Skip to main content
HashiCorp logo

HashiCorp

GDPR evidence

HashiCorp, Inc. is an American software company and subsidiary of IBM based in San Francisco, California

hashicorp.comCloud and hostingLast verified 29 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

HashiCorp and GDPR

CertReports found no public GDPR evidence for HashiCorp as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: UK Extension Certification, EU-US Certification, SW-US Certification
as of 29 Sep 2026 · confidence 100%
Kind
Listing
Issued or listed
26 May 2018
Expires or valid through
23 Oct 2026
Scope
HashiCorp is a business-to-business software company. We process personal data from visitors to our websites and our customers, including: personal details such as registration, subscription and contact information information such as Name, Company, Address, Phone Number, and Email Address. We also collect certain data from our business customers, typically business email addresses and other company contact details, in order to provide customer support for the software they purchase. To the extent we process financial data, such as credit card and payment information, we rely upon a secure, PCI-DSS Compliant Payment Processor; HashiCorp stores only limited payment information required to process such purchases and to fulfill legal and regulatory obligations. By visiting our websites, users also provide us with their computers’ IP addresses and other information automatically collected by internet servers. We do not share any personal information with any third parties without user consent unless otherwise stated. As part of our acquisition by IBM, all HashiCorp employees have converted to IBM employees and are now subject to IBM's privacy program. For that reason, we are excluding HR data from this renewal.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
29 Sep 2026HashiCorp, Inc.: Active: UK Extension Certification, EU-US Certification, SW-US Certification
Live pagesha256 6542b86408
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is HashiCorp GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 29 Sep 2026First indexed by CertReports2 evidence rows across 2 frameworks entered the index.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Cloud and hosting category) whose GDPR row is verified or vendor-stated, ranked by similarity.

All articles