Compliance & Certifications
General Data Protection Regulation (EU) — HeyDrop is fully GDPR compliant with robust data protection practices and user rights implementation.
System and Organization Controls — HeyDrop is in SOC 2 readiness phase, with security controls and evidence collection in place ahead of formal certification.
All data is encrypted at rest using AES-256 via AWS Key Management Service and in transit using TLS 1.2+. Secrets are managed with AWS Secrets Manager.
Our primary infrastructure partner AWS is certified under the EU-US DPF, enabling lawful data transfers between regions.
California Consumer Privacy Act — HeyDrop respects all CCPA requirements including data access, deletion, and opt-out rights.
CookieYes consent platform — We provide transparent cookie and data collection consent options for all users.
Documentation & Resources
Detailed information about our infrastructure, encryption, authentication, and monitoring practices.
→ Read more Data Processing AgreementOur Data Processing Agreement (DPA) for organizations processing customer data.
→ Read more Subprocessor ListComplete list of third-party vendors and services that process customer data on our behalf.
→ Read more Privacy PolicyOur comprehensive privacy policy detailing data collection, use, and user rights.
→ Read more Terms of ServiceLegal terms governing your use of HeyDrop and our services.
→ Read more Data DeletionInstructions for requesting account deletion and permanent data removal.
→ Read more