Skip to main content
The information below pertains to how Stytch by Twilio handles data in accordance with the GDPR.Consult your legal and compliance team to determine the exact impact on your business.The information on this page does not, and is not intended to, constitute legal advice; instead, all information is for general informational purposes only.

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive European Union law that dictates how organizations collect, process, and protect personal data. It grants individuals greater control over their personal information and enforces strict privacy and security standards globally for any business that handles the data of EU residents.

How Stytch complies with GDPR

Stytch complies with GDPR directives and is committed to helping you comply with GDPR. Our key measures include:
  • Data Processing Agreement (DPA): We offer a DPA that incorporates Standard Contractual Clauses (SCCs) for lawful cross-border data transfers.
  • Technical and Organizational Measures (TOMs): We implement robust security measures to protect customer data.
  • End-user Data Management: We support deleting user records (right to be forgotten); data deletion requests can be made to support@stytch.com.

Data residency

For most B2B SaaS companies, a Data Residency approach - where core customer data is stored regionally but processed globally - is standard and typically sufficient. In this model, authentication data, i.e. what is stored within Stytch, is almost always explicitly excluded from regional requirements. This means when using Stytch for your auth flow, you generally do not need a regionally isolated auth deployment. A global auth configuration paired with regional storage for your proprietary app data will satisfy typical compliance demands, while preserving a unified developer experience and enabling seamless user features like centralized login and cross-region organization switching. However, if you operate in highly regulated industries or process sensitive, unstructured data, you may face demands for strict Data Localization, where all data, including authentication data, must be stored, processed, and served entirely within a specific region. Because Stytch operates exclusively out of U.S. servers, achieving this level of rigid localization with their service is not possible. Therefore, your strategy hinges on deeply validating your pipeline’s specific compliance requirements: If your enterprise prospects accept the standard carve-out for auth data, Stytch remains a great fit, but if they mandate absolute regional isolation, Stytch’s centralized infrastructure will be a hard blocker.

Data Privacy Framework (DPF)

Stytch self-certifies compliance with the Data Privacy Framework requirements for data transfers from the EU, United Kingdom, and Switzerland to the United States. Key measures Stytch has in place include:
  • Public Self-Certification: Stytch has publicly committed to the DPF Principles and is listed on the official DPF participant list.
  • Privacy Policy: Our DPA explicitly outlines our DPF commitments, data processing practices, and provides information for individuals to contact us regarding privacy concerns.
  • Third-Party Management: We require all third-party vendors handling EU, UK, or Swiss personal data on our behalf to provide equivalent data protections.
  • User Rights: We provide mechanisms for individuals to access, correct, or request deletion of their personal information.
  • Dispute Resolution: We offer independent recourse mechanisms for addressing unresolved privacy complaints, as required by the DPF.
  • Security Measures: Robust technical and organizational security measures are implemented to protect all customer and end-user data.