When you use Gleap, you are the data controller, and Gleap is the processor: you decide what customer data is collected, and Gleap processes it on your instructions.
This page points to the documents that say so, and to the ones procurement usually asks for.
The DPA is the agreement that makes the above binding. It's published on Gleap's site, and it carries the two annexes people actually need: the technical and organisational measures, and the sub-processor list.
Most reviews are satisfied by the published document. If yours needs a signed copy, ask.
The full list is on Gleap's trust pages, grouped by what each provider does — hosting, email delivery, real-time infrastructure, billing, monitoring, and the AI providers. Each entry names the company, its country, and where it processes.
Under the DPA, engaging a sub-processor beyond that annex requires your written consent, and you're entitled to inspect sub-processors. To be told when the list changes, email [email protected] and ask to be notified.
This is what most reviews now focus on, so the specifics matter.
AI providers only process data when AI features are actively used, and those features can be disabled entirely. The providers are listed individually on the sub-processors page, with their locations — not as “an AI provider”.
Under Gleap's agreements with them, they are contractually prohibited from using submitted data to train or improve their models.
If a review can't accept processing outside the EU, note that the list includes EU-hosted providers — worth discussing rather than assuming AI is all-or-nothing.
Gleap is SOC 2 Type II audited. The current report is available on request from [email protected].
Personal data breaches are reported to affected customers immediately on becoming aware, with the nature of the breach, the data categories involved, a contact point and the measures taken — the detail you need to meet your own notification deadlines.
As controller, some obligations stay with you whatever Gleap does:
Telling your users that you use Gleap, in your own privacy policy.
Deciding what your product sends — attributes, replays, network logs. Masking is yours to configure.
Handling access and deletion requests from your users, which you can do from the contact page.
Gleap's data protection officer can be reached at [email protected] for anything a questionnaire doesn't cover.