Q: GDPR Compliance – EU-Based Business

I’m a small business owner based in Germany and considering using Encharge for email automation. Before moving forward, I have a few GDPR-related questions:
1. Data Hosting
– Where is user data stored (AWS region)?
– Do you provide Standard Contractual Clauses (SCC)?
– Can we sign a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR?
– Do you work with any sub-processors or external vendors for handling data?
2. Double Opt-In (DOI)
– Can Encharge support GDPR-compliant DOI flows?
– Is confirmation tracking (e.g. timestamp or tag) possible?
3. General Compliance
– Any guidance or docs for EU users?
– Do you set any tracking cookies or link trackers by default?

For context: we only collect names and email addresses – no sensitive data.

Thanks in advance for your help!

flinker.affePLUSApr 16, 2025
Founder Team
David_Encharge

David_Encharge

Apr 16, 2025

A: Hi flinker.affe 👋

Thank you for the thoughtful and thorough GDPR-focused questions — really appreciate how clearly you laid everything out 🙌 Here’s a full breakdown for you:

1. Data Hosting & Compliance
• Data Hosting: All user data is hosted securely on Amazon Web Services (AWS), specifically in the EU (Frankfurt region).
• Standard Contractual Clauses (SCCs): Yes, we provide SCCs as part of our compliance documentation for international data transfers.
• Data Processing Agreement (DPA): Absolutely. You can sign a DPA with us in accordance with Art. 28 GDPR. This is available to all Encharge customers — just shoot us an email at support@encharge.io and we’ll get you set up.
• Sub-processors: Yes, like most SaaS tools, we do rely on a small number of carefully vetted sub-processors (like AWS, Mailgun for email delivery, etc.). You can request the full up-to-date list via support — we’re transparent about who we work with and why.

2. Double Opt-In (DOI)
• Yes, Encharge supports GDPR-compliant DOI. You can create a fully custom DOI flow using our visual automation builder. For example:
• A person submits a form,
• You send a confirmation email,
• Only upon clicking the confirmation link does the person get added to your active list or receive emails.
• Confirmation tracking: Yes, you can track this using tags (like “DOI Confirmed”) or even store timestamps in custom fields if you want to get extra precise. Many of our EU customers use this exact setup.

3. General GDPR & EU Compliance
• Docs/Guidance: Apologies, we don’t have a dedicated GDPR whitepaper (yet). I'll note that down and share it with the team so we can begin looking at how we could do this in the near future!
• Cookies/Trackers: Encharge does not set tracking cookies or link trackers by default. You can choose to enable page visit tracking or use custom UTM rules — but it’s 100% optional and requires explicit implementation on your end. So you’re in control here ✅

Since you're only collecting names and emails — and you’re already thinking ahead to DOI and lawful basis — you’re in a great spot to stay GDPR compliant with Encharge 💪

Let me know if you'd like us to send over the DPA or sub-processor list directly — or if you want help setting up your DOI flow inside the app. Happy to help!!

Share
Helpful?
Log in to join the conversation
Related questions
View product details