Data Portability (Account Export)
Under GDPR Article 20, individuals have the right to receive their personal data in a portable format. EuroMail provides an API endpoint to export all data associated with your account:
curl https://api.euromail.dev/v1/account/export \
-H "Authorization: Bearer em_live_..."
The response includes account information, domains, templates, webhooks, email history, and suppression entries. The export is returned as a JSON document.
Right to Erasure (Account Deletion)
GDPR Article 17 grants individuals the right to have their personal data deleted. You can delete a whole euromail account in the dashboard under Settings > Delete this account, which asks for the account's email address and the owner's password, or over the API:
curl -X DELETE https://api.euromail.dev/v1/account \
-H "Authorization: Bearer em_live_..." \
-H "X-Confirm-Delete: DELETE"
The account stops sending immediately and the data is erased seven days later. The response says the date. Until then the deletion can be cancelled, in the dashboard or with:
curl -X POST https://api.euromail.dev/v1/account/restore \
-H "Authorization: Bearer em_live_..."
The erasure removes the account and everything belonging to it: domains, templates, email metadata, delivery logs, tracking events, contacts, suppression entries, API keys, and any sub-accounts. After the seven days it is irreversible. Emails already delivered to recipients' mail servers cannot be recalled; the erasure covers the data held at euromail. Invoices are kept for seven years, as Finnish accounting law requires.
Per-Email Data Export
In addition to full account exports, EuroMail supports exporting all data associated with a specific email address. This is useful when handling data subject access requests (DSAR) for individual recipients:
curl "https://api.euromail.dev/v1/gdpr/[email protected]" \
-H "Authorization: Bearer em_live_..."
The response includes email metadata (without bodies), delivery events, tracking tokens, suppression entries, unsubscribe events, inbound emails, agent mailbox messages, engagement stats, webhook delivery logs, ISP feedback-loop (complaint) reports, and any matching entries in the delivery retry queue, for the specified address — matched anywhere it can appear as a recipient (the to address, a cc/bcc entry, or a reply-to address), not only as the primary recipient. This endpoint is rate limited to 1 request per minute per account.
Per-Email Data Erasure
To erase all data associated with a specific email address without deleting the entire account, use the per-email erasure endpoint:
curl -X DELETE "https://api.euromail.dev/v1/gdpr/[email protected]" \
-H "Authorization: Bearer em_live_..."
This permanently deletes every category listed under Per-Email Data Export above — emails naming the address as the envelope recipient (with their associated delivery events and tracking tokens), suppression entries, unsubscribe events, contact list memberships, inbound emails, agent mailbox messages, engagement stats, webhook delivery logs, ISP feedback-loop reports, and matching entries in the delivery retry queue. An email where the address appears only as a cc, bcc or reply-to — not the primary recipient — has the address stripped from those fields instead of the email being deleted, since deleting it would remove a different recipient's delivery record. The action is logged in the audit trail — with the address stored masked, not in plaintext — and cannot be undone. This endpoint is rate limited to 1 request per minute per account.
Audit Logging
Every action performed through the API or dashboard is recorded in the audit log with the following details:
| Field | Description |
|---|---|
timestamp | When the action occurred (UTC) |
user | API key identifier or dashboard user who performed the action |
action | What was done (e.g., email.sent, domain.created, suppression.deleted) |
ip_address | Source IP address of the request |
resource | The affected resource identifier |
details | Additional context about the action |
Audit logs are accessible through the API and dashboard. They are retained for the duration of the data retention period and cannot be modified or deleted.
curl https://api.euromail.dev/v1/audit-logs?limit=50 \
-H "Authorization: Bearer em_live_..."Data Retention
EuroMail automatically manages data retention. Email body content (HTML and text) is purged after 30 days. Email metadata and delivery logs are retained for 6 months. Suppression list entries are retained independently of the retention period to prevent re-sending to bounced or complaining addresses.
Data Processing Agreement
A Data Processing Agreement (DPA) compliant with GDPR Article 28 is included with all EuroMail plans. The DPA covers the categories of data processed, processing purposes, sub-processor disclosures (none outside the EU), security measures, and breach notification procedures. Download the current DPA from euromail.dev/legal/dpa/.
Processing Records
EuroMail maintains records of processing activities as required by GDPR Article 30. These records document the types of personal data processed (email addresses, message metadata, IP addresses), the purposes of processing (transactional email delivery), and the technical and organizational security measures in place. You can request a copy of the processing records for your account at any time through the dashboard or by contacting support.