STRIVR and GDPR
CertReports found no public GDPR evidence for STRIVR as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 18 Oct 2019
- Expires or valid through
- 10 Jun 2027
- Scope
- Our organization processes personal data for several purposes, relying on the Data Privacy Framework(s). The following are the main purposes for which we collect and process personal information: Communication and Account Management: We collect Identifiers, which include basic identifying data such as names, titles, addresses, email addresses, and phone numbers, to communicate with individuals in relation to their accounts. This information also helps us perform our obligations, exercise our rights under agreements, ensure compliance with applicable laws, and respond to government authorities' requests where required. Additionally, it serves the purpose of protecting the legal interests, health, or safety of users, our organization, or others. Account Creation and Management: We process Commercial information, which includes account and billing data, contact data, credentials, and details of the services ordered or purchased. This information is used to create and manage user accounts, fulfill orders, provide customer service, and technical assistance. It also supports the legal protection of interests, health, or safety and is relevant in the context of mergers, acquisitions, sales, or similar transactions. Service Enhancement and Compliance: Device and Usage Data, such as internet protocol addresses, login data, browser information, location data, and usage patterns, are collected to provide, maintain, monitor, secure, debug, customize, and optimize our services. We use this data to improve our products and services, fulfill obligations under agreements, and ensure compliance with applicable laws. We also respond to government requests as required. Marketing and Communication: Marketing and Communication Data, including preferences in receiving marketing communications, are processed to provide marketing communications, promotional offers, and updates on new products and services, subject to applicable law and consent requirements. Types of Personal Data Processed: The types of personal data processed by our organization can be categorized into the following: Identifiers: This includes names, titles, organization/company details, addresses, email addresses, and phone numbers. Commercial Information: This category encompasses account and billing data, contact information, credentials, and details of ordered services, including billing and payment information. Device and Usage Data: This comprises internet protocol addresses, login data, browser information, location data, and usage patterns, along with telemetry data. Marketing and Communication Data: This category includes information related to individual preferences in receiving marketing communications. Our organization does not consider Device or Usage Data to be Personal Information unless it is linked to an individual or required by applicable law. Third-Party Disclosure: We may share the collected Personal Information with various third parties under specific circumstances permitted by applicable law, including: Trusted third-party service providers to assist in providing, improving, protecting, and promoting our services. Business partners and entities involved in business reorganizations, such as mergers, acquisitions, sales, or similar transactions. Auditors and advisors for the purpose of audits and advisory services. Entities as required to comply with legal obligations, such as subpoenas, court orders, legal processes, or governmental requests. Entities involved in establishing or protecting legal rights, property, or safety, or defending against legal claims. It's important to note that the specific personal data disclosed to third parties may vary depending on the circumstances and the applicable legal requirements.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | STRIVR: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 d432ffd34c |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is STRIVR GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.