GDPR compliance
Last updated: 2026-07-26
SieveGuard is built for EU customers. This page summarises in plain English how we comply with the GDPR; the formal contractual commitment lives in the Data Processing Agreement.
The roles in one paragraph
When you submit emails to SieveGuard for screening, you are the Controller and SieveGuard is the Processor. We process those emails only on your instructions, only for the purposes you set, only for as long as you tell us. When we collect data about you (your account, your billing, your usage of our website), we are the Controller for that data and our Privacy Policy applies.
At a glance
- Data residency: all detection + verification runs on AWS Frankfurt (eu-central-1). Your data does not leave the EU.
- Encryption: TLS 1.3 in transit; AES-256 at rest.
- Tenant isolation: PostgreSQL Row-Level Security — your data is database-level isolated from every other customer.
- Retention: detection records kept for the lifetime of your subscription + 30 days. Right to immediate purge from the portal.
- Sub-processors: current list available on request to
[email protected]; 30-day notice before any change. - Breach notification: 72 hours from awareness.
- Data subject requests: forwarded to
[email protected]with assistance per GDPR. - No advertising tracking: we do not run third-party analytics or marketing pixels on our website.
Signing the DPA
The DPA at /dpa is automatically incorporated into your Terms of Use when you subscribe — no separate signature needed for most customers. If your procurement team requires a counter-signed copy, email [email protected] with your company details and we counter-sign within two business days.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port or object to the processing of your data, and to withdraw consent at any time where consent is the legal basis. Send any request to [email protected]; we respond within 30 days.
If we get it wrong
You have the right to complain to a supervisory authority. You may also lodge a complaint with the supervisory authority in your country of residence.
Contact
GDPR / privacy: [email protected] · General: [email protected].