Privacy Policy
How Send by Kodar handles personal data. We act in two different roles: as a controller for our own account holders, and as a processor for the recipient data our customers send through us.
Last updated 19 August 2026 · Kodar Tarkvara OÜ · Tallinn, Estonia
01Who we are
Kodar Tarkvara OÜ (Sõpruse pst 221-10, 13422 Tallinn, Estonia, reg. 17337554) operates Send by Kodar. For privacy questions contact privacy@kodar.io.
02Our two roles
Controller (account data). For the personal data of the people who create and run Send by Kodar accounts — name, email, sign-in records, billing records, and the details of anyone who asks us for an account — we decide the purposes and are the controller.
Processor (sent email). For the recipient email addresses and message content our customers send through the API, the customer is the controller and we are the processor, acting on their documented instructions. That processing is governed by our Data Processing Agreement.
03Account data we process
- Identity & sign-in
- Your name, email address and whether it is verified. Your password and your list of signed-in devices are held by the identity service listed as a subprocessor below (Neon Inc.), which is what makes one Kodar account work across Send, Sign and kodar.io — we never see or store your password. Our own records hold the workspace membership: which workspace you belong to, your role in it, and the terms version you accepted.
- Access requests
- The name, email, company and accepted terms version of anyone who asks for an account — whether or not access is granted — plus which of our admins decided it and when. We keep this to review the request, to recognise a repeat application and to prevent abuse of the signup queue (Art. 6(1)(f)), and we delete a decided request 12 months after the decision.
- Workspace
- Company name, plan, API keys (stored hashed), sending domains and DKIM keys.
- Billing
- Plan, orders, invoices and payment status (payments handled by Montonio).
- Usage & logs
- Send counts, delivery events, and diagnostic logs.
04Why, and on what legal basis
We process account data to provide the service and perform our contract with you (Art. 6(1)(b) GDPR), to comply with legal obligations such as tax and accounting (Art. 6(1)(c)), and for our legitimate interests in securing and improving the service and preventing abuse (Art. 6(1)(f)).
05Subprocessors & transfers
We use the following subprocessors to run the service:
- Amazon Web Services EMEA SARL (Amazon SES)
- Outbound email delivery (last mile) — EU (eu-north-1, Stockholm)
- Neon Inc.
- Managed Postgres — message metadata and bodies, recipient addresses, delivery events, account identity and credentials — EU region; US-incorporated provider, EU Standard Contractual Clauses
- Vercel Inc.
- Hosting for the dashboard, the REST API, the event ingest and the unsubscribe endpoint — EU region; US-incorporated provider, EU Standard Contractual Clauses
- Railway Corp.
- Hosting for the worker that renders and sends each message and dispatches webhooks — US-incorporated provider, EU Standard Contractual Clauses; deployment region not yet confirmed
- Montonio Finance UAB
- Payment processing for subscriptions (billing contact and payment status) — EU (Lithuania)
Data is hosted and processed in EU regions except where the table above states otherwise. Several of these providers are incorporated outside the EEA and may be subject to access by their parent group, so those transfers rely on the EU Standard Contractual Clauses together with supplementary technical measures (encryption in transit, encryption of secrets at rest). We publish changes to this list before a new subprocessor starts processing.
The public site loads no third-party fonts, scripts, analytics, or embeds, so visiting it sends your IP address to no one but us and our hosting provider.
06Retention
Account data is kept for the life of the account and a limited period afterward for legal and accounting purposes. Message content — the HTML and text body and any attachments — is erased 30days after the message reaches a final delivery state. Message metadata (recipient address, subject, status) and delivery events are then kept for your plan's log window — 30 days on Free, 90 days on Pro, 12 months on Scale and Enterprise — and automatically deleted after it. Deleting your account removes your workspace data (see Terms).
A request for an account is deleted 12months after it is decided, approved or refused alike. If you asked for an account and were turned down, that request is the whole of what we hold about you — and you do not have to wait for the window: sign in, and the “Your data” card on your status page removes it, along with the Kodar sign-in that was created when you applied, straight away.
Payment records — the amount, date, reference and who was billed — are the one thing we keep longer on purpose: seven years, as Estonian accounting law requires of a source document, and they survive the deletion of the account they belonged to (Art. 17(3)(b) GDPR). Our Terms say the same.
These windows are enforced by an automated pass, not by hand, and each run is recorded so we can show it happened.
07Your rights
Subject to law, you may request access, rectification, erasure, restriction, portability, or object to processing. Contact privacy@kodar.io. If you are a recipient of email sent through us, please contact the sender (the controller); we will assist them as their processor. You may also complain to your data-protection authority.