Sendie touches your calls, payments, customer data and inboxes. Here is how we protect every part of it, who we work with, and the legal documents that back it up.
SMTP, payment and login keys are encrypted at rest. Traffic is TLS 1.2+ end to end.
Consent, data export and deletion are built in, not bolted on, with a 30-day deletion grace window.
Payments run on Stripe. Sendie never touches or stores raw card data.
Every sensitive action is logged, timestamped and exportable, behind role-restricted admin access.
Daily encrypted offsite backups with a tested restore procedure (RPO under 24 hours).
Two-factor authentication on every account, with least-privilege internal access.
For the data you upload and create, Sendie acts only as your processor, on your documented instructions. Sendie's own prospect database is separate and governed by our Privacy Policy.
Transfers outside the EEA/UK rely on the EU Standard Contractual Clauses (Controller to Processor) and the UK Addendum where applicable.
We notify you without undue delay, and within 72 hours of confirming a personal data breach that affects your data.
Unsubscribes and bounces are suppressed automatically, and one-click unsubscribe is supported across outreach.
Enterprise customers can request a countersigned DPA, the EU SCCs, and answers to a security questionnaire. Our team will get back within one business day.
Contact our team