Data processing
If you put other people's personal data on Drift, the GDPR makes you the controller and Drift the processor, and it requires a written agreement between us saying what we may do with it. This page is that agreement, plus the list of everyone else who touches the infrastructure it runs on.
It is published rather than sent on request, because "ask sales for the DPA" is the kind of friction Drift exists to not have. Your DPO can read it now, and so can your client's.
This page is the agreement
Who is what
- Role
- You are the controller, Drift is the processor
- Meaning
- Your app's records, uploads, identities and secrets. We act on your instructions and nothing else.
- Role
- Drift is the controller
- Meaning
- Email address, username, credentials, and the audit trail of what the account did.
The instruction we act on is your use of the platform: deploying, running, storing, and the commands you issue. We do not read your slice's data, mine it, train on it, or share it. There is no analytics product behind this and no second business model.
What is processed
Subject matter and duration. Hosting and running the application you deploy, for as long as the slice exists, plus a seven-day grace period after it expires, plus whatever is still inside a backup that has not yet aged out.
Nature and purpose. Storage, execution, transmission and backup of the data your application handles, so that your application works.
Types of personal data. Whatever your application puts in it. Drift imposes no schema and inspects no content, so the categories are yours to determine. In practice this is Backbone records (NoSQL, SQL, blobs, queues), Deed identities and their encrypted payloads, your secrets, your Canvas site, and the request logs your functions produce.
Categories of data subjects. Whoever your application serves. Your users, your customers, your employees.
What we commit to
- We process only on your documented instructions, and we tell you if an instruction looks unlawful to us rather than acting on it quietly.
- Everyone with access is bound to confidentiality. Today that is one person.
- We keep the security measures described on the security page, and that page is deliberately specific about which are in force and which are not yet.
- We assist you with data subject requests. Access, rectification, erasure and portability are things you can do yourself against your own slice with the CLI, which is usually faster than asking us. Where you cannot, we help.
- We assist you with your Article 32 to 36 duties, including breach reporting and impact assessments, to the extent the information is ours to give.
- We notify you of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of one, so that your own 72-hour clock is still runnable.
- At the end, you choose. Delete or return.
drift slice snapshot downloadis the return, anddrift account deleteis the deletion. The one thing that survives account deletion is the tamper-evident audit log, which names the actor; the security page says so plainly and explains why. - We make available what you need to verify this, and submit to audits or inspections you carry out or mandate. Given the size of the platform, expect that to be a conversation and a document rather than a data-centre visit.
Sub-processors
Everyone outside Drift who touches infrastructure that your data passes through or rests on. The list is short, which is the point of building it this way.
- Where
- Karlsruhe, Germany
- What it does
- Compute and storage. The servers running the platform, every slice, and the off-site backup repository.
- Where
- Ireland, under a US parent
- What it does
- Delivery of transactional email only: the signup verification code, renewal notices and operational alerts. It receives your email address and the content of those messages.
Everything your application holds is on the first row. There is no CDN in front of you, no managed database service, no analytics vendor, no error-tracking SaaS, no log shipper and no customer messaging tool. Everything else in the stack is software Drift runs itself on those servers: the database, the object store, the certificate handling, the reverse proxy, the backups.
The email row is a seam in the sovereignty story, and we are not going to hide it
Named for transparency, though not sub-processors. These see metadata about your deployment but not the personal data inside it, so they do not belong in the table above. They are listed because leaving them out and having you find them later is worse than the awkwardness of listing them.
- Let's Encrypt (ISRG, United States) issues the TLS certificates for
ondrift.euand for custom domains. It receives the hostname being certified and nothing else. There is no EU-based certificate authority with equivalent automation, and this is one of the places where the sovereign story has a genuine seam in it rather than a clean answer. - GitHub (Microsoft, United States) hosts the container images and the public CLI and SDK repositories. It is in the build path, not the request path, and no slice data is stored there.
Changing the list. We give 30 days' notice by email before adding a sub-processor, so you have time to object. If you object and we cannot resolve it, you can take your snapshot and leave, and we refund the unused part of the prepayment.
Where your data is
Everything your application holds is in Germany, on netcup's servers, and nowhere else. For that data there is no international transfer, so there is no standard contractual clause to review and no transfer impact assessment for you to write.
Account email is the exception, and it is named in full in the sub-processor warning above: it goes through Microsoft's Irish entity, so it stays in the EU but sits under a US parent. That is being moved.
That is a stronger claim than an EU region operated by a non-EU company, where the data sits in Europe but the company holding it answers to a legal system that can compel disclosure. Drift is a European company on European infrastructure, subject to EU law and nothing else. The reasoning is on Made in Europe.
What Drift keeps about you
Separate from your slice's contents, as controller of your account:
- Why
- Identifying the account, sending it operational mail
- How long
- Until the account is deleted
- Why
- Logging you in
- How long
- Until the account is deleted
- Why
- Running and billing what you asked for
- How long
- Until the account is deleted
- Why
- Operating the service, investigating abuse
- How long
- Per your slice's log retention, 24 hours on the free tier
- Why
- Recovering from failure
- How long
- 3 days on the free tier, longer on a configured slice
- Why
- A tamper-evident record of privileged actions
- How long
- Kept after account deletion, by design
Drift takes no card payments today, so there is no payment data and no financial record we are obliged to retain for tax purposes. That is a side effect of being pre-revenue rather than a permanent property, and this page changes when it does.
Contact
Questions about this page, or a data protection request: info@ondrift.eu.
Drift has not appointed a Data Protection Officer. At this size, and processing what it processes, it is not required to. If that changes, the DPO is named here.
Last updated 11 August 2026.