Stova and GDPR
CertReports found no public GDPR evidence for Stova as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 23 Jan 2025
- Scope
- • Stova provides its clients with a cloud-based event management platform and related services for their organization, hosting and management of conferences, business meetings, seminars and other corporate events organized or hosted by the client. Stova collects, stores, transfers, and otherwise Processes Personal Data of individuals who are invited to, register for, or otherwise participate in one or more of the client’s events, and from the client’s employees and agents who administer any such event. Processing occurs only upon the instruction of the client, as the data exporter, in accordance with the terms of the applicable agreement, including any data processing agreement in effect between the client and Stova. Personal Data may be subject to the following Processing activities: (1) Storage and other Processing activities necessary to provide, maintain, and improve the Services provided to the client; and/or (2) Transfer or disclosure in accordance with the applicable agreement, including any data processing agreement, and/or as required by applicable laws. • Stova acts as the data processor and data important for the data provided to it by its clients. Clients may submit personal data to Stova, the extent of which is determined and controlled by the by the client in its sole discretion, and which may include, but is not limited to, personal data relating to the following categories of data subjects: (1) Prospects, customers, business partners and vendors of Client (who are natural persons); (2) Employees or contact persons of Client’s prospects, customers, business partners and vendors; (3) Employees, agents, advisors, contractors of Client (who are natural persons); (4) Natural persons who are invited to, register for, or otherwise attend events organized or hosted by Client; and (5) Client’s users authorized by the Client to access the services provided by Stova. In connection with its receipt of Services under the applicable agreement, a client may submit Personal Data to Stova, the extent of which is determined and controlled by the Client in its sole discretion. Such Personal Data may include, but is not limited to the following categories of personal data: (1) Identification Data (Name, personal address, personal email addresses and other contact information); (2) Employment Information (Title; Employer; Business address, business email address and other corporate contact information; Professional life data); (3) Personal life data (e.g., meal preferences); (4) Financial Data (payment information); (5) Connection and usage data; and (6) Location data. • Stova may engage sub-processors to Process Personal Data when necessary to provide the services. Sub-processors are used for cloud hosting services, usage analytics, support services, video processing and streaming, email delivery, payment processing, and client account management. A list of current sub-processors can be found here: https://stova.io/subprocessors/.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Stova Group LLC: Inactive | Live pagesha256 01f63ebff7 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Stova GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.