Is Smokeball GDPR Compliant?
What You Need to Know
A complete breakdown of Smokeball's privacy posture, sub-processors, and what your agency needs to do to use them legally.
Overall Status
Compliant with Configuration
Vendor Overview
Headquarters
United States
Category
Marketing / Analytics
Transfer Mechanism
Standard Contractual Clauses (SCCs) + Data Privacy Framework
Sub-processors
12 known sub-processors
GDPR Compliance Status
- Data Processing Agreement (DPA) AvailableSmokeball provides a standard DPA that you must sign or accept in their settings before processing personal data.
- EU Hosting AvailableYou can select an EU data center (e.g., Frankfurt or Dublin) during setup to keep data within the EEA.
What you need to do
To use Smokeball compliantly as an agency, you must:
- Sign their Data Processing Agreement (DPA).
- Configure EU hosting in your account settings (if applicable).
- Update your Record of Processing Activities (ROPA).
- List them in your Privacy Policy as a sub-processor.
Track Smokeball's compliance automatically.
Stop manually checking for vendor updates. Custodia tracks Smokeball alongside the other tools agencies commonly run, alerting you if their DPA or hosting changes.
Start free assessment