The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
Appcues is an AI-powered customer engagement platform that triggers in-app, email, and push experiences right when users are paying
For each regulation, how many of the requirements it places on your vendors Appcues’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
16 documents listed on Appcues’s trust centre
trust.appcues.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where are your servers located?
“Appcues hosting environments are operated by Amazon Web Services as follows: US - Oregon, USA EU - Frankfurt, Germany”
Regions named: EU, US, Germanyas of 21 Sep 2026Source
International data transfers
Does Appcues do a Transfer Impact Assessment (TIA)?
“Appcues does not conduct TIAs. Any impact will depend on what data customers choose to send us. Please refer to our subprocessors page which describes how Appcues will transfer data onward.”
Regions named: USas of 21 Sep 2026Source
Encryption
Do you encrypt data at rest?
“All Appcues services and data are protected with strong encryption at rest, using AWS KMS and AES-256.”
as of 21 Sep 2026Source
Encryption
Do you encrypt data in transit?
“All Appcues services and data are protected with strong encryption in transit, using TLS 1.2 and above.”
as of 21 Sep 2026Source
Use of customer data to train models
Does Appcues use data to train AI models?
“No. Appcues does not use customer or end-user data to train AI models. Appcues AI features, such as draft content suggestions or language translation, are based only on information that customers choose to provide. End-user data is not used for AI training or generation. Any draft AI content is optional, reviewed and approved by customers, and not automatically shown to end-users.”
as of 21 Sep 2026Source
Penetration testing
Can you share details of the findings of your pen test?
“Due to confidentiality obligations with our customers, we can not share the specific details of any findings reported by a third party. If you would like to discuss specific findings, Appcues can provide written guidelines for conducting your own pen test assessment of the Appcues platform. Appcues will track and communicate the status of any reported vulnerabilities according to our vulnerability disclosure policy.”
as of 21 Sep 2026Source
Data retention and deletion
What is the data retention policy?
“Since Appcues uses data for core functionality of the product, data is retained for the life of the contract with the customer. Data is deleted upon request from the customer, or in accordance with the EU’s GDPR law. Deletion requests should be sent to [email protected]”
as of 21 Sep 2026Source
Data retention and deletion
What is your data retention period?
“Appcues does not have a data retention window. By default, data sent to Appcues will be retained indefinitely. This is necessary because of the nature of the Appcues product. If a user sees a flow that is configured to only display to the user once, Appcues needs to remember that the user has already seen the flow, so that we don't show the flow to that user again. If we allowed data to expire out of our platform,...”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.