Skip to main content
Directly logo

Directly

GDPR evidence

directly.comCustomer supportLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Directly and GDPR

CertReports found no public GDPR evidence for Directly as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
13 Apr 2018
Scope
The personal data we collect depends on a user's specific interactions with our website and platform. We receive personal and other data directly from the user, for example, when a user creates a Directly account to become an expert, completes a form, or sends us an email or other communication. We may also collect personal data by recording interactions with our website or platform. The collection and use of personal data from a variety of sources is essential to our ability to provide the platform and related services – and to help keep it reliable and secure. Specifically, we and our authorized third party providers use personal data to (i) provide our platform; (ii) promote, analyze and improve our platform and related services; (iii) detect and prevent fraud, harmful or abusive conduct or other harm to users, corporate customers and Directly. Examples of how we may use personal data include: · to create a Directly account, · to identify a user on our system, to ensure the security of our platform and services and enable a user to send or respond to task, · to respond to user requests, to administer and improve our website and platform, · to inform a customer of relevant activity and use of the platform in the aggregate · to provide technical support and respond to inquiries by users, · to solicit feedback to improve and customize the user experience, · to inform users about new features, services, and programs, · to customize use of the platform and/or content or other material · to conduct aggregate analysis and develop business intelligence that enable us to operate, make informed decisions, and improve and report on the performance of our business, · For audits and assessments, regulatory purposes, or compliance with industry standards and customer requirements, · to prevent or take action against activities that may be in breach of our Terms, Privacy Policy or applicable law · for any other purpose, provided we disclose this to users at the relevant time, and provided that users agree to the proposed use of personal data. Directly does not sell or rent personal data to marketers or unaffiliated third parties. We share personal data collected by Directly with third party providers only in limited circumstances, including: (i) with consent; (ii) to an authorized third-party provider who meets data protection standards; or (iii) when we have a good faith belief it is required by law, such as pursuant to a subpoena or other legal process, or to enforce our Terms. We also share data with certain third party providers who help us provide the website, platform and related services. For example, certain third party providers help us with such activities as web-hosting and data analysis. Currently, we use Amazon, for hardware, software, networking, and storage services which are necessary to operate our website, platform and related services. We may also share data with users (and other third-party providers, such as merchants and application providers) as necessary to process payments or provide aspects of the platform and services. Such providers are prohibited from using personal data other than to provide the services specified under written contract by Directly and for no other purposes.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Directly, Inc.: Inactive
Live pagesha256 2c1f3cc664
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Directly GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Customer support category) whose GDPR row is verified or vendor-stated, ranked by similarity.