International Data Transfers
How ETS Labs lawfully transfers personal data from the European Economic Area, the United Kingdom, and Switzerland to the United States. This policy replaces our former Safe Harbor policy.
ETS Labs is a division of Etech Global Services, LLC
1903 Berry Drive, Nacogdoches, TX 75964, United States
Attention: Privacy Office
Email: privacy@qeval.ai | security@etechgs.com
ETS Labs collects, uses, and discloses personal information in a manner consistent with the laws of the countries in which it does business. This page explains the legal safeguards ETS Labs applies when personal data is transferred from the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland to the United States. It supersedes our former Safe Harbor Privacy Policy. The EU-US Safe Harbor Framework was invalidated by the European Court of Justice in October 2015 (Schrems I), and its successor, the EU-US Privacy Shield, was invalidated in July 2020 (Schrems II). Cross-border transfers are now governed by the mechanisms described below.
1. Scope
This policy applies to all personal data that ETS Labs receives in the United States from the EEA, the UK, and Switzerland, in any format, whether electronic, paper, or verbal. It covers:
- Personal data of website visitors, marketing contacts, and job applicants who are located in the EEA, UK, or Switzerland
- Personal data that enterprise clients transfer to ETS Labs for processing through the QEval® platform under a Data Processing Agreement
For information on how the QEval® platform handles customer conversation data, PCI redaction at ingest, and our security certifications, see our Security and Trust page. For general website privacy practices, see our Privacy Policy.
2. Where data is stored
ETS Labs hosts all QEval® platform data in Amazon Web Services data centers located in the United States (AWS US East regions). Platform data is not transferred outside the United States at any stage of the analytical lifecycle. The transfer mechanisms described in this policy govern the lawful movement of personal data from the EEA, UK, and Switzerland to ETS Labs's US infrastructure. ETS Labs does not transfer personal data onward from the United States to other jurisdictions, except to the limited set of subprocessors listed at trust.etslabs.ai, each of which is bound by contractual data protection obligations at least as protective as this policy.
3. Transfer mechanisms
ETS Labs relies on the following lawful transfer mechanisms, used individually or in combination depending on the nature of the data and the parties involved.
- Standard Contractual Clauses (SCCs). ETS Labs uses the European Commission's June 2021 Standard Contractual Clauses as the primary contractual safeguard for all transfers from the EEA, UK, and Switzerland to the United States. The applicable module is selected based on the roles of the parties: Module 2 (controller-to-processor) applies where an EU-based client is the data controller and ETS Labs is the processor; Module 3 (processor-to-sub-processor) applies for transfers to our subprocessors. The UK International Data Transfer Addendum is appended for transfers originating in the UK. ETS Labs maintains SCCs as a standing backup safeguard for all transfers, including those that also rely on the Data Privacy Framework, so that a valid mechanism remains in place regardless of changes in the framework's legal status.
- EU-US Data Privacy Framework (DPF). If ETS Labs is registered on the EU-US Data Privacy Framework list at dataprivacyframework.gov, state: "ETS Labs is certified under the EU-US Data Privacy Framework, pursuant to the adequacy decision adopted by the European Commission in July 2023, and under the UK Extension and Swiss-US Data Privacy Framework extensions." If ETS Labs is not registered, remove this card entirely and rely on SCCs as the sole transfer mechanism. Publishing an unconfirmed DPF claim constitutes a deceptive practice under FTC Section 5.
- UK International Data Transfer AddendumFor transfers of personal data originating in the United Kingdom, ETS Labs supplements the EU SCCs with the UK International Data Transfer Addendum (IDTA) issued by the UK Information Commissioner's Office, as required under the UK GDPR and the Data Protection Act 2018.
- Swiss Federal Act on Data Protection For transfers originating in Switzerland, ETS Labs relies on the Swiss-US Data Privacy Framework where applicable, supplemented by the Standard Contractual Clauses adapted for Swiss law requirements. Where the Swiss-US DPF is not available, ETS Labs relies on SCCs alone as the primary safeguard.
A Data Processing Agreement incorporating the applicable SCCs and transfer addenda is available to enterprise clients on request from privacy@qeval.ai | security@etechgs.com.
4. Principles we follow
Whichever transfer mechanism applies, ETS Labs commits to the following data protection principles. These principles carry forward from the Safe Harbor and Privacy Shield frameworks and are now embedded in the Data Privacy Framework and our Standard Contractual Clauses.
Notice
Where ETS Labs collects personal data directly from individuals in the EEA, UK, or Switzerland, it provides clear notice of the purposes for collection, the types of third parties to whom data may be disclosed, and the choices and means available for limiting use and disclosure. Notice is given at or before the time of collection, or as soon as practicable thereafter, and always before data is used for a materially different purpose.
Choice
ETS Labs offers individuals the opportunity to choose whether their personal data is disclosed to a third party acting outside ETS Labs's instructions, or used for a purpose materially different from the purpose for which it was originally collected. For sensitive personal data, ETS Labs obtains affirmative and explicit opt-in consent before any such disclosure or alternative use.
Accountability for onward transfer
When ETS Labs transfers personal data to subprocessors acting on its behalf, it does so under written contract. Those contracts require the subprocessor to provide at least the same level of protection required by this policy and by the applicable SCCs. ETS Labs remains accountable for processing carried out by its subprocessors. A current list of subprocessors is published at trust.etslabs.ai.
Security
ETS Labs takes reasonable and appropriate technical and organizational measures to protect personal data from loss, misuse, unauthorized access, disclosure, alteration, and destruction. These measures include AES-256 encryption at rest, TLS 1.2 or higher in transit, role-based access control, multi-factor authentication, and annual third-party penetration testing. Full details are at trust.etslabs.ai.
Data integrity and purpose limitation
ETS Labs uses personal data only in ways compatible with the purposes for which it was collected or subsequently authorized. ETS Labs takes reasonable steps to ensure personal data is relevant, accurate, complete, and current, and retains it only for as long as it serves those purposes, consistent with the retention schedule in our Privacy Policy.
Access
Upon verified request, ETS Labs grants individuals reasonable access to the personal data it holds about them and reasonable means to correct, amend, or delete data shown to be inaccurate or incomplete, subject to the limits permitted by law. See the Access and rights section below for how to submit a request.
Recourse, enforcement, and liability
ETS Labs conducts internal compliance reviews to verify adherence to this policy and provides recourse for individuals affected by non-compliance. Any employee found to have intentionally violated this policy is subject to disciplinary action up to and including termination. For complaints that cannot be resolved internally, ETS Labs cooperates with the relevant supervisory authority and any independent recourse mechanism applicable to the transfer. See the Recourse and enforcement section below.
5. Sensitive personal data
Sensitive personal data means information that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, sex life or sexual orientation, or other categories treated as sensitive under applicable law. ETS Labs treats as sensitive any information that a customer or third party identifies and provides to us as sensitive.
ETS Labs obtains affirmative, explicit opt-in consent before disclosing sensitive personal data to any third party acting outside its instructions, or before using it for a purpose materially different from the purpose for which it was originally collected.
Where QEval® processes call recordings that may incidentally contain sensitive data (for example, a caller disclosing health information during a customer service interaction), such data is handled under the client's Data Processing Agreement and subject to ETS Labs's PCI and PHI redaction controls as described in our Privacy Policy.
6. Onward transfers to subprocessors
ETSLabs engages a limited number of subprocessors to support platform operations. Each subprocessor is subject to a written data processing agreement requiring at least the same level of protection as this policy. Where ETSLabs learns that a subprocessor is using or disclosing personal data contrary to this policy or its contractual obligations, ETSLabs takes prompt steps to prevent or stop the use or disclosure and, where necessary, terminates the subprocessor relationship.
The current subprocessor list is published and kept up to date at trust.etslabs.ai. Enterprise clients who have executed a Data Processing Agreement are notified of material changes to the subprocessor list in advance, consistent with their agreement's notice-and-object provisions.
7. Access and individual rights
Individuals whose personal data ETS Labs holds as a controller may request:
- Access to the personal data ETS Labs holds about them
- Correction or amendment of inaccurate or incomplete data
- Deletion of data where ETS Labs no longer has a legitimate purpose for retaining it
- Restriction of processing in defined circumstances
ETS Labs reserves the right to verify the requester's identity before acting on any request. Requests may be submitted to privacy@qeval.ai | security@etechgs.com. ETS Labs will acknowledge requests within 48 hours and respond within 30 calendar days.
For personal data that ETS Labs processes as a processor on behalf of an enterprise client, data subject requests should be directed to the relevant client as the data controller. Where a data subject contacts ETS Labs directly about platform data, ETS Labs will promptly route the request to the appropriate client controller.
8. Security
ETS Labs maintains a documented information security program with technical, physical, and administrative safeguards designed to protect personal data in its possession. Platform-level certifications include SOC 2 Type II, ISO 27001:2022, HIPAA, and PCI DSS. Security reports and certifications are available to enterprise clients under NDA at trust.etslabs.ai. In the event of a personal data breach, ETS Labs notifies the relevant supervisory authority within 72 hours where required by law and notifies affected enterprise clients within 24 hours of detection.
9. Recourse and enforcement
Questions or concerns about the use or disclosure of personal data under this policy should be directed to the ETS Labs Privacy Office at the address below. ETS Labs will investigate and attempt to resolve complaints in accordance with the principles in this policy within 30 days of receipt.
If a complaint cannot be resolved directly, ETS Labs will cooperate with the applicable supervisory authority and any independent recourse mechanism. Depending on the transfer mechanism in use:
- For SCC-based transfers, individuals may file complaints with the relevant EU or UK supervisory authority.
- For DPF-certified transfers (if applicable), individuals may invoke the DPF's binding arbitration mechanism and may file complaints with the US Department of Commerce or the Federal Trade Commission.
- For Swiss transfers, individuals may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
10. Limitations
Adherence to the principles in this policy may be limited to the extent required or permitted by applicable law or legal process, including to respond to a lawful request from public authorities, to meet national security or law enforcement requirements, or to the extent expressly permitted by an applicable law, rule, or regulation. ETS Labs will notify affected individuals of such limitations to the extent permitted by law.
11. Changes to this policy
ETS Labs may amend this policy from time to time, consistent with the requirements of applicable data protection law and the terms of the transfer mechanisms in use. When this policy is changed in a material way, ETS Labs will update the effective date at the top of this page and post a notice. Enterprise clients with active Data Processing Agreements will be notified of material changes through the notice provisions of those agreements.
12. Contact
Email: privacy@qeval.ai | security@etechgs.com
Tel: +1 936-559-2258
ETSLabs (a division of Etech Global Services, LLC)
Attention: Privacy Office
1903 Berry Drive, Nacogdoches, Texas 75964, United States