Rewst and GDPR
CertReports found no public GDPR evidence for Rewst as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 5 Sep 2025
- Expires or valid through
- 19 Feb 2027
- Scope
- ANNEX I: DETAILS OF PROCESSING This Annex I includes details of the Processing of Customer Personal Data. 1. Subject matter of the Processing of Customer Personal Data: Rewst provides a multi-tenant RPA platform that enables Managed Service Providers (MSPs) to automate repetitive tasks such as endpoint management, ticketing workflows, and onboarding/offboarding across their integrated systems. MSPs retain control of their data in their own environments, while Rewst’s platform orchestrates these automated tasks. Rewst’s platform includes: • Crate Marketplace for prebuilt automations, • Dashboard for monitoring workflows and tracking errors, • Automation Builder for creating and managing custom workflows, and • Form Builder for gathering data to trigger workflows. • Rewst processes personal data only to facilitate these automations on behalf of its MSP clients. 2. Duration of Processing: Rewst will process personal data for the duration of the Controller’s subscription, or as needed to fulfill the services described. Upon termination of the subscription or as otherwise instructed, Rewst will delete or return personal data in accordance with this DPA and any additional contractual obligations. 3. Purpose for Processing: Rewst processes personal data solely to provide, support, and maintain its cloud-based robotic process automation platform in accordance with the Controller’s instructions. This includes executing automated tasks (such as user account creation, password resets, and other IT or MSP workflows) across the Controller’s integrated systems. The data is processed only to the extent necessary to perform these services and is not used for any other purposes without the Controller’s explicit authorization. 4. Processing Instructions: Rewst acts solely on the Controller’s documented instructions when processing personal data unless otherwise required by applicable law. Any additional instructions beyond the agreed scope must be mutually documented and appended to this DPA. 5. Categories of Customer Personal Data to be Processed: The specific personal data may vary based on how the Controller configures its recipes and integrations, but generally includes: • Identification Data: Names, usernames, email addresses, or other unique identifiers. • Employment-Related Data: Department, title, job role, managerial reporting lines, • hire/termination dates, if included in automated workflows. • Contact Information: Business phone numbers or other necessary contact details. • System/Account Data: Login credentials, security group memberships, ticket or • incident data, IP addresses, or other data points relevant to the automated workflows. Note: Rewst does not independently determine which personal data is processed; it only processes data as configured by the Controller. 6. Categories of Data Subjects to whom the Customer Personal Data relates: Data subjects may include: • The Controller’s employees, contractors, or authorized users whose data must be processed to automate tasks. Potentially external individuals (e.g., customers or partners) if the Controller configures recipes that involve such data.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Rewst: Active: EU-US Certification, UK Extension Certification | Live pagesha256 811eeba83c |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Rewst GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the DevOps and observability category) whose GDPR row is verified or vendor-stated, ranked by similarity.