GDPR Compliance

Full compliance with the EU General Data Protection Regulation with EU server location, DPA and transparent data processing.

Our GDPR Compliance

SendMeSafe was designed from the ground up for GDPR compliance. We meet all requirements of the European General Data Protection Regulation:

  • All data is stored and processed exclusively in the EU (Hetzner)
  • No data transfer to third countries without appropriate safeguards
  • Data Processing Agreement (DPA) available according to Art. 28 GDPR
  • Technical and organizational measures (TOM) according to Art. 32 GDPR
  • Full implementation of all data subject rights (Art. 15-22 GDPR)
  • Transparent documentation of all subprocessors
  • Encryption of all data in transit (TLS 1.3) and at rest (AES-256)
  • Complete audit trail for all data protection relevant processes

Server Location EU

All your data is stored and processed exclusively on servers in the EU. Our hosting partner Hetzner operates ISO 27001-certified infrastructure. There is no data transfer to third countries.

Server Location EU

All data is processed exclusively in the EU

H

Hosting Provider

Hetzner Online GmbH

EU (Hetzner)
ISO 27001DSGVO

Security Features

ISO 27001 certified
GDPR compliant
Redundant power supply
24/7 monitoring
DDoS protection
No data transfer to third countries

Data Processing Agreement (DPA)

As a business customer, you get access to a complete Data Processing Agreement according to Art. 28 GDPR. The DPA is automatically populated with your company data from the settings and can be printed directly.

Data Processing Agreement (DPA)

The DPA regulates the processing of personal data according to Art. 28 GDPR.

Your Company Data
Complete

DPA Document

Art. 28 GDPR

Contracting Parties

Controller

Your Company Ltd

Processor

SQAN LTD (SendMeSafe)

Takes effect automatically upon use
Company data is taken from settings

The DPA takes effect automatically upon use of our services. A separate signature is not required.

Technical and Organizational Measures (TOM)

We implement comprehensive technical and organizational measures according to Art. 32 GDPR to ensure an appropriate level of protection. The complete TOM documentation is available in your dashboard.

Technical and Organizational Measures (TOM)

Measures according to Art. 32 GDPR to protect personal data

Measure Categories

Access Control

Physical access protection to data centers

Entry Control

Authentication and authorization

Data Access Control

Role-based permissions

Transfer Control

Encryption during transmission

Input Control

Audit trail for all changes

Availability Control

Backups and disaster recovery

Last update: January 2025

Subprocessors

We only work with carefully selected subprocessors who are contractually bound to GDPR compliance. All service providers are transparently documented.

Subprocessors

Transparent overview of all service providers processing data

ProviderPurposeLocationGuarantee
Hetzner Online GmbH
Hosting & StorageGermanyISO 27001, DSGVO
Stripe Inc.
Payment ProcessingUSA (SCC)PCI DSS, SCC
Brevo (Sendinblue)
Email DeliveryEUISO 27001, DSGVO
All subprocessors are contractually bound to GDPR compliance

Data Subject Rights

We ensure full implementation of all data subject rights according to Chapter III of the GDPR:

Data Export (Data Portability)

According to Art. 20 GDPR, you can export your personal data in a machine-readable format at any time.

Request Data Export

Export all your personal data (Art. 20 GDPR)

Data to Export

Account Data

Name, email, settings

Client Data

All client information

File Metadata

Upload logs, timestamps

Activity Log

All logged actions

Export Format

The export will be provided within 30 days

Data Deletion (Right to be Forgotten)

According to Art. 17 GDPR, you can request the deletion of your data. We delete your data immediately, unless legal retention obligations apply.

Data Deletion (Right to be Forgotten)

Delete your data according to Art. 17 GDPR

Deletion Options

Delete All Files

Permanently delete uploaded and shared files

Delete Client Data

Remove all client information and contacts

Delete Account

Permanently delete entire account and all data

Warning

This action cannot be undone.

Processing time: 30 days

Note: Billing data is retained according to legal retention periods (10 years).

All Data Subject Rights

Right of Access

Art. 15 GDPR

Right to Rectification

Art. 16 GDPR

Right to Erasure

Art. 17 GDPR

Right to Restriction

Art. 18 GDPR

Right to Data Portability

Art. 20 GDPR

Right to Object

Art. 21 GDPR

Data Processing

We only process data necessary for providing our services. Processing is transparent and purpose-limited:

1

Account Data

Name, email address and password for authentication. Deleted upon account closure.

2

Client Data

Client information you capture (name, email, company). You have full control over this data.

3

Uploaded Files

Files uploaded via upload links. Stored with AES-256 encryption.

4

Usage Data

Technical logs for security and support. Automatic deletion after 90 days.

Legal Basis

The processing of your data is based on the following legal grounds:

Art. 6(1)(b) GDPR

Contract performance: Processing to provide our services according to the terms of use.

Art. 6(1)(f) GDPR

Legitimate interests: Platform security, fraud prevention and improvement of our services.

Art. 6(1)(c) GDPR

Legal obligation: Retention of billing data according to commercial and tax law requirements.

Retention Periods

We only store data as long as necessary for the respective purpose or as required by legal retention obligations:

Data TypeRetention PeriodBasis
Account DataUntil account closureContract performance
Uploaded FilesConfigurable (30-365 days)User setting
Billing Data10 yearsLegal requirement
Security Logs90 daysLegitimate interests

Privacy Contact

For questions about data protection or to exercise your data subject rights, contact us at:

This documentation is for informational purposes. For legally binding information, please refer to our complete Privacy Policy and the Data Processing Agreement (DPA) in your dashboard.