Back to Tools
Tidio logo

Tidio

Partially Compliant

Live chat and Lyro AI agent platform whose Terms name the operating entity as Tidio LLC, a California company, with a Polish office in Szczecin as joint controller only.

๐Ÿ‡ช๐Ÿ‡บEU HostedNon-EU ยท United States

Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.

Freemiumfrom $24.17/month
Tidio website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryUnited States
OwnershipNon-European
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
Global"We mainly process the data you submit within the EEA and the servers located there. Note, however, that TIDIO LLC, as the entity entering into the Agreement with you, is a U.S.-based entity, and therefore some of your data may be transferred from the EEA and/or the United Kingdom and processed in the United States" (tidio.com/privacy-policy/, last updated March 12, 2026, read raw 2026-09-07). Annex A of the Terms additionally lists per-provider hosting regions for AI sub-processors: OpenAI L.L.C. (EU), Anthropic PBC (US), Google Cloud Platform (EU).
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified7 September 2026

How we reached this

Terms of Service (tidio.com/terms/, last updated March 12, 2026) name the operating entity in the opening line: "Tidio LLC (with its registered office in 1301 Sansome Street, San Francisco, California 94111, United States of America), a California limited liability company", governed by California law with venue in San Francisco County, read raw (curl, not WebFetch summary) 2026-09-07. Tidio LLC is stated as controller of user/account/website data; Tidio Poland Sp. z o.o. (Szczecin, Wojska Polskiego 81) is named as an additional joint controller in the Privacy Policy but is not the Agreement counterparty. This is the pattern this directory already flags for folk.app (see seed-euromakers-gap.ts): a product widely marketed under a European city, where the operating/contracting entity named in the vendor's own legal documents is American. ownershipOrigin is set NON_EU and hqCountry "United States" on that basis, matching folk's treatment, rather than crediting the Szczecin office as headquarters or treating this as an EU-HQ-with-foreign-parent case (the US entity is the primary one, not a parent above an EU subsidiary). extraterritorialExposure is US_CLOUD_ACT at the entity level: Tidio LLC itself, not merely its infrastructure vendor, is a US company. PARTIAL rather than COMPLIANT despite genuinely strong documentation: the Privacy Policy sets out legal bases, retention periods and data-subject rights in detail, participates in the EU-US Data Privacy Framework (with UK and Swiss extensions) in addition to Standard Contractual Clauses, and a signed DPA is incorporated by reference into the Terms and linked from the Terms page, giving dpaEvidence PUBLISHED. sccInPlace true on the same DPF/SCC combination. schremsIIRisk MEDIUM rather than LOW because, DPF certification aside, the controlling entity is itself American and the same document states some EEA/UK data is processed in the United States. dataHostingLocation GLOBAL: EEA processing is stated as the main case, but a US entity relationship and named US-hosted sub-processor (Anthropic) both apply.

About Tidio

Widely Listed as Polish, Legally a California LLC

Tidio started in Szczecin, Poland, and is still routinely described as a Polish company, including by other European software directories. Reading its own Terms and Privacy Policy raw (not a summary) tells a different story about who you are actually contracting with.

What the Documents Actually Say

The Terms open with the operating entity:

Tidio LLC (with its registered office in 1301 Sansome Street, San Francisco, California 94111, United States of America), a California limited liability company... operates the website and services available through and as described on the www.tidio.com website.

And later, on data protection specifically:

Tidio LLC is the controller of your personal data (a) as a Tidio user (in connection with the purchase of Services and settlements) and (b) as a visitor to the www.tidio.com website... Tidio Poland (as a company in the TIDIO capital group), is also the controller of your personal data.

Tidio Poland Sp. z o.o., Szczecin, is a genuine joint controller, not a nominal one; it appears throughout the Privacy Policy alongside Tidio LLC. But it is not the entity whose Terms you accept, and it is not the entity the Agreement names as the counterparty. Governing law is California, and the venue for disputes is San Francisco County.

This is the same shape this directory flags for folk: a product widely listed under a European country by team location, where the legal document you actually sign names a US corporation as the operating entity. It is not the reverse pattern (an EU HQ with a foreign parent); the entity you contract with is itself American, with a Polish office rather than a Polish parent with a US office. Ownership origin is recorded as NON_EU on that basis, and HQ country as United States, matching how folk is recorded in this directory rather than crediting the Szczecin office as the headquarters.

The Product

Tidio bundles Live Chat, the Lyro AI Agent (resolves a stated 67% of customer queries automatically), a Help Desk for email tickets, and Flows for proactive automation, plus integrations across Shopify, WordPress, Squarespace and more. Its Terms carry a detailed AI supplementary section naming three sub-processors for AI features: OpenAI, L.L.C. (US, EU hosting region stated), Anthropic PBC (US, US hosting region stated) and Google Cloud Platform (EU hosting region stated), each contractually barred from training on customer data.

Pricing

Starter from roughly $24/month, Growth around $49/month, Plus from $300/month plus usage, and a custom Premium managed tier. The Lyro AI Agent is a separate add-on starting around $32.50/month. A free plan exists with limited conversations.

Data Transfers, Data Privacy Framework and a Published DPA

The Terms flag a DPA prominently and incorporate it by reference for EU, UK and Swiss users, and a signed copy is linked from the Terms page ("Agreement for entrusting the processing of personal data"), so this is one of the stronger DPA postures among the tools reviewed here, US ownership notwithstanding. Tidio LLC also certifies to the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US DPF, in addition to relying on Standard Contractual Clauses as a fallback safeguard.

The Part That Matters for a Buyer

None of this means Tidio mishandles data; its Privacy Policy is unusually thorough on legal bases, retention and rights, and it has real DPF certification rather than just a claim of one. It means a buyer choosing Tidio because it is "European" is choosing on a fact that its own Terms of Service do not support: the entity you sign with is a California LLC, reachable under the US CLOUD Act regardless of where the data physically sits.

Where It Fits

Compare against Dixa, a genuinely Danish-incorporated alternative with native phone support, in Live Chat & Chatbots.

Key Features

Live Chat with multilanguage support and mobile apps
Lyro AI Agent, stated to resolve up to 67% of customer queries automatically
Help Desk for unified email ticket management
Flows for proactive, rule-based automation
Integrations across Shopify, WordPress, Squarespace, Wix and Magento
EU-US Data Privacy Framework certification (with UK and Swiss extensions) alongside SCCs
Named per-provider hosting regions for AI sub-processors in Annex A of the Terms

Pros & Cons

Genuinely detailed Privacy Policy on legal bases, retention and data-subject rights
Real EU-US DPF certification, not just a claim, plus SCCs as a fallback
Signed DPA incorporated by reference and linked directly from the Terms page
Free plan available, and paid tiers start well below most competitors here
Names hosting regions per AI sub-processor rather than staying generic about "AI providers"
Operating entity is Tidio LLC, a California LLC, not the Polish company it is usually marketed as
Governing law is California and disputes are heard in San Francisco County, not the EU
US_CLOUD_ACT exposure applies at the entity level, not just to an infrastructure vendor
One named AI sub-processor (Anthropic) is stated as US-hosted, not EU-hosted
Higher tiers (Plus, Premium) move to opaque or usage-based pricing

Tidio GDPR & data protection: common questions

Is Tidio GDPR compliant?

Partly. Tidio meets some of the requirements, with caveats worth reading before you commit. Tidio is based in United States, outside the EU/EEA, data is hosted across multiple regions globally.

Where does Tidio store data?

Tidio states: ""We mainly process the data you submit within the EEA and the servers located there. Note, however, that TIDIO LLC, as the entity entering into the Agreement with you, is a U.S.-based entity, and therefore some of your data may be transferred from the EEA and/or the United Kingdom and processed in the United States" (tidio.com/privacy-policy/, last updated March 12, 2026, read raw 2026-09-07). Annex A of the Terms additionally lists per-provider hosting regions for AI sub-processors: OpenAI L.L.C. (EU), Anthropic PBC (US), Google Cloud Platform (EU).". Data is hosted across multiple regions globally. An EU region is available.

Does Tidio offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Tidio. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover โ†’

Is Tidio a European company?

No. Tidio is based in United States, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.

Is Tidio subject to the US CLOUD Act?

Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is. Standard Contractual Clauses are in place for transfers, which is the required safeguard but does not override a lawful US order.

Schrems II compliance checklist โ†’

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Tidio and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.