20-minute walkthrough with 2–3 personalized examples on your real pages.
Email, chat, or 24/7 phone support included on every paid plan.
How Personyze supports GDPR-compliant personalization for our customers and their visitors.
Last updated: May 2026
Personyze is committed to helping our customers operate in full compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR. This page explains how Personyze is built to support GDPR-compliant personalization, the role we play in your data flows, and what we provide to help you meet your obligations as a controller.
For our complete privacy practices, see our Privacy Policy. The contractual terms governing GDPR processing are set out in the Data Processing Addendum (DPA) attached to our Terms & Conditions.
When you deploy Personyze on your website, app, or marketing channels, you are the data controller of the personal data collected from your visitors and customers. Personyze acts as a data processor, handling that data only on your documented instructions and only for the purposes you configure within the platform.
This relationship is governed by our DPA, which incorporates the European Commission’s Standard Contractual Clauses where personal data leaves the EEA, and the UK International Data Transfer Addendum for transfers subject to the UK GDPR. For Swiss data, we apply the additional modifications described by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Personyze provides a unified personalization layer across multiple channels — recommendations, A/B testing, dynamic landing pages, popups, social proof, push notifications, email personalization, and more. To deliver these experiences, the platform may collect, depending on what you choose to enable:
By default, Personyze builds pseudonymized visitor profiles based on behavior and interests, not on directly identifying information. You decide whether identifying fields (such as email or customer ID) are ever passed to Personyze.
As the controller, you are responsible for establishing a lawful basis for collecting and processing visitor data. For most personalization use cases in the EU and UK, this means obtaining valid consent through a properly configured cookie banner or consent management platform (CMP) before Personyze tracking begins. Personyze integrates with standard CMPs and exposes a JavaScript API for consent-gating — see our consent integration guide for implementation details.
Personyze provides the tooling required to honor your visitors’ GDPR rights:
Personyze is designed around data minimization. Key controls include:
Personyze uses a small set of vetted sub-processors to operate the Service (cloud hosting, email delivery, payment processing). All sub-processors are bound by data-protection obligations no less protective than those we owe you. A current list is available on request.
Where personal data leaves the EEA or the UK, we rely on Standard Contractual Clauses and the UK IDTA as appropriate; for Swiss data, we apply the FDPIC’s modifications.
Personyze applies administrative, technical, and physical safeguards consistent with industry practice for SaaS providers of comparable size and scope. These include encryption in transit (TLS), role-based access control under least-privilege principles, network protections, regular patching, written incident-response processes, personnel under confidentiality obligations with privacy and security training, and reputable cloud-hosting providers for physical security. Further detail is provided in Annex 2 of our DPA.
If Personyze becomes aware of a confirmed security incident affecting your data, we will notify you without undue delay and in any event within seventy-two (72) hours of confirmation, and will provide reasonable cooperation in any investigation, mitigation, and regulator-notification obligations under the GDPR.
Personyze retains personal data only as long as needed to provide the Service or as configured in your account. On termination, data is returned or deleted within ninety (90) days, subject to applicable legal-retention requirements and standard backup-rotation cycles. Aggregated or de-identified data that cannot reasonably be linked to a person is not subject to deletion.
Our standard DPA is incorporated by reference into our Terms & Conditions and applies automatically when you process EU/UK personal data through Personyze. If your organization requires a signed copy or has specific amendments, contact us at support@personyze.com.
For any GDPR question, request, or complaint:
Personyze Email: support@personyze.com Website: www.personyze.com