GDPR Compliance

Last updated: December 17, 2025

Unosend is fully compliant with the General Data Protection Regulation (GDPR). We take data protection seriously and have implemented comprehensive measures to protect your data. This document outlines our commitment to GDPR compliance and the measures we have in place.

1. Our Commitment

Unosend is committed to GDPR compliance across all aspects of our service. We act as a Data Processor on behalf of our customers (Data Controllers) when processing email data through our API. We have implemented technical and organizational measures to ensure the security and privacy of all personal data processed through our platform.

2. Data Processing Agreement

We offer a Data Processing Agreement (DPA) that outlines our obligations as a data processor under GDPR Article 28. The DPA includes:

  • Nature and purpose of data processing
  • Types of personal data processed
  • Security measures implemented
  • Sub-processor obligations
  • Data subject rights assistance
  • Data breach notification procedures

You can view our full Data Processing Agreement at /dpa or contact us at legal@unosend.co for a signed copy.

3. Data Location & Storage

Your data is processed and stored in the following locations:

ServiceProviderLocation
Primary DatabaseSupabase (PostgreSQL)EU (Frankfurt, Germany)
SMTP InfrastructureContabo GmbHGermany
Application HostingVercelGlobal (Edge)
Payment ProcessingDodo PaymentsIndia

4. Sub-Processors

We use the following sub-processors to provide our services. All sub-processors are contractually bound to comply with GDPR requirements:

ProviderPurposeLocation
Supabase, Inc.Database & AuthenticationEU (Frankfurt)
Dodo PaymentsPayment ProcessingIndia
Vercel, Inc.Application HostingGlobal (Edge)
Contabo GmbHSMTP Server InfrastructureGermany
Better Stack, Inc.Uptime MonitoringEU

5. Data Subject Rights

Under GDPR, individuals have the following rights which we fully support:

  • Right of Access — Request a copy of personal data we hold
  • Right to Rectification — Correct inaccurate personal data
  • Right to Erasure — Request deletion of personal data
  • Right to Restrict Processing — Limit how we use your data
  • Right to Data Portability — Export data in a machine-readable format
  • Right to Object — Object to processing based on legitimate interests

To exercise any of these rights, please contact privacy@unosend.co. We will respond within 30 days.

6. Data Breach Notification

In the event of a personal data breach, we will notify affected customers within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Our notification will include:

  • Nature of the breach
  • Categories and approximate number of affected individuals
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

7. Technical & Organizational Measures

We implement the following security measures to protect your data:

  • TLS 1.3 encryption in transit
  • AES-256 encryption at rest
  • Regular security audits
  • Access controls & authentication
  • Automated daily backups
  • DDoS protection at edge
  • API rate limiting
  • Secure API key hashing (SHA-256)

8. Data Retention

We retain data only as long as necessary:

Data TypeRetention Period
Email content & metadata30 days
Email logs & analytics90 days
Account dataUntil account deletion
Billing records7 years (legal requirement)

9. International Data Transfers

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements. This includes the use of Standard Contractual Clauses (EU SCCs) approved by the European Commission. Details of these transfers and safeguards are outlined in our Data Processing Agreement.

10. Contact

If you have any questions about our GDPR compliance or need a Data Processing Agreement, please contact us: