Legal
Privacy Policy
Last updated · July 2026
Sendnord respects your privacy and your right to control your personal data. We are transparent about what we collect and why, and we protect it with technical and organizational measures appropriate to the service.
- For our customers' subscriber and recipient data we are a processor: it is processed only on the customer's instructions, never for our own purposes.
- We never sell personal data and never combine it across customers. Within each customer's own account, we use their data to analyze engagement and the best time to reach recipients, using AI.
- We make no automated decisions with legal or similarly significant effects about you, perform no profiling for our own purposes, and do not track your browsing for marketing.
- Non-essential cookies on our website are set only after your active consent in the cookie settings.
- Customer Data is stored and processed in the EU/EEA - every provider, its processing location and any applicable safeguard is listed in our sub-processor register.
01Who we are and our two roles
The Sendnord service (the "Service") is provided by Sitepulse Marketing AB (reg. no. 559332-8510) ("Sendnord", "we"). We process personal data in two distinct roles:
- As controller: for our website, your account, billing, security and our own business communication.
- As processor: for Customer Data: the subscriber and recipient data our customers submit to the platform. It is processed only on the customer's documented instructions under our Data Processing Agreement.
If you receive email sent through Sendnord, the sender is the controller of your data. Contact the sender with questions or rights requests: we are obliged to assist them and provide the tools to do so (see "Your rights" below).
02Data we are responsible for: account and website
What we collect: name, work email address, phone number, company and billing details; login and usage logs; device data; support communication; and security data such as IP address and coarse location at login, used for security notices.
Purposes and legal bases:
| Purpose | Legal basis |
|---|---|
| Providing and administering your account, including support | Contract (Art. 6(1)(b)) |
| Security: login notices, abuse and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Billing, accounting and tax | Legal obligation (Art. 6(1)(c)) |
| Service communication about your account | Contract / legitimate interest |
| Product development: analyzing how the Service is used, to improve and secure it | Legitimate interest (Art. 6(1)(f)) |
| Marketing of our own, similar services to existing customers and to contacts who have asked to hear from us, always with an opt-out honored immediately | Legitimate interest (Art. 6(1)(f)); email marketing only within the limits of the Swedish Marketing Act (19-20 §§) |
We make no decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you. Where we have obtained your contact details from a source other than you: for example a public company register: we tell you the source when we first contact you.
Retention: account data is kept while the account is active and is deleted within thirty (30) days of account termination, unless a longer period is required by law or is necessary to establish, exercise or defend legal claims. Accounting records are kept for seven (7) years under the Swedish Bookkeeping Act. Data processed for our own marketing is not used longer than three (3) years after your last active contact with us.
03Customer Data we process on behalf of customers
Categories of Customer Data: subscriber identifiers and attributes (email address, name and custom fields the customer defines), consent records, message content, delivery events (sent, delivered, bounced), engagement events (opens, clicks, unsubscribes, complaints), coarse location derived from IP addresses (city/country level), device and email-client information, and suppression records.
We process this data solely to provide the Service on the customer's instructions. We do not sell it, do not use it for our own marketing, do not combine data across customers, build no identity profiles, and do not use it to train AI models. Engagement analysis and send-time optimization within the Service are performed on the customer's instructions and for the customer's purposes; we make no automated decisions with legal or similarly significant effects about any recipient. We may produce aggregated, anonymized statistics that can identify neither an individual nor an individual customer.
04How email tracking works
Emails sent through Sendnord may contain a tracking pixel and rewritten links so the sender can measure opens and clicks and compile statistics, including the coarse location described below. Whether and how tracking is used is decided and configured by the sending customer, who as controller is responsible for the legal basis: and, where required, the consents: for such measurement, and for informing recipients about it in its own privacy notice. This section describes what Sendnord collects when tracking is used and how it is handled, and senders may refer their recipients here for that description. Questions about tracking in a specific email should be directed to the sender.
When a tracking event occurs, our servers receive the requesting IP address. It is used for two purposes: deriving coarse location (city/country) and protecting the platform against abuse. Geolocation is performed against a local database on our own infrastructure: the IP address is never sent to a third party. The raw IP address is retained for a maximum of 72 hours in a segregated security log and is then truncated or deleted; only the coarse location is stored with the event. Location is never derived at finer than city level.
Where identifiable, we filter automated events: such as mailbox providers pre-fetching images or security systems pre-clicking links: from engagement reporting.
Unsubscribe and bounce-handling links are strictly necessary for the service and function for every recipient regardless of tracking settings.
05AI features
The AI features assist our customers with content generation, send-time optimization and campaign insights. Where a feature requires processing in a language model, the processing takes place in EU regions, under agreements that prohibit the provider from training on the data, and we pseudonymize or exclude personal data from the calls where the feature allows. The providers involved, their processing locations and any applicable safeguards are listed in our sub-processor register.
We do not use Customer Data to train or fine-tune AI models. Account-specific optimization (for example learning a list's best send times) uses only that account's own data, within the Service, and is never shared between customers.
06Where data is processed
Customer Data is stored and processed within the EU/EEA: application, database and sending infrastructure with Leaseweb in the EU (Germany), frontend hosting with Vercel with compute in EU regions, media and asset storage in Cloudflare R2 under EU jurisdiction controls, and AI inference in EU regions. Several of these providers have a parent company outside the EU; we engage them only where the processing stays inside the EU and under safeguards that meet EU requirements.
Each provider, its purpose, its processing location and: where relevant: the transfer safeguard applied (an adequacy decision, the EU Standard Contractual Clauses, or the EU-US Data Privacy Framework) is identified in our sub-processor register.
08Retention and deletion
- Account data: see "Data we are responsible for" above.
- Engagement events: retained while the customer's account is active, then deleted under the termination process below.
- Raw IP addresses: maximum 72 hours (see "How email tracking works").
- On account termination: export window and completed deletion within 30 days in total, including instructions to sub-processors.
- Backups: encrypted, rotated out within 35 days; deleted data is not restored to production: deletion is re-applied on any restore.
Customers can delete individual subscribers at any time; the deletion cascades through profile data, events and logs, while a hashed suppression record is retained so the opt-out remains effective.
09Your rights
If you have a Sendnord account, you can request access, rectification, erasure, restriction and data portability, and object to processing based on legitimate interest, by contacting privacy@sendnord.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY, imy.se) or your local supervisory authority.
If you are a subscriber or recipient of one of our customers, direct your request to the sender, who is the controller. We provide our customers with self-serve tools to export, rectify and delete individual subscribers' data, and we assist them without undue delay.
11Security
We protect data with encryption in transit and at rest, role-based access control and least privilege, isolation between customer accounts, logging of access to Customer Data, data minimization (including the IP truncation described under "How email tracking works") and a documented incident-management process. In the event of a personal data breach concerning Customer Data, we notify affected customers without undue delay in accordance with the Data Processing Agreement, so they can meet their own obligations toward supervisory authorities and data subjects.
12Links to other websites
Where our website contains links to third-party websites, they are provided for information purposes only. We have no control over, and accept no responsibility for, the content of such websites; their respective privacy policies apply there.
13Changes and contact
We may update this policy and always state the date of the latest revision above. Material changes affecting account holders are communicated by email or in the Service.
Questions and personal-data requests: privacy@sendnord.com.
This page is provided for general information and is not legal advice.