
RedEye
Partially CompliantLondon marketing automation platform, part of the Dutch Spotler Group, ISO 27001 and ISO 27701 certified and CSA-accredited for inbox placement.
Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.
Paid
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | United Kingdom |
| Ownership | Non-European , owned by Spotler Group (Netherlands) |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | Unknown |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | View sub-processors |
| Schrems II Risk | Medium Risk |
| SCCs in Place | |
| Last Verified | 1 September 2026 |
How we reached this
UK company, number 04035064, VAT GB 710433874, UK/EMEA headquarters 1 Angel Court, 1st Floor North, London EC2R 7HJ, read 2026-09-01. Ownership fact worth surfacing: the compliance page states that RedEye is part of the Spotler Group, whose ISO 27001 ISMS covers RedEye and is externally audited annually. Spotler is already listed separately on this site as a Netherlands company, so RedEye and Spotler are not independent options, and RedEye is a UK operation with an EU parent rather than the more usual reverse. Certifications are the strongest in this tranche: ISO 27001 through the group ISMS, ISO 27701 for privacy information management (which very few marketing vendors hold and which is specifically GDPR-shaped), Certified Sender Alliance accreditation through eco (which has a direct effect on inbox placement at German mailbox providers), and DMA membership. RedEye also publishes a customer data processors page, which names Amazon Web Services EMEA and Telefónica UK Limited; publishing that list at all puts it ahead of most UK vendors here. PARTIAL because no processing region is stated for those processors and no DPA was located at a public URL. Exposure US_CLOUD_ACT on the AWS dependency. Ownership NON_EU on the UK HQ, with the Dutch parent recorded separately.
About RedEye
A UK Platform With a Dutch Parent
RedEye is a behavioural marketing automation platform built around a single customer view, aimed at sectors where repeat purchase is the whole game: retail, travel, museums and attractions. The product joins web behaviour to purchase history and drives lifecycle campaigns off the result.
The fact worth surfacing first is the ownership. RedEye is part of the Spotler Group, which this directory already lists separately as Spotler, a Netherlands company. So although RedEye is a UK operation with UK/EMEA headquarters at 1 Angel Court, London EC2R 7HJ, the group above it is Dutch.
That cuts both ways and both are worth knowing. If you were considering RedEye and Spotler as independent options, they are not independent. But it also means a UK vendor whose ultimate parent sits inside the EU, which is the opposite of the usual pattern in this directory, where the risk is an EU vendor with an American parent.
The Certifications Are the Strongest in This Tranche
- ISO 27001, through the Spotler Group information security management system, audited annually by an external party
- ISO 27701, the privacy information management extension, which very few marketing vendors hold and which is specifically about GDPR-shaped obligations rather than general security
- Certified Sender Alliance accreditation, the eco-run whitelisting programme, after what the company describes as a rigorous acceptance process and ongoing monitoring
- Membership of the DMA
ISO 27701 plus CSA is a stronger combination than almost any other vendor on this site publishes. CSA in particular has a direct practical effect on inbox placement at German mailbox providers.
Customer Data Processors, Published
RedEye publishes a customer data processors page, which names Amazon Web Services EMEA and Telefónica UK Limited among them. Publishing the list at all puts RedEye ahead of most of this tranche. AWS in the chain is why the row carries US CLOUD Act exposure, and no processing region is stated for it.
Company number 04035064, VAT GB 710433874.
Where It Fits
Against Spotler, its own parent, and Symplify and Dotdigital at a similar level. On published certifications, RedEye is the strongest of the four. See marketing automation.
Key Features
Pros & Cons
Categories
RedEye GDPR & data protection: common questions
Is RedEye GDPR compliant?
Partly. RedEye meets some of the requirements, with caveats worth reading before you commit. RedEye is based in United Kingdom, outside the EU/EEA.
Where does RedEye store data?
We could not locate a clear statement of where RedEye hosts data. Ask the vendor directly, or check their privacy policy and sub-processor list before signing.
Does RedEye offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for RedEye. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover →Is RedEye a European company?
No. RedEye is based in United Kingdom, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.
Is RedEye subject to the US CLOUD Act?
Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.
Schrems II compliance checklist →Who are RedEye's sub-processors?
RedEye publishes its sub-processor list at https://www.redeye.com/legal/customer-data-processors/. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.
Related Tools

Brevo
All-in-one marketing platform with email, SMS, CRM, and automation. French company, EU data hosting.

MailerLite
Email marketing and automation platform from Lithuania. EU data processing.

rapidmail
German email marketing with data exclusively hosted in Germany.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at RedEye and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.