EU-hosted email API · GDPR
A transactional email API that keeps your data in the EU.
Announcer stores everything on one server in Stockholm, never keeps the body of a message, and has no tracking to switch on. If you are choosing an email provider with a data protection review ahead of you, this page is the short answer to most of its questions.
By construction
Less to store means less to protect.
Data minimisation is usually a policy. Here most of it is a property of the system: the things below are true because of how Announcer is built, not because someone promised.
Stored in Stockholm, and nowhere else
Accounts, domains and message records live on a single host in Sweden, inside the EEA. There is no second region to replicate to, and backups are encrypted before they leave the server.
Message bodies are never stored
What you send is assembled, signed and handed to the mail server. No database record keeps it, so it cannot leak from us, be subpoenaed from us, or turn up in a support session. We keep the envelope, the subject line and what happened to the message.
No tracking pixels, no rewritten links
Open and click tracking is not a setting that defaults to off — it does not exist. Your recipients are not measured, so there is no tracking to justify, document or disclose.
Deletion that does not wait for us
Message history is deleted automatically when it falls outside your plan's window. Closing your account deletes everything attached to it immediately, from the dashboard, without an email to anyone.
For your records of processing
The facts a data protection officer usually asks a processor for, in one place. Each comes from our data processing agreement or privacy policy, which are the documents that bind us.
| Processor | Trohld AS, Ladebekken 38, 7041 Trondheim, Norway (trading as Misralo) |
| Your role and ours | You are the controller for your recipients' data; we are your processor |
| Where data is stored | One host in Stockholm, Sweden |
| Personal data processed | Recipient and sender addresses, subject lines, delivery metadata, bounce and complaint reports, your suppression list |
| Not stored | Message bodies |
| Retention | Message records: 14 days on Free, 90 days on Pro, then deleted automatically. Suppression list: until you remove an entry |
| Sub-processors | Akamai (Linode), hosting and backups, Stockholm. Cloudflare, DNS for our own domains. The list, with 30 days' notice of any change |
| Article 28 terms | In force from the moment an account is created; a countersigned copy on request |
| Breach notification | Without undue delay, as soon as a breach is confirmed |
The questions worth asking
Does my mail leave the EU?
When it has to. Data we store stays in Stockholm, but a message goes to the recipient's own mail provider, wherever that provider is. Mail to a Gmail address goes to Google. That is how email works with every provider, and the destination is set by the address you send to, not by us. The DPA covers it in section 8.
Who runs the server?
Akamai, through its Linode cloud, in its Stockholm data centre. Akamai is an American company. Any access it has to data from outside the EEA, in running or supporting that infrastructure, is covered by the European Commission's Standard Contractual Clauses in its own data protection terms. We name it here so you do not have to go looking.
Can you show me a message I sent?
The envelope, yes: who it went to, when, its subject and every change of delivery status. The body, no — not to you, not to support, and not to anyone who asks us for it. That is the trade-off. If you need a copy of what you sent, keep it on your side, where it is already under your own controls.
What about subject lines?
Those are stored, on purpose, because "which message was that?" is unanswerable without them. Keep anything sensitive out of the subject and it never reaches our database.
Do I need to sign anything?
No. The DPA applies to every account automatically. If your organisation needs a signed copy on paper, write to privacy@misralo.com and we will sign one.
What happens when one of my users asks what you hold about them?
You can answer it yourself, straight away: message records are searchable by recipient
in the dashboard and through GET /v1/messages, and your
suppression list is readable and editable the same way. If the person writes to us
instead, we tell them to contact you, and tell you it happened.
Does using Announcer make me GDPR compliant?
No provider can do that for you. You still need a lawful basis to email the people you email, and what you put in a message is yours to answer for. What Announcer can do is hold as little as possible, in one place, under terms you can read in ten minutes.