Privacy
Sendrill is an email sending platform, so personal data is the substance of the product, not a side effect. This page says exactly what we do with data on this website, what we do with data inside the service, and where it all lives.
Last updated: 13 September 2026
Who we are
Sendrill is operated by eSolutions Softhouse Limited, the company behind CookieTrust, ComplianceMonitor, ThreadDesk, ImgHaste and Domainwise.
- Company legal name
- eSolutions Softhouse Limited
- Registered address
- Samou 5, Paphos, Cyprus
- Contact for privacy questions
- privacy@sendrill.com
Two different roles
There are two kinds of personal data here and they are governed differently. For this website — sendrill.com — we are the controller and decide what is processed. For the service — the contacts you upload, the people you email and the events their messages generate — you are the controller and we are your processor. We act on your instructions, we do not decide what you send or to whom, and we never use your contacts for our own purposes.
If you need a data processing agreement covering that second role, write to us and we will send you one.
What this website processes
This page and the rest of sendrill.com are static files. There is no analytics, no advertising pixel and no tracking cookie on this site, and nothing you read here is reported back to us.
Your browser preferences
Your language and light/dark choice are stored in your own browser's localStorage under sr-lang and sr-theme. They stay on your device, are never sent anywhere, and you can clear them with your browser's site data.
Server logs
The site is served by Cloudflare Pages. Cloudflare processes the technical request data any web server sees — IP address, time, requested path, user agent — to deliver the page and to protect the service from attack. We do not build profiles from those logs.
Messages you send us
If you email support or ask for a data processing agreement, we keep that correspondence for as long as it takes to answer you and to keep a record of what was agreed.
What the service processes
Inside Sendrill, on your instructions and on your behalf, we process:
- Your contacts — email address, the name and any custom fields you choose to store, tags, source, country and language.
- Consent records — when, how and from which IP address each contact opted in, and the wording they agreed to. This exists so that you can prove a list was collected lawfully.
- Message and event data — what was sent to whom, and whether it was delivered, opened, clicked, bounced, reported as spam or unsubscribed. Opens and clicks are only tracked if you leave tracking enabled.
- Suppression data — addresses that must never be mailed again because they hard-bounced, complained, or asked to be removed.
- Account data — the names, email addresses and roles of the people in your workspace, and your billing details.
Sending uses Amazon SES in eu-central-1 (Frankfurt). Your contacts, consent records and events are stored in the EU.
Who else is involved
These are our sub-processors. Each one is bound by a contract that limits it to processing data on our instructions.
| Sub-processor | What for | Where |
|---|---|---|
| Amazon Web Services | Sending mail (SES), hosting and storage | EU (eu-central-1) |
| Cloudflare | Serving this website, DNS and protection against attacks | Global edge network |
| Stripe | Subscription payments and invoices | EU / USA |
We will tell you before adding a sub-processor that handles your contacts or your mail.
How long we keep things
- Contacts and consent records — for as long as your workspace exists. You can delete a contact at any time, and deleting it removes its consent record too.
- Message log and events — kept for a limited retention window so you can investigate delivery problems, then deleted.
- Suppression list — kept for as long as your workspace exists. This one is deliberate: forgetting that somebody asked never to be emailed again is worse than remembering it.
- Billing records — kept for as long as tax and accounting law requires.
- After you close your account — your workspace data is deleted, other than what we must keep by law and the suppression list described above.
Your rights
Under the GDPR you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, object to processing or ask for it in a portable form.
If you are one of our customers, write to privacy@sendrill.com and we will answer within one month. If you received an email sent through Sendrill and want your data removed, the sender — the business whose name is on that email — is the controller, so please ask them; every campaign carries an unsubscribe link, and if you contact us we will pass the request on and suppress the address.
You can also complain to a supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection, or the authority in your own country.
Security
Traffic is encrypted in transit, API keys are stored hashed and are never recoverable in plain text, access to production data is limited to the people who operate the service, and administrative actions are logged. If a breach affects your data, we will tell you.
Changes
If we change this page in a way that matters, we will update the date at the top and, for material changes affecting customers, tell you in the app or by email.
Contact
Privacy questions: privacy@sendrill.com. Anything else: support@sendrill.com.