Trust
GDPR and data residency
Most tools bury this in a policy PDF. Here is the short version, on one page.
Who you are contracting with
SendHeron is operated by Kohi Solutions Ltd, a company registered in Bulgaria, an EU member state.
- str. Filip Simidov 1, entr. B, floor 3, apt. 11, Veliko Tarnovo 5000, Bulgaria
- Company registry number (EIK): 206220247
- VAT number: BG206220247
Under the GDPR, you are the controller of your contacts' personal data and Kohi Solutions Ltd is your processor. We process contact data only to provide the service, on your instructions.
Where your data lives
Your contact records, the events you track against them, and your sending history are stored and processed in the European Union, on servers in Germany.
Every email we send is delivered by Amazon SES in Frankfurt (eu-central-1). That covers the mail you send to your contacts and the mail we send you, so the message and the recipient address stay in the EU along with the records.
Traffic to the site and the API is served through Cloudflare's global network, so a TLS connection terminates at the point of presence nearest the visitor rather than always inside the EU. Files you upload go to Cloudflare R2, which is not currently pinned to an EU location.
Where a provider on the tables below processes outside the EU, the transfer stands on a recognised safeguard under Chapter V of the GDPR: Cloudflare, Stripe and Sentry (Functional Software, Inc.) are certified under the EU-US Data Privacy Framework, and for OpenAI we rely on the standard contractual clauses in its data processing addendum.
What we deliberately do not claim: SendHeron is not "sovereign", not "CLOUD-Act-proof", and not "Schrems-II-proof". Those phrases get used loosely in this market and none of them are things a small EU company can honestly promise. What we can say is that the company is European, your contact data is stored and sent from the EU, and the tables below name every third party that touches it, including the ones outside the EU.
Sub-processors
These are the third parties that process your contacts' data on our behalf, what each one does, where it processes, and which legal entity you are contracting with. Vendors that are wired into the service but process nothing today are not listed: naming a company that never sees your data would pad the disclosure rather than inform it.
| Sub-processor | What it does | Processing region | Contracting entity |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting and database | Germany (EU) | Hetzner Online GmbH, Germany |
| Amazon SES | Delivery of every email we send, to your contacts and to you | eu-central-1 (Frankfurt, EU) | Amazon Web Services EMEA SARL, Luxembourg |
| Cloudflare | CDN, DNS, TLS termination, object storage (R2) and images | Global network. Object storage has no EU location hint set, so it is not pinned to the EU. | Cloudflare, Inc., United States |
| OpenAI | AI onboarding: reads your public website and drafts sequences for your approval | United States | OpenAI, L.L.C., United States |
| Sentry | Error monitoring. Receives error reports with request metadata when the service breaks | United States | Functional Software, Inc., United States |
Vendors that see your account, not your contacts
These process the account holder's own data, meaning your name, your email address and your billing details. They never receive a contact list. For this data we are the controller rather than your processor, so they are not sub-processors in the Article 28 sense and objecting to them is not a thing the DPA gives you. They are listed because they are still a real transfer of your personal data, and leaving them out would be the more convenient half of the truth.
| Sub-processor | What it does | Processing region | Contracting entity |
|---|---|---|---|
| Stripe | Payment processing and billing for your own subscription | United States and Ireland | Stripe, Inc. (US) and Stripe Payments Europe Ltd (Ireland) |
When this list changes
We give you at least 30 days' notice by email before a new sub-processor starts processing your contacts' data, so that the right to object under Article 28(2) is a right you can actually use. If you object and we cannot offer a workable alternative, you can stop using the service and we refund the unused portion of whatever you have already paid. Notice applies to the first table only: the second is our own supplier list and changes without a notice period.
Last updated 2026-08-05. We update this page when the list changes, and the date is the disclosure, not decoration.
Data processing agreement
A GDPR-compliant DPA is available to every customer at no cost. Email [email protected] and we will send it over. A self-serve PDF is coming; for now a human sends it, which also means you can raise redlines in the same thread.
Export, deletion, and your contacts' rights
Your contacts have rights under the GDPR, and because you are the controller, requests normally reach you first. We support you in answering them:
- Export. Every contact, tag, event, and send record is readable over the REST API, so you can pull a full export yourself at any time without asking us.
- Deletion. Deleting a contact through the API or the dashboard removes the record and its associated events. Backups age out on their own retention cycle.
- Account closure. You delete your own account from the dashboard, without asking us and without waiting on us. What a request covers depends on whether you are the owner, so the mechanics have their own section below.
- Unsubscribes. Every marketing email carries one-click unsubscribe, and an unsubscribe is honoured across your whole workspace rather than per sequence.
Deleting your account
Erasure under Article 17 is self-service and does not go through us. In the dashboard, open Settings, then Security, then Delete account. You confirm with your password, which is there so that a borrowed session cannot delete an account.
What a request covers depends on who makes it, and there are only two answers. An owner is the only account that can delete an organization, so an owner's request takes the whole of it: every member, every workspace, and all of their contacts, templates, sequences, campaigns, domains, API keys and sending history. A team member's request removes only their own account and leaves the organization and its data untouched.
When an owner asks, sending stops at once rather than at the end of the waiting period. Campaigns are cancelled, scheduled emails are cancelled, active sequences and the contacts moving through them are paused, and API keys are revoked. We do this first because mail that is already queued would otherwise keep arriving for two more weeks after somebody asked to leave, which is not what the request meant.
The deletion itself runs 14 days later, and it is permanent. The confirmation email names the date. Until then you can call it off from the prompt that appears when you log in, which turns sending back on. It does not switch the rest back on: the cancelled campaigns, the revoked keys and the paused sequences stay as the request left them, so you restart what you still want.
Your subscription is cancelled immediately rather than at the end of the period you have paid for, and the remaining paid time is not refunded. Cancelling the deletion does not bring the subscription back; you would subscribe again. This is the one part of the flow that costs you something, which is why the dialog says so before you confirm and why the terms separate deleting from cancelling.
Two things deliberately survive the delete. Invoices and receipts are kept for as long as Bulgarian accounting and VAT law requires, which Article 17(3)(b) allows: an erasure request does not remove our legal obligation to keep tax records. And one row per deletion is kept as proof the erasure happened, holding a hashed form of the email address rather than the address itself, so it can show that an account was erased without recording whose it was.
Images you uploaded to templates are purged from public storage as part of the delete. Our CDN may go on serving a cached copy for a short time afterwards, so a URL somebody already holds can stay reachable briefly after the account is gone.
That route needs you to be able to log in. If you cannot, write to [email protected] and a person will do it for you.
Contacting us about data protection
Write to [email protected]. A person reads it. We are a small company, which is the reason you get a human rather than a ticket number.
Private beta
Data questions answered before you sign anything
Join the list and the DPA, the sub-processor list, and a person who can answer a redline all come with the onboarding email.