Skip to main content
UP

Upstash

GDPR evidence

upstash.comLast verified 18 Sep 2026
GDPR mark, CertReports state Vendor-stated as of 18 Sep 2026Vendor-stated

Upstash and GDPR

Upstash states it holds a data processing agreement. CertReports captured this on 18 Sep 2026 from its trust centre (Vanta); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states GDPR on its trust centre
as of 18 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Upstash trust centre (Vanta)
Vendor trust centre · HTTP 200
18 Sep 2026GDPR
Live page Snapshotsha256 9ab1560cf3
VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
8 May 2025
Expires or valid through
29 Apr 2027
Scope
Upstash is the cloud database provider offering managed Data solutions that customers need to store, process, and manage their data ("Services"). In order to provide our Services, we collect personal information from our customers and their respective application users or applicable visitors ("end user"), and we store, process and transfer such information outside of the European Economic Area. Upstash processes customers' and their end users' personal information ("non-HR data"), such as name, email address, phone number, and IP address. We process non-HR data to provide, operate, deliver, monitor, administer, improve, and maintain our Services, provide assistance and technical support, and communicate with customers for account administration, marketing activities, security and legal purposes. In addition, Upstash may process personal information from event attendees and website visitors for internal marketing or user experience purposes and to analyze usage trends and activities in connection with our products and services. We disclose non-HR data to our customers, partners, event sponsors, third parties service providers and legal and public authorities. We disclose this information as necessary to provide our data services, as required by law, or as part of our business practices. Upstash processes employee and job applicant personal information ("HR data"), such as contact and identity information, employment and business relationship information, benefits, financial information, and internal engagement and preferences information. We process HR data to facilitate a working relationship with our employees, including communications, maintaining employment records and claims, conducting performance management efforts, complying with legal, insurance, financial, and audit obligations, managing workforce benefits and travel expenses, and maintain security, health, safety, and administrative programs, and for other legitimate interest purposes. Upstash discloses HR data to third party service providers, and legal and public authorities. We disclose this information to third parties as required by law and as part of our business practices in administering employment and improving our personnel experience processes.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Upstash, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 de05a7573a
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Upstash GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 18 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  2. 18 Sep 2026Subprocessor added: Amazon Web ServicesAmazon Web Services appeared on the subprocessor list.
  3. 18 Sep 2026Subprocessor added: AnthropicAnthropic appeared on the subprocessor list.
  4. 18 Sep 2026Subprocessor added: AtlassianAtlassian appeared on the subprocessor list.
  5. 18 Sep 2026Subprocessor added: ClerkClerk appeared on the subprocessor list.
  6. 18 Sep 2026Subprocessor added: ClickHouseClickHouse appeared on the subprocessor list.
  7. 18 Sep 2026Subprocessor added: Cloudflare, Inc.Cloudflare, Inc. appeared on the subprocessor list.
  8. 18 Sep 2026Subprocessor added: Customer.ioCustomer.io appeared on the subprocessor list.

Alternatives with GDPR evidence

Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.

No same-category vendor has GDPR evidence in the index yet.