messages, and account data routinely cross borders as part of how the Services function.

International transfers happen for a small number of concrete reasons:

  • Call and message routing. Voice traffic is handed off to interconnect and termination partners in the destination country or region, and SIP/SMS signalling metadata travels with it.
  • Regional storage and replication. To meet our 99.99% uptime commitment, call detail records, recordings, and configuration data are replicated across regional points of presence in the Americas, Europe, and Asia-Pacific.
  • Follow-the-sun support and engineering. Troubleshooting a live outage or a support ticket may require an engineer outside the customer's home region to access diagnostic logs for a limited time.
  • Sub-processor infrastructure. Cloud hosting, number-provisioning, and payment vendors we rely on operate their own global infrastructure footprints.

This pack exists so that EU and UK customers can see, in one place, the safeguards Rozper applies whenever personal data governed by the GDPR or UK GDPR leaves the EEA or UK. It is written for privacy and procurement teams who need to document a lawful transfer basis before signing off on a vendor, and it is kept current as our infrastructure footprint and partner list evolve.

None of this is unusual for a telecommunications provider — connecting a call from Berlin to Nairobi, or a virtual number in London to a mobile handset in Manila, always involves at least one hop outside the caller's home jurisdiction. What matters is that every such hop is backed by an appropriate legal mechanism and a proportionate set of technical safeguards, which is exactly what the rest of this page documents.

2 · Transfer mechanisms we rely on

Rozper layers multiple safeguards rather than depending on a single mechanism. Depending on the receiving country and the data flow, we rely on the following.

  • Standard Contractual Clauses (SCCs). We enter into the European Commission's 2021 modular SCCs (controller-to-processor and processor-to-processor modules, as applicable) with our contracting entity and with sub-processors handling EEA-originated personal data. Hong Kong does not currently benefit from an EU adequacy decision, so transfers into our Hong Kong-based infrastructure and support functions are covered by SCCs.
  • Adequacy considerations. Where a receiving country or territory is covered by a valid European Commission adequacy decision, we treat that as sufficient on its own and layer SCCs on top only where a sub-processor or contractual chain requires it for completeness.
  • Supplementary measures. Following the Schrems II line of guidance, we do not treat contractual clauses alone as sufficient. We pair them with technical and organisational measures: encryption of data in transit and at rest, role-based and least-privilege access controls, logging and monitoring of access to production systems, data minimisation in diagnostic tooling, and contractual audit and termination rights over sub-processors.

Full detail on the technical and organisational measures referenced above is maintained in our security documentation and can be requested alongside the SCC package described in Section 6. We review our transfer-impact assessments periodically and whenever we onboard a new sub-processor or open a new regional point of presence, so the mechanism in place for a given flow reflects the current state of our infrastructure rather than a document written once and left unchanged.

3 · UK International Data Transfer Addendum

For transfers subject to UK GDPR rather than EU GDPR, the EU SCCs alone are not a recognised transfer mechanism. Rozper incorporates the UK Information Commissioner's Office (ICO) International Data Transfer Addendum to the EU Commission's SCCs into our Data Processing Agreement, so UK customers get an equivalent safeguard without needing a separately negotiated document.

The Addendum is appended to, and read together with, the underlying EU SCC module that applies to the relevant data flow. Where a customer has already executed our DPA, the Addendum is deemed incorporated for any UK-originated personal data processed under that agreement.

4 · Where customer data may be processed or stored

The table below summarises, at a regional level, where customer data is typically processed or stored. It is a summary for planning purposes — the authoritative, sub-processor-level detail lives in our sub-processors list.

  • Asia-Pacific (primary region). Core platform infrastructure, number provisioning, and our Hong Kong headquarters process account, billing, and communications metadata for customers routed through this region.
  • European Union / EEA. Customers who pin their tenant to the EU have primary storage and processing kept within EU data centres, with call routing to in-region interconnect partners where available.
  • United Kingdom. UK-specific number ranges and certain support functions are served from UK-adjacent infrastructure, subject to the same regional-pinning option.
  • Americas. North American points of presence handle traffic and storage for customers and end users routed through the region.
  • Rest of world. For destinations outside the regions above, call termination necessarily involves local carrier partners in the destination country, consistent with how the public telephone network works everywhere.

Where technically supported, customers can request tenant pinning to a specific region; that pinning is enforced at the storage layer as described in our Privacy Policy. Pinning affects storage, not the destination-country routing inherent to placing or receiving a call in that country.

6 · Requesting the full signed SCC package

Customers and prospective customers can request a copy of the executed SCC modules, the UK Addendum, and our current transfer-impact assessment summary at any time. Two ways to reach us:

  • Email legal@rozper.com directly with your company name and the entity you have contracted with.
  • Submit a request through /contact/ and ask for the SCC package — our legal team will route it and follow up by email.

We typically respond within a few business days. Enterprise customers with specific SCC annex requirements (for example, customer-specific Annex I/II detail) can request a tailored version through the same channels.

7 · Frequently asked questions

Does Rozper transfer personal data outside the EEA? Yes. As a global telecom platform headquartered in Hong Kong with points of presence across 150+ countries, some processing of EEA and UK personal data outside those territories is inherent to the Services — most obviously, routing a call to its destination country.

What legal basis governs those transfers? Depending on the destination and data flow, we rely on European Commission adequacy decisions where available, Standard Contractual Clauses, and the UK International Data Transfer Addendum, layered with supplementary technical and organisational measures.

How do I get a copy of the signed SCCs? Email legal@rozper.com or use /contact/. See Section 6 above.

Can I keep my data in a single region? Where technically supported, yes — customers can request tenant pinning to the EU, UK, Americas, or Asia-Pacific region for storage. Destination-country call routing is not affected by pinning, since it depends on where the call is placed or received.

Does this pack cover sub-processors individually? No — for a named, per-vendor breakdown, see our sub-processors page, which this pack complements.

Questions? · legal@rozper.com