Webflow hosts user websites primarily on servers located in the United States, which has implications for compliance with EU data protection laws such as the GDPR. Here's how it works and what you need to consider if you're using Webflow in the Netherlands.
1. Where Webflow Stores Website Data
- Hosting Infrastructure: Webflow uses Amazon Web Services (AWS) and Fastly for content delivery. These services primarily host Webflow sites on servers in the United States.
- Submission Data: Form submissions are also stored on US-based servers unless exported or connected to an external integration.
2. GDPR Compliance of Webflow
- Webflow as a Data Processor: When handling visitor data (like contact forms), Webflow acts as a processor, while you are the controller under GDPR.
- Legal Grounds: Webflow provides a Data Processing Agreement (DPA) compliant with the GDPR, including Standard Contractual Clauses (SCCs) for data transfers to the US.
- Subprocessors: Webflow lists its subprocessors publicly, including AWS and Fastly, which also adhere to SCCs and have GDPR-compliant measures.
3. Using Webflow in the Netherlands
- Yes, you can use Webflow in the Netherlands without automatically violating GDPR, provided you take appropriate legal steps, such as:
- Sign Webflow’s DPA: Available via their Privacy Policy.
- Disclose Data Transfers: You must inform your users that form data or other personal data may be stored outside the EU (e.g., in the USA).
- Provide Consent Where Necessary: If using cookies, tracking scripts, or collecting personal information, use a cookie banner with consent options in accordance with the GDPR and the Dutch UAVG.
- Implement Opt-in Policies: Use explicit opt-in on forms where personal data is collected.
- Privacy Policy: Your site must include a clear privacy policy detailing these data practices.
4. Workarounds for EU Hosting (If Needed)
- Third-Party Form Handlers: Use services like Formspree EU or Netlify Forms (with EU data routing) to keep form data within the EU.
- Exporting CMS or Hosting Externally: You can export your site and host it on a compliant EU-based hosting provider, but CMS and dynamic features will be lost.
- Reverse Proxy with EU Cache/CDN: Some advanced users use reverse proxy setups to serve Webflow sites through EU-based CDNs (complex and unsupported by Webflow natively).
Summary
Webflow hosts data on US servers, but it provides GDPR-compliant measures via Standard Contractual Clauses. You can legally use Webflow in the Netherlands if you sign their DPA, disclose data processing, and ensure GDPR-compliant consent and privacy practices on your website.