Hex and GDPR
CertReports found no public GDPR evidence for Hex as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 26 Oct 2023
- Scope
- Hex collects and processes personal data for the purposes of delivering the Hex platform to its customers. Hex Customers may collect, the extent of which is determined and controlled by the Hex customer in its sole discretion, and which may include, but is not limited to the following categories of Personal Data: ● Contacts – Such as name, email address from Customer’s users and customers ● Interaction Information - On how users and customers of Customer use its services. ● Device Information – e.g., IP address, user agent, browser settings from Customer’s users and customers ● Third-Party Information - Additional information collected from public sources and third parties based on the information Customer’s users and Customer has provided. ● Additional Information - Other information, when and to the extent submitted to Customer by Customer’s users and customers. For example, participation in a focus group, contest, request support, leave reviews, or otherwise communicate with Customer. ● Cookie Information - Metadata from cookies Hex may disclose the information to required subprocessors required to provide the Hex Services.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Hex: Inactive | Live pagesha256 8e76b72474 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Hex GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Analytics category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Analytics vendor has GDPR evidence in the index yet.