EMEA-first by design
Your legal and procurement team can finish a vendor-security review in one stop. Our GDPR posture, sub-processor list, data residency, breach-notification policy and security documents, all in one place.
On this page
At a glance
- EU primary data residency
- Your workspace data is stored in the EU as its primary home.
- 22 sub-processors, listed
- Every service that processes data for us is named on a public page.
- Encrypted at rest and in transit
- AES-256-GCM at rest. TLS in transit.
- Exports kept tight
- Exports include active leads only and stay locked for an account's first 7 days.
- WhatsApp consent, recorded
- Numbers connect through Meta's Embedded Signup. Leads without opt-in are never messaged.
- Your mailbox, your sender
- Campaign email goes through your own Gmail or Outlook, not a shared sending pool.
Certifications
We state only what we hold. Sequenz does not claim SOC 2 or ISO certifications it does not hold.
- GDPREU and UK GDPR. Our terms as your processor are in the DPA.Compliant
- SOC 2Not held today.Planned
- ISO 27001Not held today.Planned
Data residency
Data residency
Any transfer outside the primary region requires your explicit opt-in.
Sub-processors (22)
Third parties that may process personal data on your behalf, with their region. The full list adds purpose and data categories.
- Clerk, Inc.
- United States
- Stripe, LLC
- United States / EU
- Plus Five Five, Inc. (Resend)
- United States
- Functional Software, Inc. (Sentry)
- United States / EU
- PostHog, Inc.
- EU (Frankfurt)
- Vercel, Inc.
- EU (regional routing)
- Northflank Ltd
- EU · primary store
- Upstash, Inc.
- EU
- OpenAI OpCo, LLC
- United States
- Cloudflare, Inc.
- EU (regional routing)
- HubSpot, Inc.
- Customer-chosen region (US/EU/AU/CA)
- Salesforce, Inc.
- Customer-chosen region (US/EU)
- Pipedrive OÜ
- EU
- Calendly LLC
- United States
- Google LLC
- United States / EU
- Google LLC
- United States / EU
- Microsoft Corporation
- United States / EU
- Chrome extension telemetry (operated by Sequenz Ltd)
- EU
- Meta Platforms, Inc.
- EU when WABA registered to EU entity
- IPRoyal Services FZE LLC
- UAE (Ajman)
- Bright Data Ltd.
- Israel (Netanya)
- Bouncer Sp. z o.o.
- EU (Poland; processing in EU-based AWS, Frankfurt)
Breach notification
Supervisory authority
In the event of a personal-data breach, we notify the relevant supervisory authority within 24 hours of becoming aware of it (GDPR Article 33).
Affected customers
Affected customers are notified without undue delay, within 72 hours where the breach is likely to result in a high risk to data subjects (GDPR Article 34).
Security
Data is encrypted at rest using AES-256-GCM and in transit over TLS.
Our security whitepaper covers our architecture, access controls, and incident response.
Request the dossier
Already a customer? Sign in and send our full dossier to your legal or procurement team in one click: GDPR statement, sub-processor list, security whitepaper and DPA template.