What personal data do we collect and why?

We collect different categories of personal data, depending on your relationship with Xendy:

Customers

  • Data: contact details, payment information, usage data and content of sent emails
  • Purpose: execution of the agreement, analysis and optimization of email campaigns
  • Legal basis: necessary for the performance of the agreement

Prospects and interested parties

  • Data: contact details, company name and interests
  • Purpose: marketing, providing information and offers
  • Legal basis: legitimate interest in acquiring new customers

Website visitors

  • Data: IP address, browser data, cookies and click behavior
  • Purpose: improving the website experience and providing relevant content
  • Legal basis: consent (for non-functional cookies)

Applicants

  • Data: contact details, CV, cover letters and additional application information
  • Purpose: assessing suitability for a position
  • Legal basis: necessary for pre-contractual measures

Employees

  • Data: contact details, personnel file, salary information, identification data, job title, employment contract, working hours, leave and sick leave
  • Purpose: execution of the employment contract, payroll administration and compliance with legal obligations
  • Legal basis: necessary for the performance of the employment contract, legal obligations and in certain cases legitimate interest

Retention periods

We don't keep personal data any longer than necessary for the purpose for which it was collected, unless a legal retention obligation applies:

CategoryRetention period
Customer dataDuration of the agreement + legal obligations (e.g. 7 years for financial data)
Employee dataDuration of the employment contract + legal obligations (e.g. 7 years for payroll records)
Prospect dataUntil unsubscription or after 3 years of inactivity
Applicant dataUp to 4 weeks after the end of the application process, unless you give consent for longer retention
Call recordingsMaximum 30 days, unless needed for legal investigation

Data processing by customers (role as processor)

When customers upload data into Xendy (such as email contacts), Xendy acts as the processor and the customer is the controller. This means:

  • The customer is responsible for obtaining valid consent from their contacts for sending email campaigns via Xendy.
  • Xendy processes the data solely on behalf of the customer and has no control over the legal basis of the processing by the customer.
  • Customers need to notify Xendy of any data deletion or modification to stay compliant.

Sharing data with third parties

Xendy works with carefully selected third parties for services such as hosting, data analysis and payment processing. These parties only have access to your data to the extent strictly necessary. We enter into data processing agreements with all third parties to ensure GDPR compliance.

Processing outside the EEA

Xendy processes personal data within the European Economic Area (EEA) wherever possible. If a transfer outside the EEA is still necessary, we take appropriate measures, including:

  • Use of standard contractual clauses (SCCs) as approved by the European Commission
  • Additional technical and organizational security measures

Upon request, we provide documentation on the safeguards for international data transfers. Customers are informed about the locations where sub-processors handle data.

Sharing with government authorities

In exceptional cases, Xendy may share personal data with government authorities, for example when required by law.

Joeri Ras

Written by

Joeri Ras

Founder & co-owner @ Xendy

Prefer to talk directly?

Related articles