Everything your security team needs, in one place
We market on GDPR and EU data residency, so we'd better show our work. Here's where your data lives, the mechanisms that protect it, and the agreements you can sign — no vague badges, just what's actually in place.
The short version
EU data residency
Customer data is stored and processed in the EU by default.
GDPR built in
Consent tracking, suppression lists, erasure workflows and an audit log on every send.
DPA available
A Data Processing Agreement you can review and sign, with a published sub-processor list.
Isolation & access
Every account is scoped by its own keys; access is authenticated, capability-checked and logged.
How your data is protected
Data protection
- EU data residency by defaultCustomer data is processed and stored in the EU. The DPA and the public sub-processor list are published under legal — no NDA required to read them.
- Encryption in transit and at restAll traffic runs over TLS. Vendor credentials and channel secrets are encrypted at rest with a dedicated key, and passwords are stored as bcrypt hashes — never in any recoverable form.
- GDPR tooling built inFull data export as JSON, irreversible anonymisation across every module, automated retention policies and a GDPR audit log — one API call each, documented publicly.
Access control
- Scoped roles, one login per humanAdmin, Editor and Viewer roles enforce least privilege. Role changes apply on the next request; removing a member revokes their sessions immediately via session-epoch invalidation.
- Two-factor authentication (TOTP)Standards-based TOTP works with any authenticator app. Admins can require MFA account-wide — with it on, no member signs in without a second factor.
- API keys that rotate safelyKey rotation issues the new key immediately while the old one keeps working for a 24-hour grace window — rotate on every offboarding without a deployment scramble.
Platform integrity
- Signed webhooksEvery webhook carries an HMAC signature (X-WeZend-Signature) computed with your per-account secret, so your systems can prove a callback really came from us. Secrets rotate on demand.
- Nothing fails silentlyFailed messages land in a dead-letter queue for inspection and retry. Vendor health is monitored per destination with automatic failover. Every delivery has a plain-language timeline in the Delivery Inspector.
- Audit trail on account changesRole edits, key creation, pricing changes and GDPR actions are logged with actor and timestamp. When something changed and nobody remembers changing it, the answer is in the log.
Sending compliance
- Consent enforced at send timePer-channel consent, the suppression list, frequency caps and quiet hours are checked on every single send — campaign, journey or API call alike. No code path can accidentally message someone without a legal basis.
- One-click unsubscribe & STOP handlingRFC 8058 one-click unsubscribe on every marketing email, STOP keywords intercepted and processed instantly on SMS — compliance events recorded with full history, not just a flag.
- Responsible disclosureFound a vulnerability? Write to security@wezend.com. We confirm receipt within one business day, keep you informed, and credit researchers who report responsibly.
Agreements & documents
Data you can defend. Start free.
- No credit card
- EU data residency
- 6 channels, one API
- GDPR built in
Frequently asked questions
Where is my data stored?
In the EU by default. Customer data — contacts, events, messages — is stored and processed within the EU, which is why WeZend suits regulated industries and EU-sensitive workloads out of the box.
Do you sign a DPA?
Yes. Our Data Processing Agreement is available to review, and our sub-processors are published so you know exactly who touches data. Both are linked below.
How do you handle consent and unsubscribes?
Consent is recorded on the profile, suppression lists are enforced on every send path (including the API), and opt-outs are honoured automatically. One-click unsubscribe and double opt-in are built in.
Can I delete a customer's data?
Yes — erasure workflows handle GDPR data-subject requests, removing a person's data across the platform. The audit log records that it happened.
One platform. Every customer interaction.
Replace your patchwork of messaging APIs, CDP and automation tools with a single engagement platform built for scale.
No credit card required · EU data residency · 99.99% uptime SLA