Why does pricing data need a different compliance conversation than other SaaS data?
Most SaaS compliance reviews are about personal data: whose data it is, what the lawful basis is, how long it is kept. A pricing platform holds something else — cost prices, margin floors, promotional calendars and the competitive strategy behind them. Losing that does not trigger a breach notification, but it does hand a competitor the map of your business.
That shifts the important questions. Lawful basis matters less; confidentiality terms, sub-processor disclosure, the jurisdiction whose courts enforce the contract, and which government can compel the vendor to produce data matter more. A vendor established in the EU answers the last question differently from one established outside it, regardless of where the servers sit.
What is the difference between "EU servers" and "established in the EU"?
Server location tells you where bytes rest. Establishment tells you which law governs the company holding them. A company established outside the EEA can rent EU data centre capacity and truthfully advertise EU hosting, while still being subject to disclosure obligations in its home jurisdiction.
Six of the seven vendors here are established in the EU: Omnia Retail, Pricefx, 7Learnings, Minderest, PriceEdge and Dealavo. Price2Spy is established in Serbia and processes in EU data centres — a legitimate arrangement that nonetheless needs a transfer mechanism, because the establishment and the servers are in different jurisdictions.
What should the data processing agreement actually name?
Four things, specifically. The full sub-processor list with locations, so the data map is complete rather than one layer deep. The retention period for both your uploaded data and the crawled competitor data, which are often governed differently. Whether your data is used to train models shared across customers — a live question for 7Learnings and any other machine-learning vendor. And the transfer mechanism, if any part of the chain sits outside the EEA.
A DPA that says "processing takes place in the EU" without naming sub-processors is not enough to complete a data map, and asking for the list is a normal request that a serious vendor answers without friction.
Do certifications like ISO 27001 and SOC 2 actually matter here?
They matter as evidence, not as jurisdiction. ISO 27001 certifies that an information security management system exists and is audited. SOC 2 Type II attests that specific controls operated effectively over a period, which is a stronger statement than a Type I snapshot. Neither says anything about which law governs the vendor.
7Learnings holds both, which is the strongest published position in this category and shortens a security review substantially. The other six vendors in this comparison do not publish an equivalent certification set, which does not make them insecure — it makes the review longer, because the assurance has to be gathered rather than referenced.
What does a pricing vendor review get wrong most often?
It stops at the vendor. The pricing platform is one layer; the crawling infrastructure, the cloud provider, the analytics stack and the support tooling behind it are the rest, and each is a sub-processor. A review that clears the vendor and never reads the sub-processor list has cleared the smallest part of the surface.
It also treats compliance as a one-time gate. Vendors change sub-processors, acquire companies and move workloads; Omnia Retail acquiring Patagona is an ordinary example of a change that alters a data map. A scheduled re-check, rather than a signature at purchase, is what keeps the answer true.