drift Docs
Start
What is Drift?
The tour, if you are new here.
Use cases
Whether Drift does your thing.
Getting started
Nothing to deployed, in one command.
Architecture
How a slice is put together.
What it costs
The free grant, four unit prices, two rules.
Build
Canvas
Static sites, same origin as your API.
Tools
Operate
Auth
Accounts, tokens and scopes.
Security
Boundaries, sandboxing and hardening.
Troubleshooting
Error codes
What went wrong, and what to do about it.
Legal
Acceptable use
What a slice may not be used for.
Data processing
The DPA, and every sub-processor.

Data processing

If you put other people's personal data on Drift, the GDPR makes you the controller and Drift the processor, and it requires a written agreement between us saying what we may do with it. This page is that agreement, plus the list of everyone else who touches the infrastructure it runs on.

It is published rather than sent on request, because "ask sales for the DPA" is the kind of friction Drift exists to not have. Your DPO can read it now, and so can your client's.

This page is the agreement

Creating an account accepts it, and it applies to every slice on that account. If your organisation needs it signed on paper as well, mail info@ondrift.eu and we will sign your copy.

Who is what

RoleMeaning
  • What you store in your slice
    Role
    You are the controller, Drift is the processor
    Meaning
    Your app's records, uploads, identities and secrets. We act on your instructions and nothing else.
  • Your own account
    Role
    Drift is the controller
    Meaning
    Email address, username, credentials, and the audit trail of what the account did.

The instruction we act on is your use of the platform: deploying, running, storing, and the commands you issue. We do not read your slice's data, mine it, train on it, or share it. There is no analytics product behind this and no second business model.

What is processed

Subject matter and duration. Hosting and running the application you deploy, for as long as the slice exists, plus a seven-day grace period after it expires, plus whatever is still inside a backup that has not yet aged out.

Nature and purpose. Storage, execution, transmission and backup of the data your application handles, so that your application works.

Types of personal data. Whatever your application puts in it. Drift imposes no schema and inspects no content, so the categories are yours to determine. In practice this is Backbone records (NoSQL, SQL, blobs, queues), Deed identities and their encrypted payloads, your secrets, your Canvas site, and the request logs your functions produce.

Categories of data subjects. Whoever your application serves. Your users, your customers, your employees.

What we commit to

  • We process only on your documented instructions, and we tell you if an instruction looks unlawful to us rather than acting on it quietly.
  • Everyone with access is bound to confidentiality. Today that is one person.
  • We keep the security measures described on the security page, and that page is deliberately specific about which are in force and which are not yet.
  • We assist you with data subject requests. Access, rectification, erasure and portability are things you can do yourself against your own slice with the CLI, which is usually faster than asking us. Where you cannot, we help.
  • We assist you with your Article 32 to 36 duties, including breach reporting and impact assessments, to the extent the information is ours to give.
  • We notify you of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of one, so that your own 72-hour clock is still runnable.
  • At the end, you choose. Delete or return. drift slice snapshot download is the return, and drift account delete is the deletion. The one thing that survives account deletion is the tamper-evident audit log, which names the actor; the security page says so plainly and explains why.
  • We make available what you need to verify this, and submit to audits or inspections you carry out or mandate. Given the size of the platform, expect that to be a conversation and a document rather than a data-centre visit.

Sub-processors

Everyone outside Drift who touches infrastructure that your data passes through or rests on. The list is short, which is the point of building it this way.

WhereWhat it does
  • netcup GmbH
    Where
    Karlsruhe, Germany
    What it does
    Compute and storage. The servers running the platform, every slice, and the off-site backup repository.
  • Microsoft Ireland Operations Ltd
    Where
    Ireland, under a US parent
    What it does
    Delivery of transactional email only: the signup verification code, renewal notices and operational alerts. It receives your email address and the content of those messages.

Everything your application holds is on the first row. There is no CDN in front of you, no managed database service, no analytics vendor, no error-tracking SaaS, no log shipper and no customer messaging tool. Everything else in the stack is software Drift runs itself on those servers: the database, the object store, the certificate handling, the reverse proxy, the backups.

The email row is a seam in the sovereignty story, and we are not going to hide it

Drift's transactional mail currently goes out through Microsoft 365. Microsoft Ireland is the contracting entity and the data stays in the EU, but the parent is American, which is exactly the "an EU region is a location, not a jurisdiction" problem we make elsewhere on this site. Applying our own argument honestly: this one does not pass it. What it does and does not reach. It sees your account's email address and the text of mail we send you. It does not touch your slice: not your source, your database, your blobs, your secrets, your identities or your site. Those have never left netcup and there is no code path by which they could. It is being moved to an EU-owned provider. The mail transport is a deliberate swap point in the platform rather than something welded in, and this row changes to that provider's name when it does.

Named for transparency, though not sub-processors. These see metadata about your deployment but not the personal data inside it, so they do not belong in the table above. They are listed because leaving them out and having you find them later is worse than the awkwardness of listing them.

  • Let's Encrypt (ISRG, United States) issues the TLS certificates for ondrift.eu and for custom domains. It receives the hostname being certified and nothing else. There is no EU-based certificate authority with equivalent automation, and this is one of the places where the sovereign story has a genuine seam in it rather than a clean answer.
  • GitHub (Microsoft, United States) hosts the container images and the public CLI and SDK repositories. It is in the build path, not the request path, and no slice data is stored there.

Changing the list. We give 30 days' notice by email before adding a sub-processor, so you have time to object. If you object and we cannot resolve it, you can take your snapshot and leave, and we refund the unused part of the prepayment.

Where your data is

Everything your application holds is in Germany, on netcup's servers, and nowhere else. For that data there is no international transfer, so there is no standard contractual clause to review and no transfer impact assessment for you to write.

Account email is the exception, and it is named in full in the sub-processor warning above: it goes through Microsoft's Irish entity, so it stays in the EU but sits under a US parent. That is being moved.

That is a stronger claim than an EU region operated by a non-EU company, where the data sits in Europe but the company holding it answers to a legal system that can compel disclosure. Drift is a European company on European infrastructure, subject to EU law and nothing else. The reasoning is on Made in Europe.

What Drift keeps about you

Separate from your slice's contents, as controller of your account:

WhyHow long
  • Email address, username
    Why
    Identifying the account, sending it operational mail
    How long
    Until the account is deleted
  • Authentication credentials
    Why
    Logging you in
    How long
    Until the account is deleted
  • Slice configuration and prices
    Why
    Running and billing what you asked for
    How long
    Until the account is deleted
  • Request and platform logs
    Why
    Operating the service, investigating abuse
    How long
    Per your slice's log retention, 24 hours on the free tier
  • Backups
    Why
    Recovering from failure
    How long
    3 days on the free tier, longer on a configured slice
  • Audit records
    Why
    A tamper-evident record of privileged actions
    How long
    Kept after account deletion, by design

Drift takes no card payments today, so there is no payment data and no financial record we are obliged to retain for tax purposes. That is a side effect of being pre-revenue rather than a permanent property, and this page changes when it does.

Contact

Questions about this page, or a data protection request: info@ondrift.eu.

Drift has not appointed a Data Protection Officer. At this size, and processing what it processes, it is not required to. If that changes, the DPO is named here.

Last updated 11 August 2026.

Acceptable use → · Security & trust →