GDPR Compliance
Full compliance with the EU General Data Protection Regulation with EU server location, DPA and transparent data processing.
Our GDPR Compliance
SendMeSafe was designed from the ground up for GDPR compliance. We meet all requirements of the European General Data Protection Regulation:
- All data is stored and processed exclusively in the EU (Hetzner)
- No data transfer to third countries without appropriate safeguards
- Data Processing Agreement (DPA) available according to Art. 28 GDPR
- Technical and organizational measures (TOM) according to Art. 32 GDPR
- Full implementation of all data subject rights (Art. 15-22 GDPR)
- Transparent documentation of all subprocessors
- Encryption of all data in transit (TLS 1.3) and at rest (AES-256)
- Complete audit trail for all data protection relevant processes
Server Location EU
All your data is stored and processed exclusively on servers in the EU. Our hosting partner Hetzner operates ISO 27001-certified infrastructure. There is no data transfer to third countries.
Server Location EU
All data is processed exclusively in the EU
Hosting Provider
Hetzner Online GmbH
Security Features
Data Processing Agreement (DPA)
As a business customer, you get access to a complete Data Processing Agreement according to Art. 28 GDPR. The DPA is automatically populated with your company data from the settings and can be printed directly.
Data Processing Agreement (DPA)
The DPA regulates the processing of personal data according to Art. 28 GDPR.
DPA Document
Art. 28 GDPR
Contracting Parties
Controller
Your Company Ltd
Processor
SQAN LTD (SendMeSafe)
The DPA takes effect automatically upon use of our services. A separate signature is not required.
Technical and Organizational Measures (TOM)
We implement comprehensive technical and organizational measures according to Art. 32 GDPR to ensure an appropriate level of protection. The complete TOM documentation is available in your dashboard.
Technical and Organizational Measures (TOM)
Measures according to Art. 32 GDPR to protect personal data
Measure Categories
Access Control
Physical access protection to data centers
Entry Control
Authentication and authorization
Data Access Control
Role-based permissions
Transfer Control
Encryption during transmission
Input Control
Audit trail for all changes
Availability Control
Backups and disaster recovery
Subprocessors
We only work with carefully selected subprocessors who are contractually bound to GDPR compliance. All service providers are transparently documented.
Subprocessors
Transparent overview of all service providers processing data
Data Subject Rights
We ensure full implementation of all data subject rights according to Chapter III of the GDPR:
Data Export (Data Portability)
According to Art. 20 GDPR, you can export your personal data in a machine-readable format at any time.
Request Data Export
Export all your personal data (Art. 20 GDPR)
Data to Export
Account Data
Name, email, settings
Client Data
All client information
File Metadata
Upload logs, timestamps
Activity Log
All logged actions
Export Format
The export will be provided within 30 days
Data Deletion (Right to be Forgotten)
According to Art. 17 GDPR, you can request the deletion of your data. We delete your data immediately, unless legal retention obligations apply.
Data Deletion (Right to be Forgotten)
Delete your data according to Art. 17 GDPR
Deletion Options
Delete All Files
Permanently delete uploaded and shared files
Delete Client Data
Remove all client information and contacts
Delete Account
Permanently delete entire account and all data
Warning
This action cannot be undone.
Note: Billing data is retained according to legal retention periods (10 years).
All Data Subject Rights
Right of Access
Art. 15 GDPR
Right to Rectification
Art. 16 GDPR
Right to Erasure
Art. 17 GDPR
Right to Restriction
Art. 18 GDPR
Right to Data Portability
Art. 20 GDPR
Right to Object
Art. 21 GDPR
Data Processing
We only process data necessary for providing our services. Processing is transparent and purpose-limited:
Account Data
Name, email address and password for authentication. Deleted upon account closure.
Client Data
Client information you capture (name, email, company). You have full control over this data.
Uploaded Files
Files uploaded via upload links. Stored with AES-256 encryption.
Usage Data
Technical logs for security and support. Automatic deletion after 90 days.
Legal Basis
The processing of your data is based on the following legal grounds:
Art. 6(1)(b) GDPR
Contract performance: Processing to provide our services according to the terms of use.
Art. 6(1)(f) GDPR
Legitimate interests: Platform security, fraud prevention and improvement of our services.
Art. 6(1)(c) GDPR
Legal obligation: Retention of billing data according to commercial and tax law requirements.
Retention Periods
We only store data as long as necessary for the respective purpose or as required by legal retention obligations:
| Data Type | Retention Period | Basis |
|---|---|---|
| Account Data | Until account closure | Contract performance |
| Uploaded Files | Configurable (30-365 days) | User setting |
| Billing Data | 10 years | Legal requirement |
| Security Logs | 90 days | Legitimate interests |
Privacy Contact
For questions about data protection or to exercise your data subject rights, contact us at:
This documentation is for informational purposes. For legally binding information, please refer to our complete Privacy Policy and the Data Processing Agreement (DPA) in your dashboard.