Aquassi Ltd
Website: www.aquassi.co.uk
Effective Date: 1 July 2026
UK-US Data Bridge Policy
Introduction
Aquassi Ltd (“Aquassi”, “we”, “our”, or “us”) is committed to protecting the privacy, confidentiality, and security of all personal information entrusted to us.
This UK-US Data Bridge Policy explains how we transfer personal data internationally, including transfers from the United Kingdom to organisations located in the United States under the UK Extension to the EU-US Data Privacy Framework (commonly known as the UK-US Data Bridge).
This policy should be read alongside our Privacy Policy, Cookie Policy and Terms & Conditions.
Our Commitment to Data Protection
Aquassi Ltd complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and all applicable UK privacy legislation.
Whenever personal information is transferred outside the United Kingdom, we ensure appropriate safeguards are in place to protect your information.
What is the UK-US Data Bridge?
The UK-US Data Bridge is the UK Extension to the EU-US Data Privacy Framework (DPF).
It allows UK organisations to transfer personal data to participating US organisations that have self-certified with the US Department of Commerce and continue to comply with the Data Privacy Framework Principles.
This mechanism has been recognised by the UK Government as providing an adequate level of protection for eligible transfers.
When We Use the UK-US Data Bridge
Aquassi Ltd may use trusted third-party providers located in the United States for services including:
- Website hosting
- Cloud storage
- Email communications
- Customer support software
- Marketing platforms
- Analytics
- Security monitoring
- Payment technologies
- Business productivity software
Where these providers participate in the UK-US Data Bridge, personal information may be transferred under that legal mechanism.
Where a US provider is not certified under the UK-US Data Bridge, we use alternative safeguards permitted under UK GDPR, including Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or other approved transfer mechanisms.
UK-US Data Bridge Transfer Mechanism
Where applicable, Aquassi Ltd relies upon the UK Extension to the EU-US Data Privacy Framework as the lawful transfer mechanism for transferring personal information from the United Kingdom to participating organisations within the United States.
Before transferring data, we undertake appropriate due diligence to confirm that relevant service providers maintain valid certification where required.
Participation and Certification Status
Aquassi Ltd is established in the United Kingdom and is not a US organisation eligible to self-certify under the EU-US Data Privacy Framework.
Instead, where we transfer personal data to United States organisations, we verify that those organisations have publicly self-certified compliance with:
- The EU-US Data Privacy Framework (EU-US DPF)
- The UK Extension to the EU-US Data Privacy Framework
as administered by the US Department of Commerce.
Only certified organisations may receive personal information under the UK-US Data Bridge.
Data Privacy Framework Principles
Where personal information is transferred under the UK-US Data Bridge, participating US organisations must comply with the Data Privacy Framework Principles, including:
Notice
Individuals are informed how their information is collected, used and shared.
Choice
Individuals are given meaningful choices regarding certain uses and disclosures of their personal information.
Accountability for Onward Transfer
Organisations remain responsible when transferring personal information to third-party processors.
Security
Reasonable and appropriate technical and organisational measures must protect personal data against loss, misuse, unauthorised access, disclosure or destruction.
Data Integrity and Purpose Limitation
Personal information must be relevant, accurate, complete and processed only for compatible purposes.
Access
Individuals have rights to access, correct, amend or delete their personal information where appropriate.
Recourse, Enforcement and Liability
Organisations must provide independent dispute resolution mechanisms and remain accountable for compliance.
Sensitive Personal Data
Aquassi Ltd does not intentionally collect special category personal data unless necessary for a specific service or legal obligation.
Where special category data is processed—including information relating to health, racial or ethnic origin, religious beliefs, sexual orientation, biometric information or similar categories—it is treated as sensitive personal information in accordance with UK GDPR and, where transferred under the UK-US Data Bridge, the Data Privacy Framework Principles.
Additional safeguards are applied where required.
Onward Transfers
Where a participating US organisation shares personal information with another third-party processor or subcontractor, that organisation must:
- transfer data only for specified purposes;
- ensure equivalent levels of protection;
- require contractual compliance with the Data Privacy Framework Principles; and
- remain liable if the third-party processes personal information inconsistently with those Principles unless it proves it was not responsible for the event giving rise to the damage.
Aquassi Ltd expects all service providers to maintain these standards.
Security Measures
We implement appropriate technical and organisational security measures, including:
- SSL/TLS encryption
- Secure hosting environments
- Role-based access controls
- Strong password policies
- Multi-factor authentication where appropriate
- Regular software updates
- Firewall protection
- Malware detection
- Secure backups
- Staff confidentiality obligations
These safeguards are designed to minimise the risk of unauthorised access, accidental loss or misuse.
Your Rights
Depending on applicable law, individuals may have the right to:
- access personal information;
- request correction of inaccurate data;
- request deletion of personal information;
- restrict processing;
- object to processing;
- request data portability;
- withdraw consent where processing relies upon consent;
- complain to the UK Information Commissioner’s Office (ICO).
Complaints and Independent Recourse
If you have concerns regarding our handling of personal information, please contact Aquassi Ltd in the first instance.
Where personal information has been transferred under the UK-US Data Bridge, complaints concerning participating US organisations should first be directed to that organisation.
Certified US organisations are required to provide an independent recourse mechanism that investigates unresolved complaints free of charge to the individual.
Where applicable, certified organisations may also commit to cooperating with the UK Information Commissioner’s Office (ICO) regarding unresolved complaints relating to human resources or other qualifying data.
Binding Arbitration
Where complaints cannot be resolved through the relevant organisation, the independent dispute resolution provider, or applicable regulatory authorities, eligible individuals may have the right to invoke binding arbitration under Annex I of the EU-US Data Privacy Framework.
Binding arbitration is available only under specific circumstances after other dispute resolution procedures have been exhausted.
US Regulatory Oversight
United States organisations certified under the EU-US Data Privacy Framework and the UK Extension are subject to the investigatory and enforcement powers of either:
- the US Federal Trade Commission (FTC); or
- the US Department of Transportation (DOT),
depending on the organisation’s regulatory jurisdiction.
Aquassi Ltd will seek to engage only with providers maintaining compliance with these regulatory requirements where applicable.
Third-Party Service Providers
Examples of third-party providers may include:
- website hosting providers;
- cloud infrastructure services;
- payment processors;
- customer relationship management systems;
- marketing automation platforms;
- analytics providers;
- communication platforms;
- email service providers;
- security monitoring services.
Our list of service providers may change as our business develops.
Changes to This Policy
We may update this UK-US Data Bridge Policy from time to time to reflect changes in legislation, regulatory guidance or business practices.
The latest version will always be published on our website.
Contact Us
Aquassi Ltd
Website: www.aquassi.co.uk
For any questions regarding this policy or international data transfers, please contact us using the contact information published on our website.
Last Updated: 1 July 2026