Skip to main content
Freshworks logo

Freshworks

GDPR evidence

freshworks.comCRMLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Freshworks and GDPR

CertReports found no public GDPR evidence for Freshworks as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
28 Feb 2017
Expires or valid through
12 Nov 2026
Scope
As a Software-as-a-Service (SaaS) company, we provide solutions to a global customer base. To deliver our services effectively, we process personal data on behalf of our customers and collaborate with select third-party service providers (sub-processors). Below, we outline the scope, purpose, and context of data processing under our Data Privacy Framework compliance. What Data We Process We process personal data that is necessary to provide our services. This data may include, but is not limited to: · User Identification Data: Names, email addresses, and other contact details. · Usage Data: System activity logs, metadata, and preferences related to the use of our platform. · Customer Data: Information submitted, stored, or shared by our customers while using our platform. The specific categories of data processed depend on how our customers use our platform. Why We Process Personal Data We process personal data to: · Deliver Our Services: Enable platform functionality, manage accounts, and ensure seamless operation of our solutions. · Support and Improve Services: Troubleshoot issues, provide technical support, and enhance user experiences. · Compliance and Security: Detect, prevent, and mitigate fraudulent activity, unauthorized access, and legal risks. How We Process Data Personal data is processed securely within our systems using industry-standard security measures. We follow privacy-by-design principles to limit data access to authorized personnel and only process data for legitimate purposes in compliance with applicable laws and regulations. More details can be found here: https://www.freshworks.com/technical-organisational-measures/ Sharing Data with Sub-Processors To deliver and improve our services, we share personal data with carefully selected third-party service providers who perform specific functions on our behalf. These sub-processors may include: · Cloud Hosting Providers: For secure data storage and operational infrastructure. · Communication Platforms: For email, messaging, and customer support. · Analytics and Performance Monitoring Tools: To track system performance and usage trends. · Payment Processors: For managing billing and transactions. A detailed list per solution can be found here: https://www.freshworks.com/privacy/sub-processor/ All sub-processors are contractually obligated to safeguard personal data in accordance with our privacy and security standards, as well as applicable laws. A full list of sub-processors is available upon request. Data Transfers We comply with relevant data transfer mechanisms, such as the Data Privacy Framework, to ensure personal data is protected when transferred outside its region of origin. This includes adherence to recognized safeguards like Standard Contractual Clauses (SCCs) and binding corporate rules where applicable. If you have any questions about our data processing practices, please contact us at [email protected] or [email protected]. Data Processing of Employee Data as a Controller under the Data Privacy Framework In addition to processing customer data, we also act as a data controller for the personal data of our employees. This section provides an overview of how and why we process employee data, the types of data we collect, and how it is shared. What Employee Data We Process We process personal data related to our employees for employment-related purposes. This data may include: · Identification and Contact Information: Name, address, email, phone number, and other contact details. · Employment Records: Job title, employment history, contract details, performance evaluations, and disciplinary records. · Payroll and Benefits Information: Social security numbers (or equivalent national identifiers), bank account details, salary information, tax information, and benefits enrolment data. · Workplace Data: Time and attendance records, system usage logs, and workplace productivity metrics. · Health and Safety Information: Medical leave details, disability accommodations, or incident reports, as required by law. Why We Process Employee Data We process employee data for legitimate business purposes and to fulfill our legal obligations, including: · Employment Management: Administering payroll, benefits, performance reviews, promotions, and internal communications. · Legal Compliance: Meeting obligations under labour, tax, and workplace safety laws. · Operational Purposes: Managing schedules, monitoring workplace productivity, and maintaining internal IT systems. · Security and Fraud Prevention: Ensuring the safety of our employees and protecting company assets. How We Process Employee Data Employee data is processed securely and used only for authorized purposes. Access is limited to internal HR, payroll, and IT teams, as well as other relevant personnel on a need-to-know basis. Appropriate technical and organizational measures are implemented to protect this data from unauthorized access, loss, or misuse. Sharing Employee Data with Third Parties We may share employee data with select third-party service providers and external entities in the following circumstances: · Payroll and Benefits Providers: For processing payments and managing employee benefits (e.g., payroll processors, insurance providers). · IT and Systems Providers: For the provision of internal communication, collaboration tools, and IT system maintenance (e.g., Microsoft, Google Workspace). · Legal and Regulatory Authorities: To comply with applicable laws, legal requests, or audits. · Background Check and Compliance Services: Where applicable, during the hiring process or for legal compliance (e.g., background check providers). All third parties are contractually bound to handle employee data in compliance with our privacy standards and applicable laws. International Data Transfers In cases where employee data is transferred across borders, we rely on approved safeguards under the Data Privacy Framework, such as Standard Contractual Clauses (SCCs), to ensure an equivalent level of data protection. Retention of Employee Data Employee data is retained only for as long as necessary to fulfill its purpose and comply with legal obligations. Once data is no longer required, it is securely deleted or anonymized. If employees have questions about how their personal data is processed or wish to exercise their rights, they can contact [email protected] or [email protected].
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Freshworks, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 7a21a65c2d
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Freshworks GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the CRM category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No CRM vendor has GDPR evidence in the index yet.