GDPR Compliance
Last updated: December 17, 2025
Unosend is fully compliant with the General Data Protection Regulation (GDPR). We take data protection seriously and have implemented comprehensive measures to protect your data. This document outlines our commitment to GDPR compliance and the measures we have in place.
1. Our Commitment
Unosend is committed to GDPR compliance across all aspects of our service. We act as a Data Processor on behalf of our customers (Data Controllers) when processing email data through our API. We have implemented technical and organizational measures to ensure the security and privacy of all personal data processed through our platform.
2. Data Processing Agreement
We offer a Data Processing Agreement (DPA) that outlines our obligations as a data processor under GDPR Article 28. The DPA includes:
- Nature and purpose of data processing
- Types of personal data processed
- Security measures implemented
- Sub-processor obligations
- Data subject rights assistance
- Data breach notification procedures
You can view our full Data Processing Agreement at /dpa or contact us at legal@unosend.co for a signed copy.
3. Data Location & Storage
Your data is processed and stored in the following locations:
| Service | Provider | Location |
|---|---|---|
| Primary Database | Supabase (PostgreSQL) | EU (Frankfurt, Germany) |
| SMTP Infrastructure | Contabo GmbH | Germany |
| Application Hosting | Vercel | Global (Edge) |
| Payment Processing | Dodo Payments | India |
4. Sub-Processors
We use the following sub-processors to provide our services. All sub-processors are contractually bound to comply with GDPR requirements:
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database & Authentication | EU (Frankfurt) |
| Dodo Payments | Payment Processing | India |
| Vercel, Inc. | Application Hosting | Global (Edge) |
| Contabo GmbH | SMTP Server Infrastructure | Germany |
| Better Stack, Inc. | Uptime Monitoring | EU |
5. Data Subject Rights
Under GDPR, individuals have the following rights which we fully support:
- Right of Access — Request a copy of personal data we hold
- Right to Rectification — Correct inaccurate personal data
- Right to Erasure — Request deletion of personal data
- Right to Restrict Processing — Limit how we use your data
- Right to Data Portability — Export data in a machine-readable format
- Right to Object — Object to processing based on legitimate interests
To exercise any of these rights, please contact privacy@unosend.co. We will respond within 30 days.
6. Data Breach Notification
In the event of a personal data breach, we will notify affected customers within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Our notification will include:
- Nature of the breach
- Categories and approximate number of affected individuals
- Likely consequences of the breach
- Measures taken or proposed to address the breach
7. Technical & Organizational Measures
We implement the following security measures to protect your data:
- TLS 1.3 encryption in transit
- AES-256 encryption at rest
- Regular security audits
- Access controls & authentication
- Automated daily backups
- DDoS protection at edge
- API rate limiting
- Secure API key hashing (SHA-256)
8. Data Retention
We retain data only as long as necessary:
| Data Type | Retention Period |
|---|---|
| Email content & metadata | 30 days |
| Email logs & analytics | 90 days |
| Account data | Until account deletion |
| Billing records | 7 years (legal requirement) |
9. International Data Transfers
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements. This includes the use of Standard Contractual Clauses (EU SCCs) approved by the European Commission. Details of these transfers and safeguards are outlined in our Data Processing Agreement.
10. Contact
If you have any questions about our GDPR compliance or need a Data Processing Agreement, please contact us:
- Privacy inquiries: privacy@unosend.co
- Legal & DPA requests: legal@unosend.co
- Data Processing Agreement: View DPA