Where transactional email data is stored

How to assess transactional email data locations, subprocessors, backups, support access, and GDPR transfers, with Sendtier's preview answers.

GDPR imposes no general requirement to store transactional email in the EU. Article 44 and the EDPB's transfer guide explain the rules for transferring personal data outside the European Economic Area (EEA). Storage in the EEA alone does not settle the question. Access by an importer in a third country can also be a transfer, as the EDPB Guidelines 05/2021, version 2.0 describe. Ask your data protection officer how those rules apply to a given provider. The Commission's EU-US transfers page says personal data can flow freely from the EU to US companies that participate in the Data Privacy Framework.

Four parts of email data residency

Check the sending region, storage locations, responsible companies, and backup and support arrangements. Read the provider's pages for each part before you treat one region label as the whole answer.

Where the message is sent from

The sending region identifies the provider's outbound email infrastructure, so confirm its location in the provider's documentation.

Resend's region docs say you "select the region you want to send your emails". The regions on that page are us-east-1, eu-west-1, sa-east-1, and ap-northeast-1, and the label for eu-west-1 is "Ireland (eu-west-1)". For multiple regions, Resend recommends a separate subdomain per region. To change a domain's region, its documentation instructs users to delete and re-add the domain, then update DNS.

Amazon SES names the region on the API endpoint. The endpoints page lists Europe (Frankfurt) as eu-central-1. The SES API endpoint identifies the selected AWS Region, and Frankfurt's API host is email.eu-central-1.amazonaws.com.

The recipient's mail server stores the delivered copy, and the sending region does not set that location. Write the outbound region and the recipient mailbox as two places.

Where content, metadata, and logs are stored

The sending region does not decide where the provider stores the message you submitted. Resend's region docs say account data "is stored in the United States regardless of the sending region". Resend's GDPR page says "Resend stores customer data in the United States, including message content". The same page says "there is no setting today that moves stored data to the EU". Ireland can be the sending region while the stored copy stays in the United States.

Message content, delivery events, and API logs can have different storage locations. Ask which data the region setting covers, and which page names each store.

On Amazon's own service, the customer selects the storage region. The AWS GDPR white paper says "The customer selects the AWS region in which it stores its customer data." A Frankfurt SES endpoint identifies the SES API region. It does not name the database region an email vendor uses for message content.

Which company handles it, and under which law

Identify the contracting company, applicable terms, and subprocessors separately from the data center location. The city where a disk sits does not name the legal entity, the law in the contract, or each company that can process the content.

Postmark's GDPR FAQ says it stores data in the US, and its EU privacy page identifies Deft and AWS as infrastructure providers.

Resend's DPA includes standard contractual clauses and states participation in the EU-U.S. Data Privacy Framework. When relying on the framework, verify the organization's current listing and the data covered, and retain the applicable DPA version.

Backups and support access

Confirm where backup copies are stored and from which countries staff or service providers can access message content. A database region does not, by itself, name the backup copy or the countries from which people can open a message. If the provider's pages do not name those places, record the answer as unknown.

The recipient's mail server stores the delivered message. Your webhook endpoint receives event data, and any storage location depends on how you implement that receiver. Write both down, because the email API does not choose them.

Who owns the infrastructure

Ask which companies own the infrastructure and which operate it. Record those companies separately from the data center locations, and mark ownership as unknown when the provider cannot confirm it.

Questions to ask any provider

Record each answer and its supporting documentation. Mark any location or access policy the provider cannot confirm as unknown.

Questions 1 and 2 separate the sending region from stored message content. Questions 3 and 4 cover metadata, logs, and backups. Questions 5 to 7 cover the contracting company, subprocessors, and any Chapter V transfer. Questions 8 and 9 cover retention and support access.

  1. Does a public page name the region that submits mail to the recipient's server?
  2. Does a public page say whether stored message content uses that same region?
  3. Does a public page name where metadata, delivery events, and API logs are stored?
  4. Does a public page name where database backups are stored, and whether a copy can leave that region?
  5. Does the contract name the legal entity, and the law and court that govern it?
  6. Does a subprocessor list name each party, what it processes, and the country or region?
  7. Does the arrangement involve a Chapter V transfer, and what documentation supports the assessment and any applicable transfer mechanism?
  8. Does a public page state how long emails, events, and webhook deliveries are kept, and whether you can export and delete them?
  9. Does a public page say whether support staff can read message content, and from which country?

For a transfer, identify the applicable adequacy decision or safeguards. Article 49 exceptions apply only in specific circumstances.

How Sendtier answers

Sendtier is in public preview, and MB Tobuli operates it. Live sending is limited during the public preview. Here are Sendtier's answers to those questions.

  1. Yes. Email is sent through Amazon SES in AWS eu-central-1 (Frankfurt). The following MAIL FROM MX record points to the SES feedback endpoint in that region:
send.example.com.  MX  10  feedback-smtp.eu-central-1.amazonses.com.

The SPF value on that host is v=spf1 include:amazonses.com ~all. The domain guide lists the records for a real domain.

  1. Yes for the application database. It is in eu-central-1, the same region as sending. It stores the sender, recipients, subject, HTML body, text body, tags, status, and delivery events. Raw MIME is not stored.
  2. Emails, delivery events, and webhook deliveries are stored in that database. API log and archive locations are not confirmed here.
  3. Yes for automated database backups. They stay in the same region. The API, workers, and queues are in eu-central-1 as well.
  4. The operator is MB Tobuli. Governing law and dispute forum are not confirmed here.
  5. Amazon Web Services is a subprocessor, including for sending through Amazon SES. The draft list is at /legal/subprocessors/. Read it for the parties and regions it names.
  6. The transfer assessment and any applicable Chapter V mechanism are not confirmed in this guide.
  7. Yes. Emails, events, and webhook deliveries are kept 30 days by default, then removed. An organization owner can export retained emails and their events, and delete the organization. Deletion has a 30-day restore window. See the retention guide.
  8. Support-access countries and permissions are not confirmed in this guide.

A test key (st_test_) can accept a send while the domain's DNS is still pending, but that message does not reach Amazon SES. A live key (st_live_) needs a verified domain. The sending guide describes the stored fields and the request.

Try the public preview with a free test key. Test messages are not delivered.