Skip to content
Skip to content
Legal documents· Security and compliance
Trust and compliance

EMEA-first by design

Your legal and procurement team can finish a vendor-security review in one stop. Our GDPR posture, sub-processor list, data residency, breach-notification policy and security documents, all in one place.

GDPR · CompliantPosture data refreshed hourly
On this page

At a glance

EU primary data residency
Your workspace data is stored in the EU as its primary home.
22 sub-processors, listed
Every service that processes data for us is named on a public page.
Encrypted at rest and in transit
AES-256-GCM at rest. TLS in transit.
Exports kept tight
Exports include active leads only and stay locked for an account's first 7 days.
WhatsApp consent, recorded
Numbers connect through Meta's Embedded Signup. Leads without opt-in are never messaged.
Your mailbox, your sender
Campaign email goes through your own Gmail or Outlook, not a shared sending pool.
Back to top

Certifications

We state only what we hold. Sequenz does not claim SOC 2 or ISO certifications it does not hold.

  • GDPREU and UK GDPR. Our terms as your processor are in the DPA.
    Compliant
  • SOC 2Not held today.
    Planned
  • ISO 27001Not held today.
    Planned
Back to top

Data residency

Back to top

Sub-processors (22)

Third parties that may process personal data on your behalf, with their region. The full list adds purpose and data categories.

Clerk, Inc.
United States
Stripe, LLC
United States / EU
Plus Five Five, Inc. (Resend)
United States
Functional Software, Inc. (Sentry)
United States / EU
PostHog, Inc.
EU (Frankfurt)
Vercel, Inc.
EU (regional routing)
Northflank Ltd
EU · primary store
Upstash, Inc.
EU
OpenAI OpCo, LLC
United States
Cloudflare, Inc.
EU (regional routing)
HubSpot, Inc.
Customer-chosen region (US/EU/AU/CA)
Salesforce, Inc.
Customer-chosen region (US/EU)
Pipedrive OÜ
EU
Calendly LLC
United States
Google LLC
United States / EU
Google LLC
United States / EU
Microsoft Corporation
United States / EU
Chrome extension telemetry (operated by Sequenz Ltd)
EU
Meta Platforms, Inc.
EU when WABA registered to EU entity
IPRoyal Services FZE LLC
UAE (Ajman)
Bright Data Ltd.
Israel (Netanya)
Bouncer Sp. z o.o.
EU (Poland; processing in EU-based AWS, Frankfurt)

See the full list

Back to top

Breach notification

24hours

Supervisory authority

In the event of a personal-data breach, we notify the relevant supervisory authority within 24 hours of becoming aware of it (GDPR Article 33).

72hours

Affected customers

Affected customers are notified without undue delay, within 72 hours where the breach is likely to result in a high risk to data subjects (GDPR Article 34).

Back to top

Security

Data is encrypted at rest using AES-256-GCM and in transit over TLS.

Our security whitepaper covers our architecture, access controls, and incident response.

Request the whitepaper
Back to top

Request the dossier

Already a customer? Sign in and send our full dossier to your legal or procurement team in one click: GDPR statement, sub-processor list, security whitepaper and DPA template.

Back to top