← Back to docs

GDPR Tooling

Built-in tools for GDPR compliance and data subject rights

Data Portability (Account Export)

Under GDPR Article 20, individuals have the right to receive their personal data in a portable format. EuroMail provides an API endpoint to export all data associated with your account:

curl https://api.euromail.dev/v1/account/export \
  -H "Authorization: Bearer em_live_..."

The response includes account information, domains, templates, webhooks, email history, and suppression entries. The export is returned as a JSON document.

Right to Erasure (Account Deletion)

GDPR Article 17 grants individuals the right to have their personal data deleted. You can delete a whole euromail account in the dashboard under Settings > Delete this account, which asks for the account's email address and the owner's password, or over the API:

curl -X DELETE https://api.euromail.dev/v1/account \
  -H "Authorization: Bearer em_live_..." \
  -H "X-Confirm-Delete: DELETE"

The account stops sending immediately and the data is erased seven days later. The response says the date. Until then the deletion can be cancelled, in the dashboard or with:

curl -X POST https://api.euromail.dev/v1/account/restore \
  -H "Authorization: Bearer em_live_..."

The erasure removes the account and everything belonging to it: domains, templates, email metadata, delivery logs, tracking events, contacts, suppression entries, API keys, and any sub-accounts. After the seven days it is irreversible. Emails already delivered to recipients' mail servers cannot be recalled; the erasure covers the data held at euromail. Invoices are kept for seven years, as Finnish accounting law requires.

Per-Email Data Export

In addition to full account exports, EuroMail supports exporting all data associated with a specific email address. This is useful when handling data subject access requests (DSAR) for individual recipients:

curl "https://api.euromail.dev/v1/gdpr/[email protected]" \
  -H "Authorization: Bearer em_live_..."

The response includes email metadata (without bodies), delivery events, tracking tokens, suppression entries, unsubscribe events, inbound emails, agent mailbox messages, engagement stats, webhook delivery logs, ISP feedback-loop (complaint) reports, and any matching entries in the delivery retry queue, for the specified address — matched anywhere it can appear as a recipient (the to address, a cc/bcc entry, or a reply-to address), not only as the primary recipient. This endpoint is rate limited to 1 request per minute per account.

Per-Email Data Erasure

To erase all data associated with a specific email address without deleting the entire account, use the per-email erasure endpoint:

curl -X DELETE "https://api.euromail.dev/v1/gdpr/[email protected]" \
  -H "Authorization: Bearer em_live_..."

This permanently deletes every category listed under Per-Email Data Export above — emails naming the address as the envelope recipient (with their associated delivery events and tracking tokens), suppression entries, unsubscribe events, contact list memberships, inbound emails, agent mailbox messages, engagement stats, webhook delivery logs, ISP feedback-loop reports, and matching entries in the delivery retry queue. An email where the address appears only as a cc, bcc or reply-to — not the primary recipient — has the address stripped from those fields instead of the email being deleted, since deleting it would remove a different recipient's delivery record. The action is logged in the audit trail — with the address stored masked, not in plaintext — and cannot be undone. This endpoint is rate limited to 1 request per minute per account.

Audit Logging

Every action performed through the API or dashboard is recorded in the audit log with the following details:

FieldDescription
timestampWhen the action occurred (UTC)
userAPI key identifier or dashboard user who performed the action
actionWhat was done (e.g., email.sent, domain.created, suppression.deleted)
ip_addressSource IP address of the request
resourceThe affected resource identifier
detailsAdditional context about the action

Audit logs are accessible through the API and dashboard. They are retained for the duration of the data retention period and cannot be modified or deleted.

curl https://api.euromail.dev/v1/audit-logs?limit=50 \
  -H "Authorization: Bearer em_live_..."

Data Retention

EuroMail automatically manages data retention. Email body content (HTML and text) is purged after 30 days. Email metadata and delivery logs are retained for 6 months. Suppression list entries are retained independently of the retention period to prevent re-sending to bounced or complaining addresses.

Data Processing Agreement

A Data Processing Agreement (DPA) compliant with GDPR Article 28 is included with all EuroMail plans. The DPA covers the categories of data processed, processing purposes, sub-processor disclosures (none outside the EU), security measures, and breach notification procedures. Download the current DPA from euromail.dev/legal/dpa/.

Processing Records

EuroMail maintains records of processing activities as required by GDPR Article 30. These records document the types of personal data processed (email addresses, message metadata, IP addresses), the purposes of processing (transactional email delivery), and the technical and organizational security measures in place. You can request a copy of the processing records for your account at any time through the dashboard or by contacting support.

Send your first email in about 90 seconds

The free tier includes 3,000 emails a month. All data stays in Finland | GDPR compliance without the paperwork.

Create free account See live delivery data