Our updated Terms of Service, effective February 17, 2023, now include our DPA removing the need for a signed copy of our DPA. You can download our Data Processing Addendum by following the link below.
Download our Data Processing Addendum
If your organization requires a signed DPA, download the signing version and contact privacy@gleap.io to arrange execution by both parties.
To ensure consistency and avoid the imposition of additional terms beyond our standard DPA and contractual clauses, we cannot agree to sign customers’ DPAs.
The downloadable DPA was updated on September 20, 2026. It integrates signup region selection, EU and US storage, regional AI endpoints, transfer safeguards and the parties’ processing obligations into the agreement and its annexes.
Regional hosting and GDPR
Gleap supports EU and US data residency. The DPA governs processing on your behalf in either region, including security measures, sub-processors and international-transfer safeguards. Selecting US hosting does not waive GDPR (DSGVO) protections. Regional hosting and third-party processing are explained in our data residency guide.
Existing contractual restrictions continue to apply until validly amended. A website update or SDK configuration change does not by itself amend an existing agreement or authorize migration of customer data.
For an overview of our security practices, audit assurance, sub-processors, and vendor information for financial entities regulated under DORA, visit our Trust center.