HomeLegal
GDPR
How Birsend supports your obligations under the EU General Data Protection Regulation, and what our data processing agreement covers.
Last updated September 1, 2026
This document is written to be readable rather than to serve as legal advice. Have your own counsel review it before you rely on it in production.
Controller and processor
When you upload contacts and send messages, you decide the purpose and means of that processing, so you are the controller and Birsend is your processor. We process contact and message data only on your documented instructions.
For your own account, billing, and support data, Birsend is the controller.
Data processing agreement
Our DPA forms part of your contract and covers the subject matter and duration of processing, the categories of data and data subjects, our confidentiality and security obligations, sub-processor terms, assistance with data subject requests, breach notification, and deletion or return of data on termination.
- Request a countersigned copy at [email protected].
- The DPA incorporates the EU Standard Contractual Clauses for any transfer outside the EEA.
Your lawful basis for messaging
GDPR and the ePrivacy rules require a lawful basis before you send marketing messages. In most cases that means consent that is freely given, specific, informed, and recorded. Birsend cannot supply that basis for you.
- Store the opt-in source and timestamp on each contact record.
- Tell people, at the point of opt-in, that you will message them on WhatsApp and how to stop.
- Honour opt-outs immediately and keep a suppression list.
- Do not reuse a list collected for one purpose to promote something unrelated.
Technical and organisational measures
- TLS 1.2 or above for all data in transit; AES-256 for data at rest.
- EU-based primary hosting with encrypted, access-controlled backups.
- Role-based access control, mandatory MFA for staff, and audit logs on administrative access.
- Separation of production and non-production environments; no production data in testing.
- Regular dependency scanning, penetration testing, and staff data protection training.
Sub-processors
We engage sub-processors for hosting, monitoring, email, payments, and support. Each is subject to written terms no less protective than our DPA. We maintain a current list and give you notice before adding a new one, so you have a chance to object.
Data subject requests
If one of your contacts contacts us directly, we forward the request to you and do not respond on your behalf. Within the dashboard you can search, export, correct, and delete any contact record to satisfy a request yourself.
Breach notification
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any case within 48 hours, with the information you need for your own 72-hour regulatory notification.
Deletion and return
On termination we make your data available for export for 30 days, then delete it from production systems. Backup copies age out within a further 60 days.
Still have a question?
Write to us and a human will answer. We would rather explain a clause than have you guess at it.