Skip to main content
ENTANDO logo

ENTANDO

GDPR evidence

entando.comNo-code and automationLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

ENTANDO and GDPR

CertReports found no public GDPR evidence for ENTANDO as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
6 Apr 2017
Expires or valid through
13 Mar 2027
Scope
The purpose of data collection is collect Personal Information. The Data Controller will use data for the following purposes: management of the contractual relationship and the provision of software services and other services purchased by the customer and as described on http://www.entando.com or other informative or contractual material of Entando. Personal Data will be processed for the following purposes: establishment, management and termination of the contractual relationship with Entando; fulfillment of accounting and tax obligations; fulfillment of legal obligations; anti-money laundering controls; audits for tax and accounting purposes; management of disputes; provision, support, updating and information regarding the services offered and the available features; activation of online services; training courses. Purposes related to marketing activities, email marketing. With specific consent, personal data will be processed for the following purposes: market research; economic and statistical analyses; social, cultural and solidarity initiatives; updating on training initiatives; email marketing and updates on initiatives, promotions and offers from Entando or third-party companies that operate in collaboration with the Data Controller; communications and information on the activities of the owner and on the events in which the owner takes part. Entando will carry out the treatment because: it is necessary for contractual obligations; to fulfill legal obligations to which Entando is subject; because the treatment is necessary to pursue a legitimate interest. With reference to the above, on the basis of express consent. Therefore, personal data are necessary or mandatory for the purposes listed. The purpose referred to, on the other hand, does not derive from a legal obligation or contract, and the consent to provide such data for such purpose is optional and does not affect provision of the services. Any partial or total failure to provide the data will result in the partial or total impossibility of achieving the aforementioned purposes. We will not use Personal Data for any other purpose other than those described, if not by informing in advance and, where necessary, obtaining consent. Data may be communicated to Entando partners to manage contracts in place, and to third parties, to fulfill obligations deriving from the law, regulations, community regulations or for aspects concerning the management and execution of the contractual relationship. Personal data will not be transferred to third parties for marketing purposes unless you have expressly permitted such transfer. For all the purposes indicated in this statement, data may be transferred abroad, inside and outside the European Union, in compliance with the rights and guarantees provided by the current legislation, subject to verification that the country in question ensures an “adequate” level of protection. The Data will also be processed by internal resources of Entando, which operate as authorized personnel to process the Data in accordance with art. 29 GDPR. All company emails will be kept through an outsourced archiving system with adequate security measures. Access to the archived Data may be carried out only by public authorities, in the cases and methods provided for by the laws in force, in the event of legal disputes. Personal data are not subject to dissemination. For service, massive or marketing communication purposes, email addresses will be included in a contact list managed by Entando through the email service offered by https://www.hubspot.com, of the company HubSpot, Inc. 25 First St., 2nd floor Cambridge, MA 02141 USA, to which such data are communicated. Hubspot has declared to be GDPR compliant. Find links to the GDPR Compliance Checklist at HubSpot.com. Hubspot is currently included in the Data Privacy Framework.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026ENTANDO INC.: Active: EU-US Certification
Live pagesha256 58d67a7ad2
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is ENTANDO GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the No-code and automation category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No No-code and automation vendor has GDPR evidence in the index yet.