StackLégal

Hosting and network

GDPR Render

In an indie stack, Render is used for Hosting for applications, static sites, and databases. Entity cited: Render Services, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 5, 2026. Verified on October 5, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Render

Yes. Public Data Processing Addendum (stated last modification: 19 December 2024). Transfers outside the EEA: Data Privacy Framework, or standard contractual clauses if the DPF does not apply.

Read the DPA

Stated role

The DPA states that, unless expressly stated, Render is processor and the customer may be controller or processor. The annexes on US state laws specify that, outside Company Account Data and Company Usage Data, the customer is controller and Render is processor. Section 9 (“Company's Role as a Controller”) refers to the Privacy Policy for the controller role.

Personal data

Annex A cites the name, a location, the email, the phone, the address, the profession, and the title, as well as Company Account Data, Company Usage Data, and any personal data provided by the customer, including that of its end users. Data subjects: end users or customers, and/or employees of the customer.

Sub-processors of Render

The DPA points the list to render.com/trust. The public table names Amazon Web Services, Google Cloud Platform, Cloudflare, and ClickHouse Inc., each for hosting, country indicated: United States.

List published by the vendor

Transfers outside the EU

Hosting / location

The DPA states that the primary processing operations are in the United States, and that the transfer to the United States is necessary to provide the service. The documentation allows a choice of Oregon, Ohio, Virginia, Frankfurt, or Singapore for a service or a database. Static sites are on a global CDN, with no region choice. Hosting sub-processors are indicated in the United States.

EU–United States Data Privacy Framework

Render Services, Inc. is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). United Kingdom extension and Swiss-U.S. DPF: Active.

Data Privacy Framework sheet

Cookies

The Privacy Policy describes essential, functional, performance, and advertising cookies, including third-party cookies. It does not publish the names. Names set on a customer's domain: not disclosed.

Typical use, written by StackLégal and not by the vendor: Hosting for applications, static sites, and databases.

History

Last update: October 5, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 5, 2026.

Frequently asked questions

Is Render a processor within the meaning of the GDPR?

The DPA states that, unless expressly stated, Render is processor and the customer may be controller or processor. The annexes on US state laws specify that, outside Company Account Data and Company Usage Data, the customer is controller and Render is processor. Section 9 (“Company's Role as a Controller”) refers to the Privacy Policy for the controller role.

What DPA does Render publish?

Yes. Public Data Processing Addendum (stated last modification: 19 December 2024). Transfers outside the EEA: Data Privacy Framework, or standard contractual clauses if the DPF does not apply. https://render.com/dpa

Which further sub-processors does Render publish?

The DPA points the list to render.com/trust. The public table names Amazon Web Services, Google Cloud Platform, Cloudflare, and ClickHouse Inc., each for hosting, country indicated: United States. https://render.com/trust

Where does Render state that it processes data, including outside the EU?

The DPA states that the primary processing operations are in the United States, and that the transfer to the United States is necessary to provide the service. The documentation allows a choice of Oregon, Ohio, Virginia, Frankfurt, or Singapore for a service or a database. Static sites are on a global CDN, with no region choice. Hosting sub-processors are indicated in the United States.

Is Render registered under the EU–United States Data Privacy Framework?

Render Services, Inc. is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). United Kingdom extension and Swiss-U.S. DPF: Active. https://www.dataprivacyframework.gov/participant/9348

Which personal data does Render mention?

Annex A cites the name, a location, the email, the phone, the address, the profession, and the title, as well as Company Account Data, Company Usage Data, and any personal data provided by the customer, including that of its end users. Data subjects: end users or customers, and/or employees of the customer.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets hosting and network

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.