Data
GDPR Neon
In an indie stack, Neon is used for Serverless Postgres. Entity cited: Neon Inc. (DPA); Neon, LLC, a subsidiary of Databricks, Inc. (platform terms and sub-processor page). The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Neon
Yes. Public PDF.
Stated role
The DPA defines Customer Data as personal data processed by Neon as processor for the customer, the controller. Annex 1 indicates the importer as processor and the customer as controller.
Personal data
The annex cites the email, full name, and IP address of authorized users, the customer's company name and address, the role on the team, representatives' phone numbers, and partial payment-method data received through a payment provider.
Sub-processors of Neon
Public list in the name of Neon, LLC.
Transfers outside the EU
Hosting / location
The DPA indicates a transfer to and processing by Neon, Inc. in the United States and in other countries where Neon and its sub-processors operate. The documentation states that the customer chooses the region when creating the project, that each project exists in only one region, and that this choice cannot be changed afterwards. Published AWS regions: Northern Virginia, Ohio, Oregon, Frankfurt, London, Singapore, Sydney, and São Paulo. Azure regions are indicated as deprecated for new projects.
EU–United States Data Privacy Framework
Neon, LLC is a covered entity of Databricks, Inc., EU-U.S. Data Privacy Framework status: Active (United Kingdom extension and Swiss-U.S. also Active). A separate “Neon Inc.” entry has status Inactive - Lapse. That is not the same registration.
Cookies
The Auth documentation indicates an HTTP-only cookie __Secure-neonauth.session_token (opaque session token). The Next.js SDK caches session data in a signed cookie __Secure-neon-auth.next.session_data (5 minutes by default). Names of cookies on the neon.com site: not disclosed.
Typical use, written by StackLégal and not by the vendor: Serverless Postgres.
History
Last update: October 4, 2026.
Hosting: clarification of the customer's region choice, based on the documentation.
Cookies: names taken from the Auth documentation, in place of "not disclosed".
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Neon a processor within the meaning of the GDPR?
The DPA defines Customer Data as personal data processed by Neon as processor for the customer, the controller. Annex 1 indicates the importer as processor and the customer as controller.
What DPA does Neon publish?
Yes. Public PDF. https://neon.com/pdf/DPA.pdf
Which further sub-processors does Neon publish?
Public list in the name of Neon, LLC. https://neon.com/subprocessors
Where does Neon state that it processes data, including outside the EU?
The DPA indicates a transfer to and processing by Neon, Inc. in the United States and in other countries where Neon and its sub-processors operate. The documentation states that the customer chooses the region when creating the project, that each project exists in only one region, and that this choice cannot be changed afterwards. Published AWS regions: Northern Virginia, Ohio, Oregon, Frankfurt, London, Singapore, Sydney, and São Paulo. Azure regions are indicated as deprecated for new projects.
Is Neon registered under the EU–United States Data Privacy Framework?
Neon, LLC is a covered entity of Databricks, Inc., EU-U.S. Data Privacy Framework status: Active (United Kingdom extension and Swiss-U.S. also Active). A separate “Neon Inc.” entry has status Inactive - Lapse. That is not the same registration. https://www.dataprivacyframework.gov/participant/4569
Which personal data does Neon mention?
The annex cites the email, full name, and IP address of authorized users, the customer's company name and address, the role on the team, representatives' phone numbers, and partial payment-method data received through a payment provider.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.