Hosting and network
GDPR Railway
In an indie stack, Railway is used for Hosting for applications and databases. Entity cited: Railway Corporation. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 5, 2026. Verified on October 5, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Railway
Yes. Public Data Processing Addendum. Transfers: the DPA defines the Data Privacy Framework and the standard contractual clauses.
Stated role
For Personal Data, the DPA states that the customer is controller and Railway is processor, or sub-processor if the customer is itself a processor. The Privacy Policy, for the data it covers, presents Railway as controller.
Personal data
Annex A cites profile or contact data and payment data, Company Account Data, Company Usage Data, and any personal data provided by the customer, including that of its end users. The Privacy Policy also cites device data and IP address. Data subjects according to the annex: customers and employees of the customer.
Sub-processors of Railway
The DPA points the list to trust.railway.com. The named table was not in the public text of the Trust Center home page on 5 October 2026. Names: not disclosed.
Transfers outside the EU
Hosting / location
The DPA states that the primary operations are in the United States and that the transfer to the United States is necessary, with a local-storage option for the Paid Services. The Privacy Policy indicates possible hosting in the United States, the Netherlands, Singapore, or another place offered and chosen for the Paid Services. The documentation publishes four regions: US West Metal (California), US East Metal (Virginia), EU West Metal (Amsterdam), and Southeast Asia Metal (Singapore).
EU–United States Data Privacy Framework
The Trust Center displays the notices “EU-US DPF” and “Swiss-US DPF”. Official search for “Railway” and “Railway Corporation” on the list on 5 October 2026: no participant under that name. Status on the list: not disclosed.
Cookies
The Privacy Policy describes essential, functional, and performance cookies. It does not publish the names. Names: not disclosed.
Typical use, written by StackLégal and not by the vendor: Hosting for applications and databases.
History
Last update: October 5, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 5, 2026.
Frequently asked questions
Is Railway a processor within the meaning of the GDPR?
For Personal Data, the DPA states that the customer is controller and Railway is processor, or sub-processor if the customer is itself a processor. The Privacy Policy, for the data it covers, presents Railway as controller.
What DPA does Railway publish?
Yes. Public Data Processing Addendum. Transfers: the DPA defines the Data Privacy Framework and the standard contractual clauses. https://railway.com/legal/dpa
Which further sub-processors does Railway publish?
The DPA points the list to trust.railway.com. The named table was not in the public text of the Trust Center home page on 5 October 2026. Names: not disclosed. https://trust.railway.com/
Where does Railway state that it processes data, including outside the EU?
The DPA states that the primary operations are in the United States and that the transfer to the United States is necessary, with a local-storage option for the Paid Services. The Privacy Policy indicates possible hosting in the United States, the Netherlands, Singapore, or another place offered and chosen for the Paid Services. The documentation publishes four regions: US West Metal (California), US East Metal (Virginia), EU West Metal (Amsterdam), and Southeast Asia Metal (Singapore).
Is Railway registered under the EU–United States Data Privacy Framework?
The Trust Center displays the notices “EU-US DPF” and “Swiss-US DPF”. Official search for “Railway” and “Railway Corporation” on the list on 5 October 2026: no participant under that name. Status on the list: not disclosed.
Which personal data does Railway mention?
Annex A cites profile or contact data and payment data, Company Account Data, Company Usage Data, and any personal data provided by the customer, including that of its end users. The Privacy Policy also cites device data and IP address. Data subjects according to the annex: customers and employees of the customer.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.