Our commitments to the EU and UK General Data Protection Regulation, and how we help you meet yours.
TenbaMail is built with data protection in mind. We support customers who are subject to the EU General Data Protection Regulation (GDPR) and the UK GDPR by providing the contractual terms, technical safeguards and tools needed to process personal data lawfully. This page summarizes those commitments and works alongside our Privacy Policy.
Under the GDPR, our customers are the data controller for the contact data and campaigns they manage through the Service, and TenbaMail acts as a data processor, processing that data only on the customer's documented instructions. For our own account and website data, TenbaMail is the controller.
We make a Data Processing Agreement (DPA) available to all customers. Our DPA incorporates the Standard Contractual Clauses and describes the subject matter, duration, nature and purpose of processing, the categories of data subjects and personal data, and the obligations of both parties. To request a signed DPA, contact [email protected].
We process personal data in line with the GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; and integrity and confidentiality. As a sender, you are responsible for having a valid lawful basis — typically consent or legitimate interest — before contacting recipients through the Service.
The Service provides tools that help you respond to data subject requests, including the ability to search, export, update, suppress and delete contact records, and to honor unsubscribe and erasure requests automatically. If an individual contacts us directly about data processed on a customer's behalf, we will refer them to the relevant customer and assist as processor.
We engage vetted subprocessors (for example, cloud hosting and payment providers) to help deliver the Service. Each is bound by data-protection terms consistent with the GDPR. We maintain a current list of subprocessors and will provide advance notice of material changes so you can object where permitted by the DPA.
Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where required.
We maintain technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS 1.2+) and at rest (AES-256), access controls and least-privilege principles, network segmentation, logging and monitoring, and regular review of our controls. A summary of these measures is included in our DPA.
Our controls are independently verified: we hold a SOC 2 Type II report and ISO/IEC 27001 certification. These support the "appropriate technical and organisational measures" required under Article 32 of the GDPR. Copies are available to customers under NDA on request.
If we become aware of a personal data breach affecting data we process on your behalf, we will notify you without undue delay and provide the information reasonably needed to help you meet your own notification obligations to regulators and data subjects.
For GDPR inquiries, DPA requests or to reach our Data Protection Officer, email [email protected] or visit our Support page.