Security and privacy for EU customers

The short, honest version of how we host, protect and retain data — with the details that matter if you're evaluating us under GDPR.

Last updated: September 2026 · Also see our Privacy Policy and GDPR overview

Data centers and hosting

PostedApi's production systems run in SOC 2-accredited data facilities operated by established cloud providers, with primary hosting in the United States and redundant backups in a second region. Data is encrypted in transit using TLS on every public endpoint — the web application, the REST API, the SMTP relay and inbound processing.

A note on GDPR: the GDPR does not require personal data to be stored on servers physically located inside the EU. It requires adequate protection of the data wherever it is processed. For transfers outside the EEA we rely on Standard Contractual Clauses as described in our DPA, and we keep a current list of sub-processors available on request.

Facility safeguards

  • Keycard and biometric access controls, with 24/7 on-site surveillance and visitor logging.
  • Redundant power, cooling and networking, with multiple levels of backups.
  • Data at rest encrypted; backups encrypted and tested on a regular schedule.
  • Full-disk and volume-level encryption on all systems that store customer data.

Additional security measures

Access control

Access to personal data is restricted to employees and contractors who need it to operate, secure or improve the Service, and only a handful of senior engineers can reach the systems where data is stored. Staff may only open a customer account when an account owner has explicitly invited them to, or when an account is under review for a compliance matter. Every access of this kind is logged and auditable.

Confidentiality

Everyone with production access — employee or contractor — is bound by written confidentiality obligations. Violations are treated as gross misconduct, up to termination of contract and, where applicable, referral to authorities.

Application security

  • All dashboard and API traffic is served over HTTPS with modern TLS configurations, scanned automatically for weaknesses such as misconfigurations or expired ciphers.
  • SMTP submission supports both TLS (STARTTLS on ports 587/2525) and implicit TLS (port 465), so mail handed to us is encrypted on the way in.
  • Account passwords are stored only as salted, one-way hashes — no PostedApi employee can read your password.
  • Server tokens and API credentials can be rotated at any time from the dashboard, and we recommend doing so on any sign of compromise.
  • The API, SMTP, inbound and web tiers run on fully redundant infrastructure, so a single component failure does not take the Service down.
  • Operating systems are hardened and patched on a frequent, automated schedule; the production network sits behind redundant firewalls.
  • External security monitoring and periodic penetration tests are performed by independent firms; findings are triaged and remediated with priority.

Data retention

As described on our product pages, PostedApi stores the content and metadata of every email you send for 45 days by default, so you can inspect full message history, debug delivery issues and answer "did that email actually go out?" with certainty. On paid plans you can shorten or extend this window per stream, from 7 to 365 days.

After the retention window closes, message content and associated metadata are deleted from production systems and age out of backups on a rolling schedule. Two categories survive longer, by design:

  • Suppression lists. Bounces, spam complaints and unsubscribed addresses are kept indefinitely — stripped to the identifying minimum — because deleting them would let you accidentally re-mail people who already complained, which harms both your reputation and ours.
  • Aggregated statistics. Delivery rates, volume counts and performance metrics are aggregated and kept indefinitely; they contain no message content and no personal data beyond what you see in your dashboard.

Your questions

Evaluating us for a security review? Write to [email protected] and we will answer directly, including sharing our current sub-processor list and a copy of the DPA. For data-protection requests, contact [email protected].

Related documents: Privacy Policy · GDPR · Cookie Policy · Security.