# EU/EEA Vendor Policy — Total Chaos

This document defines Total Chaos' approach to selecting third-party service providers (subprocessors, vendors, and tools). It is **internal guidance**, not a legal contract or guarantee of compliance.

## Principles

1. **Prefer EU/EEA-owned providers** — Companies headquartered and primarily operated within the EU/EEA.
2. **Prefer EU/EEA-hosted data** — Data stored on servers physically located in the EU/EEA.
3. **Prefer EU/EEA support and legal jurisdiction** — Support staff and legal disputes governed by EU/EEA law.
4. **Prefer minimal data processing** — Collect only what is necessary. Static-first architecture reduces vendor dependencies.
5. **Prefer self-hosted/static solutions** — Where practical, avoid third-party services entirely.
6. **Avoid unnecessary US/non-EEA processors** — Non-EU tools are used only as documented exceptions.
7. **Review DPAs before production use** — Every active subprocessor must have a reviewed Data Processing Agreement (or equivalent contractual safeguard) before personal data is transferred.
8. **Track and publish** — All subprocessors are listed publicly on `/legal/subprocessors/` with status, location, and data categories.

## Vendor Classification

| Status | Meaning |
|--------|---------|
| `active` | Currently in use and processing data. |
| `planned` | Intention to use; evaluation or contract negotiation in progress. |
| `under-evaluation` | Being researched and compared against EU/EEA alternatives. Not yet decided. |
| `avoid` | Deliberately not used. Non-EU/EEA tool with no compelling justification. |
| `exception-required` | Non-EU/EEA tool that may be used only if a documented exception is approved (e.g., no EU alternative, specific business need, DPA + SCCs in place). |

## Geography Classification

| Region | Meaning |
|--------|---------|
| `EU/EEA` | Provider owned and primarily operated in the EU/EEA. Data hosted in the EU/EEA. |
| `Adequacy country` | Country recognized by the European Commission as providing an adequate level of data protection (e.g., UK, Switzerland, select others). |
| `Non-EU/EEA` | Provider based outside the EU/EEA and not in an adequacy country. Transfers require SCCs or other safeguards. |
| `Unknown / needs verification` | Ownership, hosting location, or legal jurisdiction not yet confirmed. Must be verified before use. |

## EU/EEA Vendor Review Checklist

Before engaging any new provider, we ask:

- [ ] Who owns the company? (Headquarters, legal entity)
- [ ] Where is data hosted? (Server location, data residency options)
- [ ] Where can support staff access data from? (Support locations, subcontractor locations)
- [ ] Is there a DPA available? (Data Processing Agreement or standard contractual terms)
- [ ] Are subprocessors listed? (Who else has access to the data)
- [ ] Are non-EEA transfers involved? (If yes, what safeguards are in place)
- [ ] Can data residency be configured? (EU-only hosting option)
- [ ] Is there a retention/deletion process? (How long data is kept, how it is deleted)
- [ ] What is the transfer risk level? (Low = EU-only; Medium = adequacy country; High = non-EU with SCCs)
- [ ] Has the DPA been reviewed by someone with data-protection knowledge?

## Non-EU Exception Policy

A non-EU/EEA provider may be considered only if:

1. No practical EU/EEA alternative exists for the specific function.
2. The business need is documented and approved.
3. A DPA (and SCCs if required) is executed before any personal data is transferred.
4. The transfer risk is documented and periodically reviewed.
5. The provider is listed on our public Subprocessors page with full transparency.

## Current Exceptions (None Active)

No non-EU/EEA subprocessors are currently active. All non-EU tools listed on our Subprocessors page are either `avoid`, `under-evaluation`, or `exception-required` and are **not configured**.

## Review Cycle

This policy and the subprocessor list will be reviewed:
- Before any new provider is engaged
- Before launching software sales
- At least annually thereafter
- Whenever a material change to an existing provider occurs
