Tidio and GDPR
Tidio states it holds a data processing agreement. CertReports captured this on 18 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- listing
- Issued or listed
- 30 Jan 2019
- Scope
- Tidio LLC collects and processes personal data primarily to provide and enhance its services, ensure secure and reliable performance, and continually improve the functionality and quality of its offerings. Personal data and related user information are gathered to facilitate user registration, provide access to Tidio LLC’s products and services, and ensure an optimal user experience. Processing of HR Information Notice In addition to its service-related purposes, Tidio LLC may collect and process personal data related to employees, job applicants, and other individuals for human resources (HR) purposes. This includes information necessary for recruitment, hiring, employee administration, payroll processing, performance management, and compliance with employment laws. Such HR-related personal data is collected and handled in accordance with applicable data privacy laws, and Tidio LLC ensures this information is managed securely and used solely for legitimate HR and employment-related purposes. Tidio LLC is committed to respecting and protecting user and employee privacy by following robust data security practices, maintaining transparency, and adhering to applicable privacy regulations. Personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF is processed to operate and support Tidio’s services, including service and website hosting, data storage, ICT support, marketing analytics, website analytics, social media activities, and payment processing. Depending on activities described in Section III, the data may include customer/client data and website/visitor data, and—where applicable—HR data. Categories of recipients. Personal data may be disclosed to other companies and service providers that perform business operations on Tidio’s behalf, including: • Website hosting providers • Subjects involved in storing data for us • Entities providing ICT services • Social media providers (e.g., Facebook Ireland Ltd., LinkedIn Ireland Unlimited Company, Twitter Inc.) • CRM (HubSpot) • Payment processing (Stripe) • Website analytics (Google Analytics, Amplitude) These companies and service providers may participate in the processing of personal data only to the extent necessary to perform services for Tidio.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Tidio LLC: Inactive | Live pagesha256 38bc7ef4fd |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Tidio GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 18 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 18 Sep 2026Subprocessor added: Third Party Dependence Yes Hosting Major CloudThird Party Dependence Yes Hosting Major Cloud appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Trust ServicesTrust Services appeared on the subprocessor list.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.