Coming soon: GDPR compliance for Teable 🇪🇺

Hi everyone :waving_hand:

Over the past months, many of you in Europe have asked us about GDPR, both here in the community and in emails to our team (thanks @steph47dh7, @t.s.123.teable, @ChrisHK, @Javier_Pastora and @Francesco_Li_Petri for raising it). For a lot of you, it’s the one thing standing between you and Teable Cloud, or between you and a client’s security review.

Until now, our answer has been “it’s on our radar, but we don’t have a timeline yet.” Today we have a better answer: we’re officially committing to GDPR compliance, and we want you to hear it here first.

Timeline :spiral_calendar:

  • Target: March 2027
  • No later than: June 2027

How we’re doing it

We’re working with a specialist compliance partner. Teable’s security controls will be independently audited, and Teable will go through third-party penetration testing. We’re not grading our own homework.

What we plan to deliver

A Data Processing Agreement (DPA) your organization can sign, including Standard Contractual Clauses (SCCs) for international data transfers. Final scope will be confirmed with our auditors.

Follow our progress

Our Trust Center is now live. It shows where our GDPR work stands, the security controls we have in place, and our current sub-processors. You’ll also find the status of our SOC 2 Type II and ISO 27001 work there.

Self-hosting Teable?

If you self-host, your data stays on your own infrastructure, so that remains the most direct option if you need full control today. This program is mainly about Teable Cloud and how Teable as a company handles personal data.

We’d love to hear from you :speech_balloon:

Is GDPR holding you back right now? Tell us a bit about your use case in the replies, and vote below:

How does GDPR affect you today?
  • It’s blocking a project or client work right now
  • I self-host Teable mainly because of GDPR
  • My clients or legal team ask about it, but it’s not a blocker
  • Nice to have, not urgent
0 voters

Want to know when it’s ready? Set this topic to Watching with the :bell: button at the bottom, and you’ll be notified when we post the update here.

10 Likes

This is awesome, thank you!!

I just love teable. It’s so good to store and structure data and build real - even very good looking and useful - apps on top of it.

I’m already building small client fullfillment apps.

With the new GDPR compliance it allows me to go more bullish into delivering a small SaaS for them as additional value.

For this, 3 things would help the most:

a) gdpr and European cloud

b) some clients have problems with the login otp emails. Their enterprise email servers block them

c) allow small customization to login otp emails. Removing teable logo, change text a bit. So that it looks more like real own software.

B and C might be quickly fixed if I could whitelist a user/client with their company email and just set them a password instead of otp.

Hope that helps

Teable is 10/10, I use it every day

1 Like

Oh, and one more wishlist: publishing to slugs instead of only cnames.

Use case:

with that, I could quickly build custom market maps and client value leads for cold dm/outrach.

Example: build a Xyz-datapreview and quickly publish to domain.com/client-name

This sparks interest by itself and is easier to manage than making custom domains for each client.

Not sure how difficult or useful it is for other people, just my wishlist :sweat_smile:

Again: thanks for bringing GDPR on the table!

Thank you so much for this, I’m really happy to see it! I’m a freelance developer in Italy and I build apps on Teable for my clients. GDPR compliance is exactly what was missing to bring real client data on board, and it opens the door to bigger and more complex projects.

Thanks for listening to the community. Looking forward to growing together with Teable!

2 Likes

@Gary @Leo this is great news for my German-based company. :tada:
I see teable evolving and evolving over the past months - this is very nice to see. :+1:
If you would like to get feedback regarding wording in the DPA wording feel free to reach out.
Post scriptum:
What I would love to see is DPF self-certification. This would be an additional big bonus point for me.

2 Likes

Hi @steph47dh7,

Thank you so much for the kind words! Hearing “10/10, I use it every day” really made our day, and it’s great to see you building client fulfillment apps on Teable. Here’s where we stand on each point:

a) GDPR & European cloud
GDPR is our first priority. As outlined above, it includes a DPA with Standard Contractual Clauses (SCCs) for international data transfers, so it will cover the compliance requirements. As for hosting servers in Europe, we’ll keep a close eye on feedback after the GDPR rollout and evaluate from there.

b) & c) Login OTP emails
Good news: you can already do both by describing what you need to the AI in Teable. For example, you can let whitelisted users sign in with their company email and a password instead of OTP, or adjust the wording of the login email.

About the Teable logo: when login emails are sent through Teable’s own email service, we’re required to include the Teable logo for compliance reasons, since Teable is the actual sender. To remove it, tell the AI you want to use your own email service and give it your email service details (e.g., SMTP settings). Once the emails go out through your own service, the Teable logo is removed. Sending from your own domain can also help with enterprise email servers that block the OTP emails.

Publishing to slugs (domain.com/client-name)
Personalized data previews for outreach is a really clever use case! To be honest, though, this one is hard for us to support right now.

A custom domain (CNAME) points a whole address, like app.domain.com, to Teable. But domain.com/client-name is a page inside your own website, and domain settings can’t send just that one page to Teable while the rest stays on your site. Making it work would need extra server setup on your side, which tends to break easily.

In the meantime, one simple workaround is to set up a redirect on your own site from domain.com/client-name to the published app. You still get a clean, personal link for outreach without managing a custom domain per client.

Thanks again for the thoughtful feedback. It really helps us shape Teable, so keep it coming!

2 Likes

Hi @t.s.123.teable,

Thank you so much for the kind words. It means a lot to hear that you’ve noticed Teable’s progress over the past months, and we’re glad this update is good news for your company.

We also appreciate your offer to review the DPA wording, and we may take you up on it.

Thanks also for raising DPF self-certification. We’ve noted it and will look into it as part of our compliance roadmap.

Thanks again for your continued support!

1 Like