Senduler privacy policy
Last updated: July 2026
Who we are
Adam Williams, operating Senduler (sole proprietorship), provides a form-backend service that receives submissions from websites on behalf of our customers (agencies and site owners). We are based in Toronto, Ontario, Canada. Our website is senduler.com.
Contact: privacy@senduler.com Related: Terms of Service · DPA (for form submission data we process on your behalf)
Two roles
When we are the data controller
We act as controller for data about account holders (registration, login, billing, support):
- Name, email address, password hash
- Agency and client configuration
- Usage and billing records
- Payment metadata processed by Stripe (we do not store full card numbers)
- Support correspondence
- DPA acceptance records (version, timestamp, accepting user)
- Security and audit logs (login activity, submission access by your team where logged)
Lawful basis: performance of our Terms of Service, and legitimate interests (security, fraud prevention, service improvement). Marketing emails, if any, rely on consent or applicable soft-opt-in rules — you may unsubscribe at any time.
We do not sell personal information.
When we are the data processor
We act as processor for form submission data submitted by visitors to our customers' websites:
- Field values submitted through forms (name, email, message, etc.)
- Uploaded files
- Technical metadata (IP address, user agent, referer, origin)
Our customers (agencies and their end clients) are the controllers for this data. We process it only on their documented instructions, as set out in our Data Processing Agreement and SCC annex where applicable.
How we use submission data
- Store submissions in a secure inbox
- Send notification emails and auto-responses as configured
- Deliver webhooks to customer endpoints
- Filter spam and abuse
- Apply retention and automatic deletion per customer settings
We do not sell submission data or use it for advertising.
Automated spam and abuse filtering
We use automated checks (honeypot, rate limits, optional captcha, keyword rules) to classify submissions as clean, suspected, or blocked. This supports abuse prevention only; it does not produce legal or similarly significant effects on visitors. Controllers review suspected submissions in the inbox.
Copies outside Senduler
Notification emails, auto-responders, webhooks, and exports may create additional copies of submission data under your control or at third parties you configure (e.g. your mail provider, Slack, your webhook URL). See international transfers FAQ.
Retention
- Account data: kept while the account is active and for a reasonable period after closure.
- Submission data: retained per each client's configured retention period (default 365 days), then automatically deleted (with a short recovery window before permanent purge). Spam/blocked submissions use a shorter default (30 days). Customers may request earlier deletion.
- Billing records: retained as required for tax and accounting law.
Cookies and similar technologies
| Context | What | Purpose |
|---|---|---|
Dashboard (app.senduler.com / local dev) |
JWT stored in browser storage after login | Keep you signed in |
| Marketing site | Essential cookies only (no third-party analytics in v1) | Basic site operation |
We do not use advertising cookies on the marketing site in v1. If we add analytics later, we will update this policy and obtain consent where required.
Children
The Service is not directed at children under 16 (or 13 in the US). Do not use Senduler to collect children's data without appropriate parental consent and legal advice.
Data location
| What | Where |
|---|---|
| Form submissions (field data), account data | United States — IONOS Cloud VPS (application and PostgreSQL database) |
| Uploaded files | United States — IONOS Cloud Object Storage |
| Senduler operations (support, administration) | Toronto, Ontario, Canada |
This applies regardless of where form visitors are located. Visitors' data is processed and stored in the United States when they submit a form.
Canada (PIPEDA and Ontario)
We are accountable under PIPEDA for personal information in our custody or control, including information transferred outside Canada. Personal information is stored in the United States. We use contractual and technical safeguards. Canadian account holders and customers should inform their own users where applicable.
Ontario residents may also have rights under provincial privacy law. You may contact the Office of the Privacy Commissioner of Canada (OPC) or, where applicable, the Information and Privacy Commissioner of Ontario (IPC).
United Kingdom and EEA (GDPR)
Where UK or EEA personal data is processed, transfers to our US infrastructure are covered by Standard Contractual Clauses — see our SCC annex. We do not rely on the EU-US Data Privacy Framework unless our legal structure changes.
Sub-processors
Some sub-processors (email, payments, captcha) may also process data in the United States or globally.
Your responsibility as a customer
If you use Senduler on your website, you must disclose in your privacy notice that submissions are processed by Senduler and stored in the United States. See our customer privacy snippet.
Your rights (account holders)
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your account data, and to object to or restrict certain processing.
Canada
Under PIPEDA and applicable provincial privacy laws (including Ontario), you may request access to and correction of your personal information. You may complain to the Office of the Privacy Commissioner of Canada (OPC) or, where applicable, the Information and Privacy Commissioner of Ontario (IPC).
United Kingdom and EEA
Under UK GDPR / EU GDPR, you may have rights including access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with your local supervisory authority (e.g. ICO in the UK).
United States
Residents of California and certain other states have additional rights under state privacy laws (including rights to know, delete, and correct personal information, and to opt out of certain sales or sharing). We do not sell personal information.
To exercise your rights, contact privacy@senduler.com. We may need to verify your identity before responding.
Account closure
You may close your account via Settings or by contacting privacy@senduler.com. We delete or anonymise account data when no longer needed, subject to legal retention requirements. Export submission data before closure if you need a copy.
Data protection officer
We have not appointed a Data Protection Officer. For privacy enquiries contact privacy@senduler.com. UK/EEA residents may lodge complaints with their supervisory authority.
Security
We use encryption in transit, access controls, rate limiting, and audit logging. See security documentation. Report vulnerabilities to security@senduler.com.
Changes
We may update this policy. Material changes will be communicated where required. The DPA version is tracked separately; you may need to re-accept the DPA when it changes.