
Windsor.ai
Partially CompliantSwiss marketing data pipeline and attribution platform, SOC 2 Type II audited, with hosting region undisclosed.
Headquartered outside the EU/EEA, so a non-EU disclosure regime may apply alongside GDPR.
Paid
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | Switzerland |
| Ownership | Non-European |
| Foreign Disclosure Exposure | Non-EU jurisdiction |
| Data Hosting Location | UnknownNot disclosed. The security page at windsor.ai/security describes leveraging "the native physical and network security features of the cloud service" without naming the provider or region; read 2026-08-24. |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | Low Risk |
| SCCs in Place | |
| Last Verified | 24 August 2026 |
How we reached this
Company is Windsor Group AG, Switzerland; the site footer states "Made in Switzerland". Frequently assumed to be Finnish, which is wrong. Switzerland is outside the EU and EEA, so transfers are restricted under Chapter V GDPR, but it holds a European Commission adequacy decision, so no additional safeguards are needed and Schrems II risk is LOW. Exposure is OTHER_JURISDICTION on that basis. The security page publishes a SOC 2 Type II audit by Prescient Assurance, references a GDPR annex for the EU and UK and a sub-processor list, but does not name the cloud provider or hosting region, so dataHostingLocation is UNKNOWN and no DPA URL could be recorded. If the underlying cloud is US-operated, CLOUD Act reach over the host would apply regardless of Swiss adequacy, which is the question to put to the vendor before signing.
About Windsor.ai
Connectors and Attribution in One Layer
Windsor.ai sits between the platforms that generate marketing data and wherever a team wants to analyse it. Several hundred connectors cover the ad networks, analytics tools, CRMs and ecommerce platforms, and destinations include Looker Studio, Power BI, Tableau, BigQuery, Snowflake, Google Sheets and increasingly AI assistants reading the same unified dataset.
Multi-touch attribution modelling sits on top, which is the difference between this and a plain ETL connector. It is a direct competitor to Supermetrics and Funnel, both already listed here.
Swiss, Not Nordic
Windsor.ai is often assumed to be Finnish. Its own footer says "Made in Switzerland" and its security page names Windsor Group AG.
Switzerland matters for a European buyer in a specific way. It is outside the EU and the EEA, so sending personal data there is a transfer under Chapter V of the GDPR. It is also covered by a European Commission adequacy decision, which means that transfer needs no additional safeguards. In practice a Swiss processor is a low-friction choice for an EU controller, unlike a US or Indian one.
What is missing is the hosting detail. The security page describes leveraging "the native physical and network security features of the cloud service" without naming which cloud or which region. A SOC 2 Type II audit is published, a GDPR annex covering the EU and UK is offered, and a sub-processor list exists, but the underlying infrastructure is not disclosed on the public site.
Worth Asking Before You Sign
Marketing data pipelines carry more personal data than teams expect, since ad platform exports routinely include click identifiers and, in CRM connectors, contact records. Ask Windsor.ai which cloud provider and region hold that data, and get the answer in the DPA rather than in an email. If the underlying cloud is American, the Swiss adequacy decision does not remove CLOUD Act reach over the host.
Alternatives are listed under web analytics.
Key Features
Pros & Cons
Categories
Windsor.ai GDPR & data protection: common questions
Is Windsor.ai GDPR compliant?
Partly. Windsor.ai meets some of the requirements, with caveats worth reading before you commit. Windsor.ai is based in Switzerland, outside the EU/EEA.
Where does Windsor.ai store data?
Windsor.ai states: "Not disclosed. The security page at windsor.ai/security describes leveraging "the native physical and network security features of the cloud service" without naming the provider or region; read 2026-08-24.". Data is hosted in a location we have not been able to verify.
Does Windsor.ai offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for Windsor.ai. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover โIs Windsor.ai a European company?
No. Windsor.ai is based in Switzerland, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.
Which jurisdiction's laws apply to Windsor.ai?
Windsor.ai is based in Switzerland, outside the EU/EEA, so a non-EU disclosure regime may apply alongside GDPR. Transfers to the vendor rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses.
Where the EU-US Data Privacy Framework stands โRelated Tools

Plausible Analytics
Lightweight, open-source, cookie-free web analytics. Fully GDPR compliant with EU data hosting.

Matomo
Leading open-source web analytics. Self-host in the EU or use cloud with EU hosting.

Mouseflow
Heatmaps, session replay, and behavior analytics. Danish company with EU-only data processing.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at Windsor.ai and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.