Upstash and GDPR
Upstash states it holds a data processing agreement. CertReports captured this on 18 Sep 2026 from its trust centre (Vanta); it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- listing
- Issued or listed
- 8 May 2025
- Expires or valid through
- 29 Apr 2027
- Scope
- Upstash is the cloud database provider offering managed Data solutions that customers need to store, process, and manage their data ("Services"). In order to provide our Services, we collect personal information from our customers and their respective application users or applicable visitors ("end user"), and we store, process and transfer such information outside of the European Economic Area. Upstash processes customers' and their end users' personal information ("non-HR data"), such as name, email address, phone number, and IP address. We process non-HR data to provide, operate, deliver, monitor, administer, improve, and maintain our Services, provide assistance and technical support, and communicate with customers for account administration, marketing activities, security and legal purposes. In addition, Upstash may process personal information from event attendees and website visitors for internal marketing or user experience purposes and to analyze usage trends and activities in connection with our products and services. We disclose non-HR data to our customers, partners, event sponsors, third parties service providers and legal and public authorities. We disclose this information as necessary to provide our data services, as required by law, or as part of our business practices. Upstash processes employee and job applicant personal information ("HR data"), such as contact and identity information, employment and business relationship information, benefits, financial information, and internal engagement and preferences information. We process HR data to facilitate a working relationship with our employees, including communications, maintaining employment records and claims, conducting performance management efforts, complying with legal, insurance, financial, and audit obligations, managing workforce benefits and travel expenses, and maintain security, health, safety, and administrative programs, and for other legitimate interest purposes. Upstash discloses HR data to third party service providers, and legal and public authorities. We disclose this information to third parties as required by law and as part of our business practices in administering employment and improving our personnel experience processes.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Upstash, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 de05a7573a |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Upstash GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 18 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 18 Sep 2026Subprocessor added: Amazon Web ServicesAmazon Web Services appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: AnthropicAnthropic appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: AtlassianAtlassian appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: ClerkClerk appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: ClickHouseClickHouse appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Cloudflare, Inc.Cloudflare, Inc. appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Customer.ioCustomer.io appeared on the subprocessor list.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.