RelationalAI and GDPR
CertReports found no public GDPR evidence for RelationalAI as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 14 Mar 2025
- Expires or valid through
- 4 Mar 2027
- Scope
- As part of running our RelationalAI service on top of Snowflake, there is data captured in the RelationalAI provider accounts to ensure we are running the service in a reliable pattern. Part of the data that we capture is non sensitive and that is shared with RAI by default. However, there is a category of data that is marked sensitive and needs customer action to be able to share with RAI. Data marked in bold below is considered sensitive and won’t be shared with RAI by default and only might be shared on demand upon client’s explicit approval case by case. Customer & Data ● Customer uploaded Data ○ What ■ This is data that is uploaded and shared with RAI ○ How ■ These are data that is already shared with RAI and are ○ Why ■ We collect and maintain personal data that you submit to us for the purpose of supplying our Services. We may collect and process your personal data whether you are interacting with us on your own behalf or on behalf of any organisation you represent. ● Customer Identity ○ What ■ User IP address - IP address; computer type, and operating system; geolocation to ensure we’re showing you the correct notices and information; ○ How ■ You may give us your personal data directly, for example, when you purchase Services through our website, contact us with enquiries, complete forms on our website or provide us with feedback. ○ Why ■ We collect and maintain personal data that you submit to us for the purpose of supplying our Services. We may collect and process your personal data whether you are interacting with us on your own behalf or on behalf of any organisation you represent.The personal data we process may include your Identity Data etc. We process this information so that we can fulfil the supply of our Services, maintain our user databases and to keep a record of how our Services are being used. Usage Data ● Operational Attributes ○ Control Plane metadata – database name, engine name, account name, server IP ○ Customer operational data – Data loading/exporting paths ● Model Attributes ○ Schema – Relation names ○ Model files – Relation names / RelPaths ● Obfuscated Query data ○ Obfuscated Constant in Query plans, Compiled Query plans ○ Query text ■ What ● Query Text: The actual text of queries executed by users. ● Metadata: Information about the queries, such as execution time, frequency, and associated user or system identifiers (without collecting personal identifiable information unless explicitly logged by the user). ■ How ● If users engage with support or request optimizations, query samples may be shared voluntarily. ● Additionally, customers can allow logging of this data via sharing of the event table from the customer account to RelationalAI. ■ Why ● Performance Optimization: Helps improve query execution speed, indexing, and caching strategies. ● Reliability & Debugging: Allows for faster issue resolution and proactive system health monitoring. ● We collect and maintain personal data that you submit to us for the purpose of supplying our Services. Operating Information ● Engine size option ● Status data ● Internal system logs ● Internal server exception message ● Etc.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | RelationalAI: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 71c618abe4 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is RelationalAI GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.