How we protect the data we process, what our role is, how we handle individuals' rights and how we respond to incidents.
Last updated: 23 September 2026 · Version 3.0
This policy explains how SendingBay protects the data it processes when providing its services, what its role is with respect to that data, how it handles individuals' rights and how it responds to incidents. It is common to all SendingBay products and services.
Each product line processes different data and has its own retention periods and obligations. That detail is set out in the annexes to this policy, which form part of it:
Where an annex specifically regulates a matter, the annex prevails; in all other respects this policy applies. When SendingBay adds a new product line, it will publish its annex at this same address.
This policy applies to all SendingBay products and services and to everyone who works on them. This policy and its annexes complement, and do not replace, the website privacy policy, the cookie policy, the terms of service with their data processing agreement, and the list of providers and sub-processors.
SENDINGBAY S.L., tax ID B44799815, with registered office at Calle Mariano Cuber 17 (Wayco Cabanyal), 46011 Valencia, Spain. Registered in the Valencia Companies Register, Volume 11330, Book 8608, Folio 68, Section 8, Sheet V-209573.
When a customer uses a SendingBay product, the customer is the controller of the data of its own customers, buyers or recipients, and SendingBay acts as processor on its behalf, following its instructions and the data processing agreement that forms part of the terms of service. With respect to the customer's account data (users, company and billing), SendingBay is the controller, for the purpose of providing the service, giving support and invoicing. Third parties involved in providing the service —carrier networks, sales platforms or others— are independently responsible for the data they receive to perform their function; each annex describes those involved in its product line.
Data is processed and stored in data centres located in the European Economic Area, with infrastructure providers bound by data processing agreements. Any international transfer of personal data would be carried out with the safeguards required by European law. The list of providers, with the purpose and location of each, is at www.sendingbay.com/subencargados.
We apply technical and organisational measures proportionate to the risk: encryption of communications and of stored data, least-privilege access control with strong authentication, logging and auditing of administrative access, encrypted backups, separation of environments, confidentiality obligations and staff training, and providers holding recognised security certifications. These measures are reviewed periodically.
Personal data is kept only for as long as needed for the purpose for which it is processed and for any applicable legal retention periods, and is then effectively and permanently deleted; backups delete it when they complete their rotation cycle. The specific periods for each product line are in its annex. Customer account data is kept for the duration of the contractual relationship and for the legal periods that follow. On a customer's written request, we confirm deletion in writing.
Any person or customer may exercise the rights of access, rectification, erasure, restriction, portability and objection, or ask us what data we process, by writing to privacidad@sendingbay.com. We will ask for reasonable identification and reply within one month at most, free of charge. Where the request concerns data for which a SendingBay customer is the controller, we will forward it and help the customer respond. A complaint may also be lodged with the Spanish Data Protection Agency (www.aepd.es).
We have an incident response procedure with defined roles, timelines and channels. In the event of an incident affecting the data or credentials of a customer or of a connected third party, we contain and assess it without delay, notify those affected without undue delay and within the timelines set by applicable law and agreements, notify the Spanish Data Protection Agency within a maximum of 72 hours where the law requires it, and inform the individuals concerned where there is a high risk to them. We provide those affected with information about the incident and the measures taken.
If you detect a vulnerability or an incident affecting SendingBay, write to seguridad@sendingbay.com.
The providers that process data on behalf of our customers are published and kept up to date at www.sendingbay.com/subencargados.
We publish each version of this policy and of its annexes at this same address with its date. If a change materially affects how we process a customer's data, we inform the customer before applying it.
SENDINGBAY S.L.