GDPR and Your Data 🇪🇺

Last updated: September 8, 2026

Audienceful believes strongly in protecting your data and strives to comply with all privacy-related regulation including GDPR.

The General Data Protection Regulation (GDPR) is a data privacy law that regulates the use of EU resident personal data, providing individuals rights to exercise control over their data and requiring organizations that process personal data to meet certain obligations.

Overall Philosophy

In accordance with GDPR, we store only the minimum data required to support our platform, far less than most email marketing platforms. We do not use 3rd party cookies, and we use privacy-focused support and analytics tools whenever possible.

Data Portability & Management

  • Import: We provide tools to import your data a number of ways. This includes via CSV upload, syncing via outside integration, website signup forms, or manual input.
  • Export: Audienceful allows you to easily export your data at any time from the same place you can import your data (the People tab). We do not believe in "vendor lock-in" as a business strategy, and do not make it difficult to switch to another platform.
  • Account deletion: Your account and all data can be deleted at any time. Soon after your account is deleted, our system will also delete any backups, so you can be sure there will be no trace left of your data on our servers. This extends to your AI agent conversations and messages, the files you uploaded to them and the images generated within them, your usage records, and your stored business context.
  • Account settings: We provide tools to manage any personal information associated with account and workspace settings, such as name, members, allowed email domains, and more from our workspace settings menu.
  • Requests: If you are unwilling or unable to use our tools to manage your account, we respond to all requests related to data deletion in a timely manner.

Our AI agent

Audienceful includes an AI agent which assists you in preparing and sending your email marketing. It acts only on your instruction, and it obtains your confirmation before taking any consequential action. No decision affecting your subscribers is taken by automated means alone.

In respect of your subscribers' personal data, you are the controller and Audienceful is your processor. Requests to our model providers are constructed so that contacts are referenced by internal identifier only: contact email addresses and custom field values are not disclosed to those providers. Where you direct the agent to act upon particular contacts or audiences, the resulting instruction is therefore carried out against identifiers, and the personal data behind them stays within our own systems. The providers listed below act as our sub-processors in respect of the material that is disclosed to them.

Each request is configured so that it may be directed only to model providers whose published terms state that they do not store the content of requests or responses and do not use it for training; such providers commonly reserve the right to retain content for a limited period, generally not exceeding thirty days, in order to detect misuse. We do not use your data, or your subscribers' data, to train models.

The right to erasure is given effect through the contact record. Contacts referenced within an AI conversation are recorded by identifier and remain associated with that contact's record, so that deleting or anonymizing a contact takes effect in the conversation history within thirty days. No separate request to us is required.

A full description of the data the agent processes, the periods for which it is retained, and the controls available to you is set out in our privacy policy.

Sub-processors

We use the following sub-processors to deliver the Services. All are based in the United States, and transfers to them rely on the Standard Contractual Clauses or, where the recipient participates in it, the EU-U.S. Data Privacy Framework.

Sub-processor Purpose Data involved
DigitalOcean Cloud hosting, databases, and object storage, including files uploaded to the AI agent All Service data
Stripe Payment processing Billing and payment data
OpenRouter AI routing gateway for all model requests AI agent requests and the workspace content in them. No data from your contact records
Google AI model provider (chat, image generation, summarization), reached through OpenRouter AI agent requests routed to it
OpenAI AI model provider (chat fallback, embeddings), reached through OpenRouter AI agent requests routed to it
Anthropic AI model provider (chat fallback), reached through OpenRouter AI agent requests routed to it
Serper Web search for the AI agent The search query written by the model. No contact data
PostHog In-app product analytics Account identifiers and in-app usage events
Wist Live chat support Support conversations you start with us

The specific AI model providers behind our gateway are configurable and change as models improve, so we may add or substitute leading model providers. We will keep this list current.

Data Security

We utilize numerous technologies to ensure the safety of your data including SSL, anonymization and SHA-256 encryption as recommended by the National Institute of Standards and Technology.

None of our support staff or contractors have access to your sensitive email list data. We do this to reduce risk of phishing or social engineering (the most common attack vector, re: Mailchimp's latest breaches). Since our founding in 2020 we have had zero data breach incidents.

However, no internet-connected service can ever be 100% secure. In the event of a future data breach, in accordance with GDPR we have protocols for promptly notifying any affected parties.

Standard Contractual Clauses (SCCs)

In accordance with the Schrems II ruling which invalidated the privacy shield framework, for any data that passes through cloud vendors we rely on the latest Standard Contractual Clauses to ensure appropriate safeguards for personal data transfers from the EU to countries outside of the EU.

Our servers are hosted in the cloud with Digital Ocean. You can view Digital Ocean's SCCs and Data Processing Agreements here (Schedule 3 relates specifically to our use of Digital Ocean as processor).

*2023 update: EU-US Data Privacy Framework

On July 10th 2023, the European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework. The adequacy decision concludes that the United States ensures an adequate level of protection compared to that of the EU for personal data transferred from the EU to US companies participating in the EU-U.S. Data Privacy Framework. This clears up any prior confusion related to using US-hosted cloud services within the EU.

As a result of adequacy decisions, personal data can flow freely and safely from the European Economic Area (EEA), which includes the 27 EU Member States as well as Norway, Iceland and Liechtenstein, to a third country, without being subject to any further conditions or authorizations. In other words, transfers to the third country can be handled in the same way as intra-EU transmissions of data.

More information

For more detailed information see our full privacy policy.