Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document footer references a dedicated GDPR page, indicating that Kit maintains separate GDPR-specific documentation addressing EU data protection obligations applicable to users in the EU and EEA.
This analysis describes what ConvertKit's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision signals that Kit asserts GDPR compliance and directs EU users to a companion document, which may contain data processing terms, lawful basis disclosures, and data subject rights procedures relevant to institutional compliance assessments.
Interpretive note: The full operative GDPR documentation was not provided in the document extract; the scope and specific obligations of this reference cannot be confirmed from available content.
EU and EEA users are directed to a separate GDPR documentation page that is expected to address data subject rights, lawful basis for processing, and related protections under EU data protection law. The agreement's incorporation of this reference means GDPR-specific terms form part of the broader contractual framework for EU users.
Cross-platform context
See how other platforms handle GDPR Compliance Reference and similar clauses.
Compare across platforms →Monitoring
ConvertKit has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
(1) REGULATORY LANDSCAPE: This provision engages the General Data Protection Regulation, enforced by EU member state Data Protection Authorities. The explicit GDPR reference indicates Kit acknowledges applicability of EU data protection law to at least a portion of its user base. The UK GDPR and the UK Information Commissioner's Office may also be implicated for UK users. (2) GOVERNANCE EXPOSURE: Medium. The reference to a separate GDPR page rather than inline disclosure means the operative data processing terms, lawful basis assertions, and controller/processor designations must be sourced from a companion document not provided in this extract, creating a gap in institutional review without that document. (3) JURISDICTION FLAGS: EU and EEA users are the primary population for whom this reference creates heightened exposure. UK users face similar considerations under the UK GDPR. Non-EU users may have fewer enforceable rights under this framework unless Kit extends GDPR-equivalent protections globally. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations using Kit as a data processor for EU personal data should confirm whether Kit offers a Data Processing Agreement consistent with GDPR Article 28 requirements. The existence of a dedicated GDPR page suggests such an agreement may be available, but its terms require separate review. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should retrieve and review the GDPR documentation linked in the Kit footer, confirm the availability and scope of a Data Processing Agreement, and assess whether Kit's stated lawful bases for processing align with the organization's own consent and legitimate interest determinations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision signals that Kit asserts GDPR compliance and directs EU users to a companion document, which may contain data processing terms, lawful basis disclosures, and data subject rights procedures relevant to institutional compliance assessments.
EU and EEA users are directed to a separate GDPR documentation page that is expected to address data subject rights, lawful basis for processing, and related protections under EU data protection law. The agreement's incorporation of this reference means GDPR-specific terms form part of the broader contractual framework for EU users.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ConvertKit.