Contracting party
The Terms of Service are an agreement between Klaviyo, Inc. (USA) and you.
Klaviyo is built for shops and thinks in profiles, not lists. That helps sell and makes consent more complicated: a profile can receive email without ever having agreed to it.
The Terms of Service are an agreement between Klaviyo, Inc. (USA) and you.
According to the sub-processor list, all existing accounts are hosted and processed in the United States. An EU data centre in Germany is available only to new accounts, chosen at account creation.
Klaviyo, Inc. is on the official list. Status on 3 October 2026: 'Active - Re-certification under Review', next recertification due on 2 February 2027.
The Data Processing Agreement forms part of the agreement and applies from its start, without a separate signature.
Lists are double opt-in by default and can be switched to single opt-in.
When someone signs up through a Klaviyo form, the profile stores the form ID and a timestamp, among other properties.
Consent is held per channel: email and SMS are tracked separately. Profiles marked 'Never subscribed', for example from a checkout without sign-up, can still receive email, but not SMS.
Without a consent column in the CSV, the one choice in the import dialogue applies to every contact in the file, for example all marked as subscribed.
New accounts send from a shared IP and a shared Klaviyo domain. A branded sending domain removes the 'via klaviyomail.com' label.
This page is not legal advice and we are not a law firm. We report what the vendor itself documents, with a date. Vendors change their terms; the linked source in its current version always prevails.
Klaviyo allows email to profiles that never consented, such as checkout customers. In Austria, marketing to them needs its own legal basis, usually the narrow existing-customer exemption. Without a filter on consent status, these profiles end up in flows and campaigns.
Without a consent column, the import marks the whole file with the same choice. Choosing 'subscribed' there turns every address into consent, without any proof being created.
Check double opt-in per list, add consent wording to forms, treat SMS separately from email.
Filter campaigns and flows on consent status and handle checkout customers separately, so 'Never subscribed' profiles do not receive marketing that needs consent.
Branded sending domain with SPF, DKIM and DMARC, data processing and US transfers in your records of processing, paragraph for the privacy notice.
No tool is compliant on its own; it depends on the setup. Klaviyo provides double opt-in per list, consent per channel, a data processing agreement and a Data Privacy Framework listing. The weak spots are profiles without consent that can still receive email, and imports.
According to the sub-processor list, existing accounts are hosted in the US; the EU data centre in Germany is only for new accounts at creation. For an existing account, transfers to the US remain, based on the Data Privacy Framework.
Technically Klaviyo allows it. In Austria, § 174 TKG 2021 requires prior consent for marketing email, with a narrow exemption for your own similar products to customers who could object free of charge at collection and in every email. Whether that applies to you is for your privacy adviser; we set up the filters accordingly.
Yes. Lists are double opt-in by default and can be switched to single opt-in. It does not apply to imports; there the consent column in the CSV counts.
The setup costs € 890 for your whole stack. The other tools we have checked the same way:
Tell us which tools you use and where your contacts come from. In the first call we will tell you whether € 890 covers it or whether more needs fixing, honestly either way.
Request the setup