Roles under the GDPR

You (controller)

  • You determine why and how personal data is processed.
  • You need to have consent and be transparent.
  • Data must stay accurate and up to date.

Xendy (processor)

  • Processes data on your behalf, such as storing contacts, sending emails, and storing the associated statistics.
  • Ensures security and compliance through clear processes.

What does Xendy take care of?

Data Processing Agreement (DPA) Through your account, you can easily view and sign the DPA. The agreement describes which data Xendy processes on your behalf, how it's secured, and what rights you and your contacts have. This legally establishes that the processing is GDPR-compliant.

Security

  • All data is encrypted, both during transfer and at rest.
  • Only authorized employees have access to sensitive data, limited to what's necessary.
  • Daily backups ensure data can be quickly restored in the event of an incident.
  • Xendy follows international information security guidelines (ISO 27001-aligned).

Data retention

  • Data is retained for as long as you actively use Xendy.
  • Upon cancellation, all data is deleted within 90 days, unless there's a legal obligation to retain it longer.

Sub-processors Xendy only works with sub-processors that comply with the GDPR, such as hosting or infrastructure providers. An up-to-date list of sub-processors is available so you always know who may have access to data.

Incident response

  • Potential data breaches or suspicious activity are actively monitored.
  • In the event of a data breach, you'll be notified within 24 hours.
  • You'll receive guidelines to correctly inform authorities and/or affected individuals.
  • Xendy takes immediate action to resolve the issue and prevent it from happening again.

What can you do yourself?

Consent Always ask for explicit consent before sending someone an email. Use clear and specific language so a contact knows exactly what they're signing up for (for example, a newsletter or offers). Assuming consent after the fact or using vague wording is not sufficient.

Are you using a webshop integration or another integration (for example via webhooks)? Then make sure you exclude everyone who has not actively signed up. You can do this under Blocked contacts in the left menu. Xendy imports all customers from your webshop by default.

Data rights Your contacts have the right to view, correct, or delete their data.

  • Edit a contact: click on the contact to open the sidebar with all known details. Click Edit to update fields.
  • Delete a contact: go to All contacts in the left menu, find the contact using the search bar, click the 3 dots to the right of the contact, and choose Delete. Confirm the action. Please note: if you're using a webshop integration, also delete the contact in the webshop — otherwise they will be imported again on the next sync.

Secure handling Limit access to personal data within your organization. Only team members who genuinely need the data should be able to access it. Manage your users via Settings > Users in the left menu. Here you can invite new users, adjust permissions, or remove users.

Unsubscribes Every email contains a working unsubscribe link. As soon as a contact unsubscribes, Xendy processes this automatically: the contact receives the status Unsubscribed and will no longer receive emails. It is not permitted to send someone emails after they have unsubscribed.

Did a contact unsubscribe by accident? Go to Blocked contacts in the left menu, find the contact, click the 3 dots, and choose Re-subscribe. The status changes to Active and the contact will start receiving emails again.

Joeri Ras

Written by

Joeri Ras

Founder & co-owner @ Xendy

Prefer to talk directly?

Related articles