Productboard and GDPR
CertReports found no public GDPR evidence for Productboard as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 22 Mar 2017
- Expires or valid through
- 22 Oct 2026
- Scope
- Categories of data subjects whose personal data is transferred. Users, Customer’s customers, suppliers, and subcontractors; and any other person who transmits data via the Services, including individuals collaborating and communicating with Users and End-Users (as those terms are defined in the Agreement). Categories of personal data transferred. Personal data submitted, stored, sent, or received by the Customer, Users or End-Users via the Services (as that term is defined in the Master Subscription Agreement), may include the following categories of data: user IDs, email, documents, presentations, images, calendar entries, tasks, and other data. Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. The Services are not designed to process any sensitive data. Customer, Users or End-Users may submit special categories of Personal Data to the data exporter via the Services, the extent of which is determined and controlled by the data exporter. The frequency of the transfer. Continuous. Nature of the processing. Productboard will process Customer Data submitted, stored, sent, or received by the Customer, Users or End-Users for the purposes of providing the Services and related technical support to Customer in accordance with the Agreement. Purpose(s) of the data transfer and further processing. Productboard will transfer and further process such Customer Data for the purposes of providing the Services to Data Exporter. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period. The applicable Subscription Term (as defined in the Agreement) plus the period from expiry of such Subscription Term until deletion of all Customer Data by Productboard in accordance with such Agreement, which shall be 90 days from the effective date of termination of the applicable Order Form(s) and/or Agreement if not earlier deleted by the Customer. When acting as a processor, Productboard does not disclose personal information to third parties unless instructed to do so by the client. Our subprocessors are listed here: https://www.productboard.com/blog/productboard-subprocessors/? When acting as a controller, Productboard may disclose to: Affiliates, which shall include Productboard UK Limited, Productboard Ireland Limited, Productboard Czechia s.r.o, and Productboard Canada, Inc., for the purposes described in this Privacy Policy To third-party business partners that may offer products of interest to the individual or may co-sponsor a contest. Productboard is not currently sharing with, but may in the future share Personal Information with a third party in the event of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings). Agents and Service Providers that perform functions or services on our behalf such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, auditing and other services. They may have access to Personal Information needed to perform their functions but are restricted from using the Personal Information for purposes other than providing services for us or to us. For example, we have a few partners who help provide onboarding services to our customers and may need their name and email address to assist. We also have SOC2, ISO27001, or financial auditors who audit Productboard annually.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Productboard, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 15af49d6e5 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Productboard GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.