Q: GDPR Compliance for EU Clients - Server Location?
Hello kiwilaunch team,
I'm a French lawyer considering kiwilaunch for client bookings. Before purchasing, I need GDPR clarifications as law firms face strict data protection obligations and attorney-client privilege requirements.
Key questions:
1. Where are EU users' data physically hosted? EU/Switzerland or US?
2. Do you provide a GDPR-compliant DPA for EU clients?
3. If data transfers occur outside EU, do you use EU Commission-approved SCCs (2021)?
4. Who are your hosting subprocessors and where are they located?
5. Is data encrypted at rest and in transit?
As a lawyer bound by absolute confidentiality, data location is critical. Your Privacy Policy (June 2022) mentions UK GDPR but doesn't specify server location or EU client guarantees.
Could you clarify before I proceed with purchase?
Thank you.
Best regards,
Orkun_kiwilaunch
Oct 27, 2025A: Hello,
Let me try to answer all:
1. Where are EU users' data physically hosted? EU/Switzerland or US?
Aws London servers.
2. Do you provide a GDPR-compliant DPA for EU clients?
You probably can interpret better, but as per the advice we got, we and you are both Data processor. We have our data processing agreement with you, but as per our guidance, you need to append your own dpa to your privacy policy.
3. If data transfers occur outside EU, do you use EU Commission-approved SCCs (2021)?
Your data is strictly hosted in our UK instance. We don’t transfer. Please don’t use the Google analytics integration as it does user tracking and we can’t ensure.
Just to clarify, we made kiwi app GDPR compliant, but kiwilaunch.com and the intercom used for in-app support is not covered. We tried to enable your compliance.
4. Who are your hosting subprocessors and where are they located?
We use AWS. But if you use Stripe or PayPal for receiving online payments, we can’t guarantee compliance from their side. Similar witg Google Calendar integrationz
We have chatgpt integration but it is only for drafting service descriptions not for processing anything related to bookings or customers.
5. Is data encrypted at rest and in transit?
It is not encrypted.
Since UK was our launch market, we had to spend more resources on this, but our last external guidance was received 18 months ago.
So if you are aware of any more recent changes from the last period, you can ask them specifically.
Hope these help.