Back to Tools
Centra logo

Centra

GDPR Compliant

Swedish commerce platform for fashion and lifestyle brands, publishing a versioned sub-processor list with EU data centres by default.

πŸ‡ΈπŸ‡ͺSwedenπŸ‡ͺπŸ‡ΊEU HostedπŸ‡ͺπŸ‡Ί European

Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.

Paid
Centra website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountrySweden
OwnershipEuropean-owned
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
European UnionSub-processor list version 12.1, 19 January 2026: "DigitalOcean, LLC, 101 6th Avenue, New York ... Cloud services and infrastructure provider for the Centra Platform. EU (default)" and the same entry for "Amazon Web Services, Inc., 410 Terry Avenue North, Seattle". Source: centra.com/legal/sub-processors-version-9.pdf (read 2026-08-24).
EU Servers Available
Data Processing AgreementView DPA
Sub-processor ListView sub-processors
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified24 August 2026

How we reached this

Centra Technology AB, Torsgatan 26, 113 21 Stockholm, Sweden, named in the privacy policy, which also identifies IMY as its supervisory authority. Subsidiaries listed as Centra Technology Polska Sp. z o.o. in WrocΕ‚aw and Centra Technology UK Limited in London, both development and support only. EU-owned. The versioned public sub-processor list names DigitalOcean, LLC and Amazon Web Services, Inc., both US-headquartered, as the cloud and infrastructure providers with a data centre location of "EU (default)", and Hetzner Online GmbH in Germany for monitoring and logging. Data therefore sits in the EU but is held by US-owned providers, so exposure is US_CLOUD_ACT and Schrems II risk MEDIUM. COMPLIANT on the strength of a published DPA, a versioned and dated sub-processor list with data centre locations, published records of processing activities and documented technical and organisational measures, which is the most complete public compliance set of any platform in this category.

About Centra

Built for Fashion, Direct and Wholesale

Centra is narrower than the general platforms on this list and better for it. Fashion brands sell the same catalogue to consumers and to wholesale buyers with different prices, terms and seasons, and Centra models that natively rather than treating wholesale as an afterthought.

Size and colour variants, drops, pre-orders, market-specific assortments and returns are all first-class. Nordic and European fashion brands are its natural customer base.

Documentation Other Platforms Should Copy

Centra publishes a sub-processor list as a versioned PDF, currently version 12.1 dated January 2026, with an information classification on every page. It names each sub-processor, its headquarters, what it does and the data centre location.

Read that document and the picture is clear rather than reassuring, which is the point. The cloud providers are DigitalOcean, LLC of New York and Amazon Web Services, Inc. of Seattle, both American companies, and both are listed with a data centre location of "EU (default)". Hetzner Online GmbH in Germany handles monitoring and logging. Subsidiaries in Poland and the United Kingdom provide development and support.

So: Swedish company, EU data centres, American cloud providers. The data sits in Europe and is held by companies a US court can order to produce it. Centra has not hidden this; it has published it in a form that let this assessment be written from primary evidence in a few minutes.

A DPA and records of processing activities are published at stable URLs alongside it.

The Judgement

If your requirement is EU data residency with documented processors, Centra meets it comfortably and provably. If your requirement is that no American company can be compelled to produce your data, the cloud layer does not meet it, and no platform on this list that runs on a hyperscaler will.

More in ecommerce platforms.

Key Features

Headless commerce for direct-to-consumer and wholesale
Native fashion catalogue model with variants and drops
Market-specific assortments, pricing and currencies
Pre-orders and season management
Returns and exchange handling
Published DPA, versioned sub-processor list and records of processing

Pros & Cons

Swedish company with EU data centres stated as the default
Versioned, dated sub-processor list naming every provider and location
Publishes a DPA and records of processing activities at stable URLs
Wholesale and direct-to-consumer on one catalogue
Cloud providers are DigitalOcean and AWS, both US-owned, so CLOUD Act reach applies
Narrow fit outside fashion and lifestyle retail
Pricing is quote-only with no public tiers

Centra GDPR & data protection: common questions

Is Centra GDPR compliant?

Yes. On the evidence we checked, Centra meets the requirements European businesses usually need. Centra is a European company headquartered in Sweden, data is hosted within the European Union, and a Data Processing Agreement is published.

Where does Centra store data?

Centra states: "Sub-processor list version 12.1, 19 January 2026: "DigitalOcean, LLC, 101 6th Avenue, New York ... Cloud services and infrastructure provider for the Centra Platform. EU (default)" and the same entry for "Amazon Web Services, Inc., 410 Terry Avenue North, Seattle". Source: centra.com/legal/sub-processors-version-9.pdf (read 2026-08-24).". Data is hosted within the European Union.

Does Centra offer a Data Processing Agreement (DPA)?

Yes. Centra publishes a DPA at https://centra.com/legal/dpa/latest. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.

What a DPA has to cover β†’

Is Centra a European company?

Yes. Centra is headquartered in Sweden and, as far as we can establish, European-owned.

Is Centra subject to the US CLOUD Act?

Indirectly. Centra itself is European-owned and headquartered in Sweden, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is.

Schrems II compliance checklist β†’

Who are Centra's sub-processors?

Centra publishes its sub-processor list at https://centra.com/legal/gdpr/sub-processors/latest. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Centra and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.