TRUST / GDPR & UK GDPR
GDPR, withoutthe theatre.
You capture people's details; that makes you a controller and us your processor. Here's how the responsibilities split - and what we've built to make yours easy.
GDPRTHE SPLIT
Who does what
YouCONTROLLER
Your responsibilityHave a lawful basis for contacting the people you scan (e.g. legitimate interest for relevant B2B outreach), be transparent, honour objections.
Qsend makes it easyUnsubscribe on every email, suppression honoured workspace-wide, contact deletion tools, event context stored so you can show where consent context came from.
UsPROCESSOR
Our responsibilityProcess contact data only on your instructions, secure it, help you answer data-subject requests, delete on verified request.
What we provideEncryption in transit and at rest, role-based access, export-by-email, verified permanent deletion, DPA and sub-processor list for enterprise agreements.
BothSHARED
Shared dutyRespect data-subject rights: access, rectification, erasure, portability, objection.
The workflowRequests to privacy@qsend.cc are routed to your workspace admin with the tooling to fulfil them - usually in minutes, not weeks.