Skip to main content
Ooma logo

Ooma

GDPR evidence

GDPR mark, CertReports state No public evidenceNo public evidence

Ooma and GDPR

CertReports found no public GDPR evidence for Ooma as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: UK Extension Certification, EU-US Certification, SW-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
20 Nov 2019
Expires or valid through
24 Nov 2026
Scope
Ooma/Broadsmart/2600: Personal Information may include name, physical address, email address, telephone number, certain billing information, website pages viewed, time spent using certain services, and demographic data collected via cookies, Internet Protocol address, operating system, browser type, username, location-based data, and interactions with an Internet website. We process Personal Information to provide our Equipment and Services, to improve the Equipment and Services, and to develop new products, services, features, and functionalities, to advertise our services, and for administrative and legal purposes. We disclose Personal Information to third party service providers such as our vendors and contractors to provide application development, hosting, maintenance, and other services and to assist Ooma in our provision of Equipment and Services and to offer co-branded Ooma Equipment and Services or to jointly create and/or offer products, services, or joint promotion. Talkatone: The types of Personal Information collected may include your full name, email address, gender, age range, mobile phone number, and any other information necessary for us to provide our Services. The Personal Information you provide is used for such purposes as providing the Services, answering your questions about the Services, and communicating with you about Talkatone’s products and Services. We may also collect third-party account credentials (for example, your log-in credentials for Google Voice, Facebook or other third-party sites) to help you take full advantage of the Services. We or third parties on our behalf may collect other types of information whenever you interact with our Website or use the Services (including mobile applications). For example, we automatically receive and record information on our server logs from your browser or device including your IP address, geolocation, device identifier, diagnostic data, “cookie” information, browser type, operating system information, and the page or feature you requested. We use this information for internal purposes such as providing the Services to you. Generally, our service automatically collects usage information, such as the numbers and frequency of calls to the Services and visitors to our Website, similar to TV ratings that indicate how many people watched a particular show. We only use this data in aggregate form, that is, as a statistical measure, and not in a manner that would identify you personally. This type of aggregate data enables us to figure out how often customers use parts of the Services or Website so that we can make them appealing to as many customers as possible, and improve them as necessary. As part of this use of information, we may provide aggregate information to our partners (including advertisers) about how our customers, collectively, use our Services or Website. We share this type of statistical data so that our partners also understand how often people use the Services or Website, so that they, too, may provide you with an optimal level of service and online experience.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Ooma, Inc.: Active: UK Extension Certification, EU-US Certification, SW-US Certification
Live pagesha256 2bbdddae65
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Ooma GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Communications and CPaaS category) whose GDPR row is verified or vendor-stated, ranked by similarity.