GDPR

How PostedApi handles personal data under the EU General Data Protection Regulation.

Last updated: September 2026

Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • Access — ask what personal data we hold about you and receive a copy of it;
  • Rectification — ask us to correct data that is inaccurate or incomplete;
  • Erasure — ask us to delete your data, also known as the "right to be forgotten";
  • Portability — receive your data in a structured, commonly used, machine-readable format;
  • Restriction — ask us to pause processing while a dispute about it is resolved;
  • Objection — object to processing based on legitimate interest, including direct marketing.

To exercise any of these rights, email [email protected] from the address associated with your account. We verify your identity, then respond within 30 days — we may extend that once by 60 more days for complex requests, and we will tell you if we do. You also have the right to complain to your national supervisory authority.

Data we process

DataExampleRetention
Account detailsYour name, email address, companyLifetime of your account
Verified sending domainsDomains and DNS records you addLifetime of your account
Message contentSubject, body and attachments of sent email45 days
Delivery metadataRecipient, timestamps, delivery status12 months
Support conversationsTickets and email threads with our team24 months
Billing recordsInvoices and tax details7 years, as required by law

Sub-processors

We use a small number of sub-processors, each bound by a written data processing agreement:

  • a cloud infrastructure provider, which hosts the service and its data in the EU;
  • a payment processor, which handles card payments and billing data only;
  • an error-monitoring service, which receives technical logs but never message content.

The list can change over time. We announce material changes by email and in the app before they take effect, and you can object to a change you are not comfortable with.

Transfers

Primary data is stored in data centers in the European Union. If personal data is transferred outside the EEA — for example to a support tool — the transfer is covered by the EU Standard Contractual Clauses or another lawful transfer mechanism recognised under the GDPR.

DPA

Customers who act as data controllers can request our Data Processing Agreement. It covers processing on documented instructions only, confidentiality commitments, the security measures we maintain, our sub-processor list, and notification of personal-data breaches without undue delay. Email [email protected] and we will send you a signed copy.

Contact

Everything GDPR-related goes to [email protected]. You are also free to reach out to your local supervisory authority at any time — that right is never affected by anything on this page.