Trust

EU data residency

An EU company, with your contact data stored and processed in the EU. What we can prove is on one page, and so is what we cannot.

What it does

SendHeron is operated by Kohi Solutions Ltd, a company registered in Bulgaria, an EU member state. Your contact records, the events you track against them, and your sending history are stored and processed in the European Union. Under the GDPR you are the controller of that personal data and we are your processor, acting on your instructions.

The practical version, which is what a buyer actually needs: the company you contract with is European, the data sits in the EU, and you can have a data processing agreement without booking a call with anybody.

All of it is written down on the GDPR page with the registered address and VAT number of the entity behind it, because a residency claim you cannot check is worth nothing.

The shape of it

  1. 01

    An EU entity

    Kohi Solutions Ltd, registered in Bulgaria, with its address and VAT number published.

  2. 02

    EU processing

    Contacts, their events and your sending history are stored and processed in the EU.

  3. 03

    A DPA on request

    GDPR data processing agreement at no cost, sent by a person.

  4. 04

    Export or delete

    Every record is readable over the API, and deletion removes the contact and its events.

How it works

Export is not a support ticket. Every contact, tag, event and send record is readable over the REST API, so you can pull a complete export yourself at any time without asking us and without waiting on our working hours.

Deletion is symmetrical. Deleting a contact through the API or the dashboard removes the record and its associated events, and backups age out on their own retention cycle. Ask us to close your account and we delete the workspace data rather than keeping it warm in case you come back.

Unsubscribes are handled at the workspace level, not per sequence. Every marketing email carries one-click unsubscribe, and once somebody opts out they are out across everything you send, which is both the legal position and the only one that does not eventually embarrass you.

  • EU company, EU VAT registered
  • Contact data stored and processed in the EU
  • GDPR DPA available at no cost
  • Full export over the API at any time
  • Deletion removes the contact record and its events

Read the GDPR page

What we will not claim

SendHeron is not sovereign, not CLOUD-Act-proof and not Schrems-II-proof. Those phrases get used loosely in this market, and none of them is something a small European company can honestly promise. What we can say is that the company is European, the data is processed in the EU, and every claim on this page has a name and an address attached to it.

We are also not publishing a sub-processor list before every entry on it has been confirmed. A sub-processor list is a legal disclosure, and a partial or wrong one is worse than an honest not yet. The working list was compiled from the service's own dependencies and is being checked against each contract. If you need it before the page goes up, ask and we will send you the current version rather than make you wait.

So what you get today is a named EU entity, EU processing, a free DPA, full export and deletion over the API, and a person who answers the email. That is less than the strongest claim on the market and more than most of them can support.

Questions

EU data residency, in detail

Private beta

EU data residency, live in the private beta

We onboard a small number of teams at a time and review every account. That is how we keep deliverability high for everyone.