
LLamasoft and GDPR
CertReports found no public GDPR evidence for LLamasoft as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 19 Dec 2023
- Expires or valid through
- 26 Dec 2026
- Scope
- Data Processor: Coupa provides SaaS products in the area of business spend management to its customers. Coupa customers can determine what data they want to process using Coupa’s products. The type and categories of data hosted by Coupa are within our customer's control. Personal data is related to the work of data subjects, and it typically includes name, contact details, and details of the transactions carried out by the data subjects on behalf of the employer. The data transfer to Coupa is necessary to perform the contract Coupa’s customers have with their vendors, customers, and employees. Coupa Customers can choose the hosting location between the EU, APAC, or USA. Additionally, data may be accessed from outside the hosting location as certain Coupa teams such as technical support reside outside of the hosting location including the United States, Ireland, and India. This is necessary to operate a 24/7 technical support. Certain services on the Coupa Platform, e.g. the Coupa Supplier Portal, are hosted in the North America region only. Coupa may engage certain sub-processors to perform some of its obligations under its customer contracts. Coupa's sub-processors are the Coupa affiliates based in other countries and certain third-party contractors which are publicly disclosed and may be consulted at www.coupa.com/legal under the section "Privacy Terms". Data Controller: Coupa may collect and use certain personal data for its own purposes in certain situations namely in the context of our recruitment activities, to manage our employee relations, to manage our vendor relations, and for the purposes for our marketing activities. For candidate data, the personal data we may collect include name and date of birth; contact details including home address and personal phone numbers; preferences related to job location and compensation; application form; application letter and cv, references, evaluative notes, and decisions for job interviews. For employee (HR data), the personal data we may process Personal details include name and date of birth; contact details including home address, personal phone numbers and email address (if relevant); salary & bonus and any other forms of compensation; marital status; gender and ethnicity; emergency contact name and phone numbers and email address (if relevant); national tax identifier; employee id; government id; dependent data (name & date of birth); performance rating. For vendor and marketing data, the personal data we may process include identification data including name, position or title, place of work, profile information from public websites, e-mail address, office address, legal address, mobile phone number, office phone number, office fax number, access registration, VAT number and/or fiscal code (if relevant). We process this data so as to be able to manage these relationships, respectively. The Coupa general Privacy Policy available at https://www.coupa.com/privacy-policy/ details the legal basis we rely on, as well as all adequate disclosures, to process the categories of personal data mentioned above. Coupa will only share this information with third parties for the following purposes: at the request of the individual, to process or service a transaction or product authorized or requested by the individual; when required by law to disclose such information to appropriate authorities; to companies that assist Coupain marketing, placement and servicing our products and services; for example, in order to support our information technology or to handle mailings on our behalf; to our event sponsors and partners in connection with event registrations and marketing events, which may include sharing personal data with our sponsors and partners for their own commercial purposes if permitted by applicable law without appropriate consent from the individual, to companies that assist us in our job recruiting efforts or evaluating job applications; and to our professional advisers.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Coupa Software, Inc.: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 0a6c4e45bf |
- Kind
- listing
- Issued or listed
- 8 Dec 2017
- Scope
- We collect personal data for the following reasons: (a) So that data subjects can be contacted, and/or can contact each other, in order to do business. (b) So that we can provide goods or services to data subjects and/or their organizations and/or receive goods or services from data subjects and/or their organizations. (c) So that we can monitor the use of our goods and services for the purposes of maintenance, improvement, and license compliance. (d) So that we can give to employees, agents, and/or contractors access to the systems and databases that they need to perform their work.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Exari Group, Inc.: Inactive | Live pagesha256 1789001529 |
- Kind
- listing
- Issued or listed
- 5 Feb 2018
- Scope
- We collect personal data for the following reasons: (a) So that data subjects can be contacted, and/or can contact each other, in order to do business. (b) So that we can provide goods or services to data subjects and/or their organizations and/or receive goods or services from data subjects and/or their organizations. (c) So that we can monitor the use of our goods and services for the purposes of maintenance, improvement, and license compliance. (d) So that we can give to employees, agents, and/or contractors access to the systems and databases that they need to perform their work.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | LLamasoft, Inc.: Inactive | Live pagesha256 791b3730c2 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is LLamasoft GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Procurement category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Procurement vendor has GDPR evidence in the index yet.