Fly.io certifies adherence to the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, and states that DPF Principles prevail over the Privacy Statement in the event of conflict. This certification covers personal information transferred from the EU, UK, and Switzerland.
This analysis describes what Fly.io's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal mechanism Fly.io asserts for transatlantic data transfers from the EU, UK, and Switzerland, and creates FTC-enforceable commitments. The DPF certification, if current and valid, provides a recognized transfer mechanism under GDPR, but the certification's adequacy depends on its scope and continued validity on the U.S. Department of Commerce registry.
The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.
View change record →Under this provision, EU, UK, and Swiss users' personal information is transferred to and processed in the United States under the DPF framework, and DPF Principles govern in the event of any conflict with the Privacy Statement. Users may exercise DPF-based rights including access, correction, and recourse.
Cross-platform context
See how other platforms handle EU-U.S. Data Privacy Framework Certification and similar clauses.
Compare across platforms →"Fly.io complies with the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework (collectively, "DPF" and the personal information collected in reliance on the DPF is "European Personal Information") as set forth by the U.S. Department of Commerce. Fly.io has certified to the U.S. Department of Commerce that it adheres to the DPF Principles with regard to the processing of European Personal Information. If there is any conflict between the terms in this Privacy Statement and the DPF Principles, the DPF Principles shall govern.Excerpt from Fly.io's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (transfers to third countries), the UK GDPR international transfer framework, and the Swiss FADP.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the legal mechanism Fly.io asserts for transatlantic data transfers from the EU, UK, and Switzerland, and creates FTC-enforceable commitments. The DPF certification, if current and valid, provides a recognized transfer mechanism under GDPR, but the certification's adequacy depends on its scope and continued validity on the U.S. Department of Commerce registry.
Under this provision, EU, UK, and Swiss users' personal information is transferred to and processed in the United States under the DPF framework, and DPF Principles govern in the event of any conflict with the Privacy Statement. Users may exercise DPF-based rights including access, correction, and recourse.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Fly.io.