Trust

EU data residency

An EU company, with your contact data stored and processed in Germany, and a published sub-processor list. What we can prove is on one page, and so is what we cannot.

What it does

SendHeron is operated by Kohi Solutions Ltd, a company registered in Bulgaria, an EU member state. Your contact records, the events you track against them, and your sending history are stored and processed in the European Union, on servers in Germany. Under the GDPR you are the controller of that personal data and we are your processor, acting on your instructions.

The practical version, which is what a buyer actually needs: the company you contract with is European, your contact data sits in the EU, and you can have a data processing agreement without booking a call with anybody.

The mail itself stays in the EU too: your contacts are sent to through Amazon SES in Frankfurt. Not every part of the service runs in the EU, though, and rounding that off would make this page useless to the person reading it most carefully. Here is the whole shape of it.

What runs where
Part of the serviceWhere it runs
Contact records and their eventsEU (Germany)
Sending historyEU (Germany)
Email to your contactsEU (Amazon SES, Frankfurt)
Account email to youEU (Amazon SES, Frankfurt)
Object storageCloudflare R2, not pinned to the EU
Site and API delivery (CDN, TLS)Cloudflare global network
AI onboardingUnited States (OpenAI)

Traffic to the site and the API is served through Cloudflare's global network, so TLS terminates at the point of presence nearest the visitor rather than always inside the EU. EU-only termination is an enterprise-tier feature we do not currently buy, and we would rather write that down than let you assume otherwise.

The shape of it

  1. 01

    An EU entity

    Kohi Solutions Ltd, registered in Bulgaria, with its address and VAT number published.

  2. 02

    EU processing

    Contacts, their events and your sending history are stored and processed in the EU.

  3. 03

    A DPA on request

    GDPR data processing agreement at no cost, sent by a person.

  4. 04

    Export or delete

    Every record is readable over the API, and deletion removes the contact and its events.

How it works

Export is not a support ticket. Every contact, tag, event and send record is readable over the REST API, so you can pull a complete export yourself at any time without asking us and without waiting on our working hours.

Deletion is symmetrical. Deleting a contact through the API or the dashboard removes the record and its associated events, and backups age out on their own retention cycle. Ask us to close your account and we delete the workspace data rather than keeping it warm in case you come back.

Unsubscribes are handled at the workspace level, not per sequence. Every marketing email carries one-click unsubscribe, and once somebody opts out they are out across everything you send, which is both the legal position and the only one that does not eventually embarrass you.

  • EU company, EU VAT registered
  • Contact data stored and processed in the EU
  • GDPR DPA available at no cost
  • Full export over the API at any time
  • Deletion removes the contact record and its events

Read the GDPR page

Related: check your own domain's SPF, DKIM and DMARC

What we will not claim

SendHeron is not sovereign, not CLOUD-Act-proof and not Schrems-II-proof. Those phrases get used loosely in this market, and none of them is something a small European company can honestly promise. What we can say is that the company is European, your contact data is stored and processed in the EU, and every claim on this page has a name and an address attached to it.

We will also not tell you that everything runs in the EU, because some of it does not. File storage sits on Cloudflare R2 without an EU location hint, so objects are placed by access pattern rather than pinned to Europe. The onboarding model runs in the United States. Both are named on the GDPR page, in two tables split by whose data each vendor actually touches, and neither is going to be quietly dropped from that page because it is the awkward half.

So what you get today is a named EU entity, EU storage and processing of contact data, a published and dated sub-processor list, a free DPA, full export and deletion over the API, and a person who answers the email. That is less than the strongest claim on the market and more than most of them can support.

What the AI sees

SendHeron can draft your first sequences for you by reading your website, which means a third party model receives some of your data. That is the first question a GDPR-conscious buyer asks, and saying nothing about it reads worse than the answer does.

The model receives your own public website content, up to five pages of it. If your site cannot be read, you type a description of the business yourself instead and it works from that. It does not receive your contact list, your contacts' personal data, or your event data. None of that is sent, so none of it can be trained on or retained.

What comes back is a draft. Nothing sends until you approve it, word by word, and the drafting step runs on OpenAI's API, processed in the United States. If that is not acceptable for your account, the onboarding is skippable and everything it produces can be built by hand instead.

Questions

EU data residency, in detail

Private beta

EU data residency, live in the private beta

We onboard a small number of teams at a time and review every account. That is how we keep deliverability high for everyone.