Q: For EU customers: Do you offer a GDPR Art. 28 DPA, and where is visitor data stored and processed?
a) Do you provide a Data Processing Agreement (DPA) compliant with Article 28 GDPR for customers in Germany/EU?
b) Where is TruConversion visitor data stored? Is the data stored within the EU, and can EU customers choose EU data residency?
c) If visitor data is processed or accessed outside the EU/EEA, which countries are involved and what GDPR transfer mechanism do you use (e.g. EU-US Data Privacy Framework or Standard Contractual Clauses)?
Fawwad_TruConversion
Aug 17, 2026A: Thank you for the detailed questions. We take GDPR and data privacy seriously.
Thank you for the question. TruConversion uses AWS infrastructure (including S3, RDS and/or Redshift) to store collected website data. Our GDPR controls include IP anonymization, data obfuscation/masking, and additional protections for EU visitors.
For the specific questions around an Article 28 DPA, EU data residency, and the exact countries/transfer mechanisms used for processing outside the EU/EEA, we don't want to give you an inaccurate answer based on assumptions. These are legal/data-processing details, so our team can provide the appropriate information directly.
Please contact [email protected] with your requirements, and we'll have the team clarify the applicable DPA and data-transfer arrangements for your organization.
You can also review our GDPR documentation here: https://help.truconversion.com/knowledgebase/truconversion-and-the-gdpr/