company logo

Help center

Go to Gleap
Privacy policyDocs
Powered by
All collectionsRun Gleap safelyGDPR, the DPA and sub-processors

GDPR, the DPA and sub-processors

What to send procurement, and what to tell your data protection officer.

Rami Magdi·August 31, 2026

When you use Gleap, you are the data controller, and Gleap is the processor: you decide what customer data is collected, and Gleap processes it on your instructions.

This page points to the documents that say so, and to the ones procurement usually asks for.

The Data Processing Addendum

The DPA is the agreement that makes the above binding. It's published on Gleap's site, and it carries the two annexes people actually need: the technical and organisational measures, and the sub-processor list.

Most reviews are satisfied by the published document. If yours needs a signed copy, ask.

Sub-processors

The full list is on Gleap's trust pages, grouped by what each provider does — hosting, email delivery, real-time infrastructure, billing, monitoring, and the AI providers. Each entry names the company, its country, and where it processes.

Under the DPA, engaging a sub-processor beyond that annex requires your written consent, and you're entitled to inspect sub-processors. To be told when the list changes, email [email protected] and ask to be notified.

info icon
Send the sub-processor page rather than an extract of it. It's kept current, so a copy-pasted into a spreadsheet is out of date the moment something changes.

The AI question

This is what most reviews now focus on, so the specifics matter.

AI providers only process data when AI features are actively used, and those features can be disabled entirely. The providers are listed individually on the sub-processors page, with their locations — not as “an AI provider”.

Under Gleap's agreements with them, they are contractually prohibited from using submitted data to train or improve their models.

If a review can't accept processing outside the EU, note that the list includes EU-hosted providers — worth discussing rather than assuming AI is all-or-nothing.

Certifications

Gleap is SOC 2 Type II audited. The current report is available on request from [email protected].

Breach notification

Personal data breaches are reported to affected customers immediately on becoming aware, with the nature of the breach, the data categories involved, a contact point and the measures taken — the detail you need to meet your own notification deadlines.

Your side of it

As controller, some obligations stay with you whatever Gleap does:

  • Telling your users that you use Gleap, in your own privacy policy.

  • Deciding what your product sends — attributes, replays, network logs. Masking is yours to configure.

  • Handling access and deletion requests from your users, which you can do from the contact page.

Gleap's data protection officer can be reached at [email protected] for anything a questionnaire doesn't cover.

Did this answer your question?
😞
😐
😁