
10000ft and GDPR
CertReports found no public GDPR evidence for 10000ft as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 26 May 2018
- Expires or valid through
- 27 May 2027
- Scope
- As a service provider, we collect data from our customers and other individuals who may visit our websites or otherwise interact with Smartsheet, that may include personal data that has originated or relates to individuals residing in the EU, United Kingdom or Switzerland in two ways: Customer Content our customers upload or submit to the Smartsheet Online Services (for which Smartsheet acts as a data processor) and other personal data that is provided to or collected by Smartsheet in relation to the websites, individuals’ interactions with Smartsheet or the provision of the Online Services (for which Smartsheet acts as a data controller). Personal data for which we act as a data controller includes login credentials, contact information, user’s name, company name, permissions, system usage data, and other similar user data or data gathered directly or automatically from website visitors, event attendees, and other individuals; this data is used to facilitate customers’ access to Customer Content, for related customer service purposes, and for Smartsheet's legitimate business purposes including analytics and improvement of the Online Services, customer engagement and marketing. With respect to Customer Content, the categories of personal data that may be processed within the Online Services are determined and controlled by our customers (the data controllers) in their sole discretion. Smartsheet does not assess, audit, block or otherwise control the Content that our customers upload, share, access, or otherwise process within the Online Services. Smartsheet retains limited rights to access Customer Content to provide the Online Services, to respond to customer support requests, to prevent fraud, abuse, and violations of our policies and agreements, or as otherwise required by law. We use service providers and need to share personal data with them, to administer services made available to all Smartsheet customers, for customer support purposes, and as otherwise required to manage the customer relationship. Where these service providers process the Customer Content customers choose to upload or submit to our Online Services, they must meet applicable Smartsheet due diligence requirements for service providers and/or subprocessors of Customer Content as disclosed on our Subrocessor page.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Smartsheet Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 cf7ca0f00d |
- Kind
- listing
- Scope
- 10,000ft may receive personal data from the EEA as a provider of its online resource management service. With respect to all data (including personal data) transferred using its services, 10,000ft is the processor and our customers are the data controllers/exporters. The data controller customer may use 10,000ft’s service to store, modify, share, distribute, disclose, and delete information, including personal data (e.g. name, phone number, company position, and other related information). The categories of data subjects whose personal data may be transferred are determined and controlled by the data exporter/controller (the 10,000ft customer) in its sole discretion. 10,000ft’s service does not impose any limits on the categories of data subjects who may be identified and Smartsheet does not review, monitor or modify any of the data uploaded by data controllers in its provision of the online service. 10,000ft applies the same level of protection to all content uploaded to the services, including any personal data incorporated therein.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | 10000ft: Inactive | Live pagesha256 ca8da79a4b |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is 10000ft GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Project management category) whose GDPR row is verified or vendor-stated, ranked by similarity.