Method
How a fact gets onto this site, what we refuse to record, and how to have us corrected.
Two rules
Every fact carries its source and its date. A row without a source URL and an observed date is not a fact. The loader enforces this: a single unsourced row and the whole vendor file is rejected rather than partly loaded, because a half-sourced page is worse than a missing one.
Observations are append-only. We never overwrite a fact. A new reading is a new row with a later date, so the current value is simply the newest one and the history comes free. That history is the only thing here that cannot be copied.
Where the facts come from
Public pages only: subprocessor lists, DPAs, trust centres, security and lifecycle pages. No authenticated scraping, no accounts created to see gated content, no terms of service broken. Where a page is gated, we record that it is gated and stop — that is the finding.
Roughly half of the pages in this registry cannot be read by a plain HTTP client: some return 403 without a browser, others render their content only after JavaScript. Those are fetched with a headless browser, at no more than one request every five seconds per host, with a user agent that identifies the crawler and links back here.
What the states mean
| Not stated | We found no statement on a page we could reach. Not the same as "no EU region exists". |
|---|---|
| Not declared | We read a lifecycle or security page and it states no support period. |
| Not yet collected | We have not looked. Never shown as "not declared" — that would manufacture a finding. |
| Service only | A pure service with nothing for you to run, so no support window attaches. Not a pass mark and not a gap: the question does not apply. |
| Refused to our client | The document exists and is not withdrawn, but an edge or bot filter answered our request with an error. Distinct from "not found". |
| EU region documented, terms not stated | The vendor documents an EU data location but says nothing about which plan reaches it or what it costs. |
| Gated | The document exists but sits behind a sales, NDA or access-request flow. |
| Partial | Our transcription covers part of a longer list. Labelled everywhere it affects a count. |
| Claimed | The vendor asserts a certification; we have not seen the certificate itself. |
What we will not do
We do not rate, score, rank or certify vendors, and we do not publish a compliance verdict. Compliance attaches to your use of a tool, not to the tool. Anything computed here is arithmetic over the facts on the page — a count of subprocessors outside the EEA, a missing declaration — shown with its inputs so you can check it.
We also do not editorialise a fact into an accusation. "This vendor has not published a support period" is a fact. "This vendor is non-compliant" is a claim we are not qualified to make and would not make if we were.
Changes and review
A change is detected by comparing a new reading against the last one. It is not published until a human has reviewed it. Unreviewed differences exist in the database and are visible to nobody. Currently 18 reviewed changes are published across 20 vendors.
Corrections
If a fact here is wrong, the fastest fix is to point at the page that says otherwise. We will add a new observation with that source and its date; the old reading stays visible, because removing it would break the only guarantee this site makes. Corrections are logged with dates, and we never quietly rewrite history.