SMTPCloud.io is fully committed to compliance with the General Data Protection Regulation (GDPR) and all applicable EU data protection laws.
SMTPCloud.io is fully committed to compliance with the General Data Protection Regulation (GDPR) and all applicable EU data protection laws. As an EU-based company with infrastructure exclusively located within the European Union, we are GDPR-compliant by design.
What this means for you:
Our approach: We believe privacy is a fundamental right, not a compliance checkbox. We've built our entire infrastructure and business practices around data protection principles from the ground up.
Under GDPR Article 6, we process personal data based on the following legal grounds:
Processing necessary to perform our email infrastructure services:
Processing necessary for our legitimate business interests:
We balance our legitimate interests against your rights and freedoms, ensuring no overriding privacy impact.
Processing required by law:
Processing based on your explicit consent:
You can withdraw consent at any time without affecting other services.
Under GDPR, you have comprehensive rights regarding your personal data. Here's what you can do:
What it is: Request a copy of all personal data we hold about you
What we provide:
How to request: Email privacy@smtpcloud.io with "Data Access Request" in the subject
Response time: Within 30 days, free of charge
What it is: Correct inaccurate or incomplete data
What you can update:
How to update:
What it is: Request deletion of your personal data
What we delete:
What we retain (legal requirements):
How to request: Email privacy@smtpcloud.io with "Deletion Request"
Processing time: 30 days, with confirmation email
Note: Account closure triggers automatic deletion after 30 days
What it is: Limit how we process your data in specific situations
When applicable:
Effect: We will store but not actively process restricted data (except with your consent or for legal reasons)
How to request: Email privacy@smtpcloud.io with details of your restriction request
What it is: Receive your data in a portable format and transfer it to another provider
What we provide:
What's included:
How to request: Email privacy@smtpcloud.io with "Data Portability Request"
Format options: JSON, CSV, or API access
Response time: Within 30 days
What it is: Object to processing based on legitimate interests or for direct marketing
What you can object to:
Effect: We will stop processing for that purpose unless we have compelling legitimate grounds
How to object:
Our position: We do NOT use automated decision-making or profiling that produces legal effects or similarly significant impacts.
What we don't do:
Human oversight: All significant decisions about your account involve human review.
Verify Identity
We'll send a verification link to your registered email address for security
We Process Your Request
Receive Confirmation
You'll get email confirmation when your request is completed
All requests are free of charge. We may charge a reasonable fee only for manifestly unfounded or excessive requests, or additional copies beyond the first one.
Exercising your rights will not affect your service or pricing. Your data protection rights are unconditional.
As a B2B service, SMTPCloud.io acts as a data processor when you send emails through our infrastructure. We offer a comprehensive Data Processing Agreement (DPA) that:
How to request: Email support@smtpcloud.io with "DPA Request"
Turnaround: Standard DPA within 5 business days, custom DPA within 15 business days
In the event of a personal data breach, we follow strict GDPR notification requirements:
We maintain robust security to prevent breaches:
Good news: We do NOT transfer your data outside the EU.
Our primary and backup infrastructure is hosted in secure, ISO 27001 certified data centers located exclusively within the European Union. We ensure all data processing activities remain within the EEA.
Your benefit: Your data always benefits from EU data protection standards. No Standard Contractual Clauses needed, no adequacy decisions required.
Service to non-EU clients: While we serve clients globally (APAC, LATAM), all data processing occurs in the EU. This provides superior data protection even for clients outside Europe.
We work with carefully vetted sub-processors, all subject to GDPR compliance. We maintain an up-to-date list of these providers, which is available upon request or as part of our Data Processing Agreement (DPA).
All sub-processors are contractually bound to protect your data and process it only according to our instructions.
All sub-processors must:
Notification: We will notify you 30 days before adding new sub-processors, giving you the right to object.
We retain data only as long as necessary:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | While account active + 30 days | Service provision |
| Email metadata | 90 days | Delivery troubleshooting |
| Usage statistics | 12 months | Service improvement |
| Support communications | 24 months | Service quality |
| Billing records | 7 years | Legal requirement |
| Security logs | 12 months | Security monitoring |
| Anonymized analytics | Indefinitely | No personal data |
After retention period: Data is permanently deleted from all systems and backups.
Early deletion: You can request deletion anytime (except legally required records).
Email: privacy@smtpcloud.io
Response time: 2 business days (initial), 30 days (full resolution)
Contact us directly
Email privacy@smtpcloud.io - we resolve most issues quickly
Formal complaint
If unresolved, you can lodge a formal complaint with us for escalation
Supervisory authority
You have the right to complain to your local data protection authority
EU Supervisory Authorities: Find your local authority at: https://edpb.europa.eu/about-edpb/board/members_en
Your rights: Lodging a complaint does not affect your ability to seek other legal remedies.
SMTPCloud.io is built with privacy as a core principle:
We continuously maintain and improve our GDPR compliance:
We publish updates about our privacy practices and GDPR compliance on our blog and send important notifications via email.
Have questions about GDPR compliance or need to exercise your data rights? Our DPO is here to help.
Email: privacy@smtpcloud.io
Response Time: Within 2 business days (initial), 30 days (full resolution)
SMTPCloud.io - Privacy-First Email Infrastructure
Questions? Contact privacy@smtpcloud.io
Last updated: November 6, 2025