StackLégal

Data

GDPR Upstash

In an indie stack, Upstash is used for Serverless Redis, Kafka, and queues. Entity cited: Upstash, Inc., a Delaware company. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 5, 2026. Verified on October 5, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Upstash

Yes. Public PDF (stated last update: April 2025), incorporated into the terms. Transfers: Data Privacy Framework according to the DPA, and standard contractual clauses if the DPF does not cover the transfer or is invalidated.

Read the DPA

Stated role

The DPA applies when Upstash processes Customer Personal Data to provide the services as processor, service provider, or an equivalent role. It does not cover processing that Upstash carries out on its own account (administration, marketing, analytics, security, legal obligations).

Personal data

The annex states that the customer controls the nature and volume of the data uploaded. Categories cited, without limitation: first name and last name, business contact details (email, phone, address), professional information (title, role), username. Data subjects cited: the customer's customers, employees, suppliers, and end users. The DPA prohibits submitting sensitive data.

Sub-processors of Upstash

Public PDF. It names in particular Amazon Web Services (cloud), Google, Intercom, Slack, Notion, Linear, OpsGenie, and StatusPage. The full table is not copied here.

List published by the vendor

Transfers outside the EU

Hosting / location

The DPA states that Upstash, Inc. receives European Data in the United States. The Redis Global documentation publishes AWS regions chosen by the customer (primary region and read regions): Northern Virginia, Ohio, Northern California, Oregon, Canada Central, São Paulo, Ireland, London, Frankfurt, Mumbai, Singapore, Tokyo, Sydney, and Cape Town. The documented creation API also documents a GCP platform, including us-central1, us-east4, europe-west1, and asia-northeast1. The Redis FAQ indicates availability on AWS, GCP, and Fly.io.

EU–United States Data Privacy Framework

The DPA states that Upstash, Inc. uses the Data Privacy Framework to receive European Data in the United States. Official search for “Upstash” and “Upstash, Inc.” on the list on 5 October 2026: no participant. Status on the list: not disclosed.

Cookies

The Privacy Policy (April 2025) indicates cookies and server logs for visitors to the site, and cites browser type, language, referring site, and IP address. Cookie names: not disclosed.

Typical use, written by StackLégal and not by the vendor: Serverless Redis, Kafka, and queues.

History

Last update: October 5, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 5, 2026.

Frequently asked questions

Is Upstash a processor within the meaning of the GDPR?

The DPA applies when Upstash processes Customer Personal Data to provide the services as processor, service provider, or an equivalent role. It does not cover processing that Upstash carries out on its own account (administration, marketing, analytics, security, legal obligations).

What DPA does Upstash publish?

Yes. Public PDF (stated last update: April 2025), incorporated into the terms. Transfers: Data Privacy Framework according to the DPA, and standard contractual clauses if the DPF does not cover the transfer or is invalidated. https://upstash.com/trust/dpa.pdf

Which further sub-processors does Upstash publish?

Public PDF. It names in particular Amazon Web Services (cloud), Google, Intercom, Slack, Notion, Linear, OpsGenie, and StatusPage. The full table is not copied here. https://upstash.com/trust/subprocessors.pdf

Where does Upstash state that it processes data, including outside the EU?

The DPA states that Upstash, Inc. receives European Data in the United States. The Redis Global documentation publishes AWS regions chosen by the customer (primary region and read regions): Northern Virginia, Ohio, Northern California, Oregon, Canada Central, São Paulo, Ireland, London, Frankfurt, Mumbai, Singapore, Tokyo, Sydney, and Cape Town. The documented creation API also documents a GCP platform, including us-central1, us-east4, europe-west1, and asia-northeast1. The Redis FAQ indicates availability on AWS, GCP, and Fly.io.

Is Upstash registered under the EU–United States Data Privacy Framework?

The DPA states that Upstash, Inc. uses the Data Privacy Framework to receive European Data in the United States. Official search for “Upstash” and “Upstash, Inc.” on the list on 5 October 2026: no participant. Status on the list: not disclosed.

Which personal data does Upstash mention?

The annex states that the customer controls the nature and volume of the data uploaded. Categories cited, without limitation: first name and last name, business contact details (email, phone, address), professional information (title, role), username. Data subjects cited: the customer's customers, employees, suppliers, and end users. The DPA prohibits submitting sensitive data.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets data

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.