GDPR Compliance

Last updated: May 20, 2026

1. Our Commitment to GDPR

Dispatchy (operated by SYNTAX-ENCODE Kft.) is committed to fully complying with the European Union's General Data Protection Regulation (GDPR). We ensure that our platform is built on the principles of Privacy by Design and Privacy by Default, protecting your and your subscribers' data at the highest level.

2. Data Controller vs. Data Processor Role

Under the GDPR, Dispatchy fulfills two distinct and clearly separated roles:

Data Controller

When you register on our platform and create a Workspace account, we act as the Data Controller of your personal data (e.g., billing details, name, email, login credentials). We process this data for the purpose of providing the service.

Data Processor

When you upload your subscribers' email lists to our system, you are the Data Controller, and Dispatchy acts exclusively on your instructions as a Data Processor. We never use imported lists for our own marketing purposes and do not sell them to third parties.

3. Data Security Measures

We guarantee the highest level of security for our clients, minimizing the risk of data leaks:

  • Encryption: All network traffic between the browser and servers uses strong TLS/SSL encryption (in-transit). Passwords are stored using one-way, secure hashing (bcrypt).
  • Row Level Security: Using technical means at the database level, we guarantee that users of a specific Workspace can only access their own data, campaigns, and subscribers.
  • Logging and Access Control: For security reasons, we log modifications to critical data. Only authorized system engineers have access to the infrastructure.

4. Data Processing Agreements (DPA) and Partners

To operate the service reliably, we use external technology partners. We have a valid Data Processing Agreement (DPA) with all our data processors, guaranteeing that they also comply with strict GDPR requirements. Our main partners:

  • Vercel Inc.: Cloud infrastructure and application hosting.
  • Neon, Inc.: Secure, scalable PostgreSQL database.
  • Amazon Web Services (AWS SES): High-deliverability global email sending.
  • Stripe, Inc.: PCI-DSS compliant processing of credit card payments.
  • Sentry: Application-level error tracking for stability.

5. Physical Data Storage and International Transfers

The database and infrastructure of our system run in strictly controlled, SOC 2 and ISO 27001 certified data centers in Europe and the United States.

If personal data is transferred outside the European Economic Area (EEA) (e.g., to the United States) to our cloud providers, this is done exclusively on the basis of the Standard Contractual Clauses (SCC) adopted by the European Commission or under the EU-US Data Privacy Framework, providing appropriate safeguards.

6. Data Portability and Right to be Forgotten

In accordance with GDPR rights, Dispatchy gives you full control over your data on the platform:

  • Data Portability: You can export your subscriber lists at any time with a single click in standard CSV format from the Dashboard.
  • Right to be Forgotten: Under the "Danger Zone" in the Settings menu, you can permanently and completely delete your entire Workspace account, campaigns, and subscribers from our system.
  • Automatic Unsubscribe: At the bottom of sent campaigns, we always include a one-click unsubscribe link, ensuring subscribers' right to self-determination.

Please send any requests or questions related to privacy, GDPR compliance, or data portability to adatvedelem@getdispatchy.com, and our Data Protection Officer will reply shortly.