Legal
Data processing
What personal data we process on your behalf, where it lives, how long we keep it, and who else touches it.
Last updated 27 July 2026
Roles
For personal data contained in the email you send through the platform, you are the controller and we are the processor. We process it only to provide the service and only on your documented instructions, of which your use of the API is one.
What we process
- Recipient email addresses and message subjects
- Delivery, bounce and complaint events, including diagnostic codes returned by receiving mail servers
- Suppression entries, which by their nature record that an address bounced or complained
- Sender addresses and the domains they belong to
Message bodies and attachments are used to construct the outgoing message and are not retained afterwards.
Location and retention
Application data is stored in Germany. Our event queue and template storage are in AWS us-east-1. Your email itself is sent from whichever AWS region you configure, in your own account.
Message and event retention is a setting you control, from zero days up to your plan's maximum. Setting it to zero means we ingest events to update delivery state and retain nothing.
On termination we delete your data within thirty days, except where a longer period is required by law.
Your rights as a controller
You can export message and event data through the API at any time, and delete it by lowering retention or deleting the organization.
Because inbound personal data reaches us at your instruction, requests from data subjects should come to you first; we will assist with any that require action on our side.
Signing a DPA
This page describes our actual processing. It is a description, not an executed agreement — we would rather say that than present generated text as a contract.
A signable DPA including Standard Contractual Clauses is available on request, and we will review yours if you would rather use your own paper.