Tools and automation
GDPR Zapier
In an indie stack, Zapier is used for Automation between applications. Entity cited: Zapier, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Zapier
Yes. Public Data Processing Addendum.
Stated role
Zapier processes the personal information in Customer Content as a processor. Zapier is an independent controller for activities that are not solely the processing of information the customer adds to the service, such as the forum, analytics, accounts, and marketing.
Personal data
Name, email, identifier, phone, title, position, address, content of messages or attachments sent to Zapier, IP address, user identifier, cookies and similar technologies, and other personal information the customer chooses to submit.
Sub-processors of Zapier
Public list.
Transfers outside the EU
Hosting / location
Information collected on the sites is transferred and processed in the United States and in any other country where Zapier, its affiliates, or its providers have facilities or personnel.
EU–United States Data Privacy Framework
Zapier, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. United Kingdom extension and Swiss-U.S. DPF: Active. The privacy policy confirms this as well.
Cookies
Zapier and third parties that provide content, advertising, or other functions may use cookies, pixels, local storage, and other technologies.
Typical use, written by StackLégal and not by the vendor: Automation between applications.
History
Last update: October 4, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Zapier a processor within the meaning of the GDPR?
Zapier processes the personal information in Customer Content as a processor. Zapier is an independent controller for activities that are not solely the processing of information the customer adds to the service, such as the forum, analytics, accounts, and marketing.
What DPA does Zapier publish?
Yes. Public Data Processing Addendum. https://zapier.com/legal/data-processing-addendum
Which further sub-processors does Zapier publish?
Public list. https://www.zapier.com/legal/subprocessors
Where does Zapier state that it processes data, including outside the EU?
Information collected on the sites is transferred and processed in the United States and in any other country where Zapier, its affiliates, or its providers have facilities or personnel.
Is Zapier registered under the EU–United States Data Privacy Framework?
Zapier, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. United Kingdom extension and Swiss-U.S. DPF: Active. The privacy policy confirms this as well. https://www.dataprivacyframework.gov/participant/4425
Which personal data does Zapier mention?
Name, email, identifier, phone, title, position, address, content of messages or attachments sent to Zapier, IP address, user identifier, cookies and similar technologies, and other personal information the customer chooses to submit.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.