The short, honest version of how we host, protect and retain data — with the details that matter if you're evaluating us under GDPR.
Last updated: September 2026 · Also see our Privacy Policy and GDPR overview
PostedApi's production systems run in SOC 2-accredited data facilities operated by established cloud providers, with primary hosting in the United States and redundant backups in a second region. Data is encrypted in transit using TLS on every public endpoint — the web application, the REST API, the SMTP relay and inbound processing.
A note on GDPR: the GDPR does not require personal data to be stored on servers physically located inside the EU. It requires adequate protection of the data wherever it is processed. For transfers outside the EEA we rely on Standard Contractual Clauses as described in our DPA, and we keep a current list of sub-processors available on request.
Access to personal data is restricted to employees and contractors who need it to operate, secure or improve the Service, and only a handful of senior engineers can reach the systems where data is stored. Staff may only open a customer account when an account owner has explicitly invited them to, or when an account is under review for a compliance matter. Every access of this kind is logged and auditable.
Everyone with production access — employee or contractor — is bound by written confidentiality obligations. Violations are treated as gross misconduct, up to termination of contract and, where applicable, referral to authorities.
As described on our product pages, PostedApi stores the content and metadata of every email you send for 45 days by default, so you can inspect full message history, debug delivery issues and answer "did that email actually go out?" with certainty. On paid plans you can shorten or extend this window per stream, from 7 to 365 days.
After the retention window closes, message content and associated metadata are deleted from production systems and age out of backups on a rolling schedule. Two categories survive longer, by design:
Evaluating us for a security review? Write to [email protected] and we will answer directly, including sharing our current sub-processor list and a copy of the DPA. For data-protection requests, contact [email protected].
Related documents: Privacy Policy · GDPR · Cookie Policy · Security.