StackLégal

Hosting and network

GDPR Fly.io

In an indie stack, Fly.io is used for Hosting for machines and applications, close to users. Entity cited: Fly.io, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 5, 2026. Verified on October 5, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Fly.io

Yes, on request. The documents page indicates a DPA pre-signed by Fly.io, effective when the customer signs it. The full text is not published on that page. PDF URL: not disclosed.

Read the DPA

Stated role

The privacy statement states that, for data in the applications, Fly.io is processor (or service provider) on the customer's instruction, the customer being the controller. For account and billing information, Fly.io is controller. It refers the detail of the processor role to the Data Processing Agreement.

Personal data

The privacy statement says it collects only the minimum necessary, and does not intentionally collect the information stored in the applications or free-form content: that content belongs to the customer. More detailed categories in a public DPA text: not disclosed.

Sub-processors of Fly.io

Public list (stated update: 24 September 2026). It names in particular, for hosting, CacheNetworks (United States) and DataPacket (United Kingdom), and AWS (United States) for account management, backups, and engineering support. The full table is not copied here.

List published by the vendor

Transfers outside the EU

Hosting / location

The privacy statement states that information stored on Fly.io's servers is stored in the United States. The regions documentation allows the application to be deployed in data centers including Amsterdam, Stockholm, Paris, Dallas, Secaucus, Frankfurt, São Paulo, Ashburn, Johannesburg, Los Angeles, London, Tokyo, Chicago, Singapore, San Jose, Sydney, and Toronto. Some rows of the table are marked gateway or Managed Postgres.

EU–United States Data Privacy Framework

Fly.io's Data Privacy Framework page asserts compliance with the EU-U.S. DPF, the United Kingdom extension, and the Swiss-U.S. DPF. Official search for “Fly.io” and “Fly.io, Inc.” on the list on 5 October 2026: no participant. Status on the list: not disclosed.

Cookies

The privacy statement consulted does not publish a table of names. Names: not disclosed.

Typical use, written by StackLégal and not by the vendor: Hosting for machines and applications, close to users.

History

Last update: October 5, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 5, 2026.

Frequently asked questions

Is Fly.io a processor within the meaning of the GDPR?

The privacy statement states that, for data in the applications, Fly.io is processor (or service provider) on the customer's instruction, the customer being the controller. For account and billing information, Fly.io is controller. It refers the detail of the processor role to the Data Processing Agreement.

What DPA does Fly.io publish?

Yes, on request. The documents page indicates a DPA pre-signed by Fly.io, effective when the customer signs it. The full text is not published on that page. PDF URL: not disclosed. https://fly.io/documents/

Which further sub-processors does Fly.io publish?

Public list (stated update: 24 September 2026). It names in particular, for hosting, CacheNetworks (United States) and DataPacket (United Kingdom), and AWS (United States) for account management, backups, and engineering support. The full table is not copied here. https://fly.io/legal/sub-processors/

Where does Fly.io state that it processes data, including outside the EU?

The privacy statement states that information stored on Fly.io's servers is stored in the United States. The regions documentation allows the application to be deployed in data centers including Amsterdam, Stockholm, Paris, Dallas, Secaucus, Frankfurt, São Paulo, Ashburn, Johannesburg, Los Angeles, London, Tokyo, Chicago, Singapore, San Jose, Sydney, and Toronto. Some rows of the table are marked gateway or Managed Postgres.

Is Fly.io registered under the EU–United States Data Privacy Framework?

Fly.io's Data Privacy Framework page asserts compliance with the EU-U.S. DPF, the United Kingdom extension, and the Swiss-U.S. DPF. Official search for “Fly.io” and “Fly.io, Inc.” on the list on 5 October 2026: no participant. Status on the list: not disclosed.

Which personal data does Fly.io mention?

The privacy statement says it collects only the minimum necessary, and does not intentionally collect the information stored in the applications or free-form content: that content belongs to the customer. More detailed categories in a public DPA text: not disclosed.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets hosting and network

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.