Switching your print on demand supplier? Get in touch with us here

Gelato Trust Centre

Gelato is a global print-on-demand platform serving 32 countries and 5+ billion people. The company holds ISO/IEC 27001 certification, follows GDPR, encrypts all data at rest and in transit, uses AWS hosting with EU data residency options, and performs regular penetration testing to maintain security while enabling businesses to scale globally.

[email protected]

3D illustration of a web login screen with a user icon and password field, surrounded by a shield with a checkmark and a padlock, on a gradient background.

Compliance

ISO 27001 Certified logo with a globe design, indicating Information Security Management System compliance.ISO 27001 Certification

Controls

A blue magnifying glass with a fingerprint inside, symbolizing identity verification or security analysis.Data & Privacy

  • Data Processing Agreements (DPAs) tailored for GelatoCreate and GelatoConnect, outlining processor/controller responsibilities, regularly reviewed & updated

  • Policies for secure data retention, classification and disposal

  • Procedures for responding to data deletion requests

  • Minimal collection of personal data, limited to necessary purposes

  • Encryption is enforced for data transit and at rest

Two interlocking blue chain links on a white background, symbolizing connection or linkage.Infrastructure Security

  • Regular system maintenance and security vulnerability patching

  • Routine backups of production data to secure off-site locations

  • Intrusion detection and continuous network monitoring

  • Privileged access to databases and networks strictly limited

  • Multi-factor authentication required for remote access

A blue shield icon with a password symbol, featuring four asterisks, representing security and protection.Internal Security Procedures

  • Frequent vulnerability scanning and prompt remediation

  • Annual continuity and disaster recovery (BC/DR) plan testing

  • Regular incident response plan reviews and tests

  • Defined access control request and approval procedures

  • Comprehensive vendor management and security reviews

A blue 3D box with a slot on top and a checkmark symbol in front, indicating approval or completion.Product Security

  • Annual penetration testing with vulnerability remediation plans

  • Secure data encryption for both stored data and transmissions

  • Defined vulnerability management and system monitoring policies

  • Security requirements integrated into the development lifecycle

  • Automated security testing integrated into CI/CD pipelines

Blue 3D icon of an ID card with a person silhouette and horizontal lines representing text.Organizational Security

  • Employee background checks performed during onboarding

  • Mandatory regular security awareness training

  • Confidentiality agreements for employees and contractors

  • Secure electronic asset disposal and documented destruction process

  • Established whistleblower policy with anonymous reporting channels

A blue magnifying glass with a fingerprint inside, symbolizing identity verification or security analysis.Data Collected 

  • Email address

  • Postal address

  • Phone number

  • Password

  • IP Addresses 

  • Payment information

  • Additional data required for specific service functionalities, configurations, or operational requirements, depending on the Gelato service you use.

For further information, please review Gelato's Privacy Policy here: https://www.gelato.com/legal/privacy 

Our key subprocessors

Orange cloud and sun icon, with a flat, minimalist design, symbolizing cloud technology or weather.Cloudflare

aws logoAWS

google cloudGoogle Cloud

logoGoogle Tag Manager

claudeClaude AI

datadogDatadog

jira logoJira

airtableAirtable

sendgridSendgrid

elasticElastic

googleGoogle Workspace

microsftMicrosoft 365

A more detailed list of subprocessors can be found on our Legal Page: (a) for GelatoCreate in the Data Processing Terms and (b) for GelatoConnect in the Data Processing Agreement

Trust & Security FAQ

For more detailed information, please visit our Help Center.