NUDAYOSH

BLOG · 2026-06-06

Where does my customer data actually go?

Every time you build an automation, you're giving an outside program access to something: names, emails, phone numbers, sometimes health or payment data of your customers. The uncomfortable question is simple: could you say, right now, where your customer data actually goes? If the answer is "not entirely," keep reading.

Automations move data, not just tasks

It's easy to think of an automation as "something that saves me work." But underneath, what it does is move information from one place to another. A form that lands in your inbox, goes to a sheet, is sent to an email service, gets copied to your CRM. At every hop, your customer's data travels — sometimes to servers in another country, to companies you didn't even know existed.

Why this is a legal issue, not just a technical one

GDPR — the European data protection law, which reaches any business handling Europeans' data — says something simple: you are responsible for your customers' data even if someone else processes it for you. If you pass data to an outside service, you're still the one who answers for it. "I didn't know where it went" is not an excuse that holds up against a complaint.

And we're not just talking fines. We're talking about your customers' trust the day they find out their data was wandering through places you didn't control.

The questions you should be able to answer

  1. What data do I collect? Names, emails, phone numbers, health data, payment data…
  2. Which services does it pass through? Every tool that touches that data counts, even if it's "just to send an email."
  3. Where are those services? Inside or outside Europe. Outside Europe there are extra rules.
  4. Do I have a contract with them? GDPR requires an agreement with each company that processes data for you.
  5. Do I collect more than I need? Many automations drag along data "just in case." What you don't need, you're better off not having.

The most common mistake: "just in case"

Most leaks don't come from a sophisticated hacker. They come from data that was where it shouldn't be: a sheet shared with half the world, a copy of the customer database in someone's personal email, a free service that "came in handy" and kept everything. The safest data is the data you don't collect or don't copy.

How we approach it

When we build custom automations, we first draw the path each piece of data travels: where it comes from, what it passes through, where it ends, and who touches it. That map, besides saving you legal headaches, almost always reveals steps that are unnecessary and data that wasn't needed.

Protecting your customers' data isn't a formality for us — it's part of the product. For websites, our security scan looks at exactly that: where data leaks out without you noticing.

Frequently asked questions

About customer data and GDPR in automations.

I just have a small website — does this apply to me?

Yes. GDPR applies to any business handling people's data in Europe, regardless of size. A small website with a contact form is already handling data.

Am I responsible if another company processes the data?

Yes. In the eyes of the law you remain the responsible party, even if someone else processes the data for you. That's why you need to know where it goes and have an agreement with each service that touches it.

Where do I start getting it under control?

By drawing your data's path: what you collect, which services it passes through, where those services are, and whether you collect more than you need. That map usually reveals steps and data that are unnecessary.