StackLégal

Measurement and observability

GDPR PostHog

In an indie stack, PostHog is used for Product analytics and events. Entity cited: PostHog, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA PostHog

Yes. Public DPA.

Read the DPA

Stated role

For PostHog Cloud, the customer is controller and PostHog, Inc. is processor of Company Personal Data.

Personal data

Name, address, email, title, position, and other contact details, social profiles, IP address, unique user identifiers such as cookie identifiers, marketing profiles, documents, images, and uploaded content.

Sub-processors of PostHog

Public list. AWS appears there for storage, in the United States or in Germany depending on the cloud chosen.

List published by the vendor

Transfers outside the EU

Hosting / location

Company Personal Data is hosted in the data center provided for in the contract. PostHog Cloud storage is in the United States for PostHog US Cloud, or in Germany for PostHog EU Cloud.

EU–United States Data Privacy Framework

PostHog Inc. is registered. EU-U.S. Data Privacy Framework status: Active.

Data Privacy Framework sheet

Cookies

The JavaScript documentation states that, with default persistence (localStorage and cookie), the first-party cookie is called ph_<project_token>_posthog and expires after 365 days. It carries a subset of identity and session data. The DPA refers ePrivacy consent to the customer. Names of cookies on the posthog.com site: not disclosed.

Typical use, written by StackLégal and not by the vendor: Product analytics and events.

History

Last update: October 4, 2026.

  1. Cookies: name of the first-party cookie taken from the JavaScript documentation.

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is PostHog a processor within the meaning of the GDPR?

For PostHog Cloud, the customer is controller and PostHog, Inc. is processor of Company Personal Data.

What DPA does PostHog publish?

Yes. Public DPA. https://posthog.com/dpa

Which further sub-processors does PostHog publish?

Public list. AWS appears there for storage, in the United States or in Germany depending on the cloud chosen. https://posthog.com/subprocessors

Where does PostHog state that it processes data, including outside the EU?

Company Personal Data is hosted in the data center provided for in the contract. PostHog Cloud storage is in the United States for PostHog US Cloud, or in Germany for PostHog EU Cloud.

Is PostHog registered under the EU–United States Data Privacy Framework?

PostHog Inc. is registered. EU-U.S. Data Privacy Framework status: Active. https://www.dataprivacyframework.gov/participant/2915

Which personal data does PostHog mention?

Name, address, email, title, position, and other contact details, social profiles, IP address, unique user identifiers such as cookie identifiers, marketing profiles, documents, images, and uploaded content.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets measurement and observability

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.