International Data Transfers

Version 1.0 Effective: 21 July 2026 Last updated: 21 July 2026

This page describes where data is stored, where it may be accessed from, and what legal mechanisms ensure your data is protected when it crosses borders outside the EU/EEA.

1. Data Storage Location

All customer data is stored in the EU.

The AB-Labz platform runs on DigitalOcean infrastructure located in Frankfurt, Germany (European Union). Customer Workspace data, Experiment Data, and account information are stored on servers in Frankfurt.

2. Transfer to Serbia (Operator Access)

AB-Labz is operated by a sole proprietorship registered in the Republic of Serbia. The operator may access production systems administratively (e.g., for maintenance, support, and incident response) from Serbia.

Serbia does not currently have an EU adequacy decision under GDPR Article 45. Administrative access from Serbia therefore constitutes a transfer to a third country under GDPR Chapter V.

Safeguard applied: Standard Contractual Clauses (SCC) issued by the European Commission — Module 2 (Controller to Processor), covering the transfer from the Customer (EU controller) to AB-Labz (non-EU processor).

3. Transfers to US-Based Sub-processors

Some sub-processors are based in the United States:

Sub-processor Data transferred Safeguard
Postmark (Wildbit) Recipient email address, name (transactional emails) SCC
OpenAI Aggregated analysis results (AI insights feature) SCC + OpenAI Enterprise DPA (zero data retention via API)
Google Analytics Anonymized website visitor data (marketing site only) SCC + IP anonymization

Google Analytics is used exclusively on the marketing website (ab-labz.com) and not within the Workbench platform. Raw Experiment Data is never transferred to Google.

4. Standard Contractual Clauses

AB-Labz relies on the Standard Contractual Clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) as the legal basis for transfers to non-adequate third countries.

Customers may request a copy of the applicable SCCs by contacting [email protected]. For large customers, countersigned SCCs are available as part of the procurement package alongside the DPA.

5. Transfer Impact Assessment

AB-Labz has assessed the risks associated with international transfers. Key mitigating factors include:

  • Data stored in the EU; Serbia access is administrative and limited to authorized personnel.
  • Experiment Data is pseudonymized or aggregated before submission (required by AUP).
  • API data is automatically deleted after 14 days.
  • OpenAI API does not retain input data or use it for model training.
  • All system access is logged and subject to access controls.

6. Runner (Self-hosted) Mode

Customers using the Corporate Self-hosted tier process Experiment Data entirely within their own infrastructure. No raw Experiment Data is transmitted to AB-Labz servers. International data transfer considerations do not apply to Runner data. Only license validation and workspace configuration data is exchanged with AB-Labz infrastructure.

7. Contact

For questions about international transfers or to request SCC documentation, contact [email protected].