SendRSS
GDPR and data protection
Last updated 28 August 2026.
This page is SendRSS’s GDPR and UK GDPR notice: who is controller, who is processor, what we process, how rights work, and what an export is. It sits with the privacy policy and terms.
Contact for privacy requests: support@sendrss.com or Contact.
Controller and processor
SendRSS as controller
SendRSS is the controller of:
- Publisher accounts (email, name, sessions, plan mapping)
- This website’s essential cookies and, if allowed, optional extras
- Public contact messages and publisher support tickets
- Closure records after an account is deleted (email, date, hashed IP, account summary — not the subscriber list)
Lawful bases typically include: contract (to provide the account), legitimate interests (security, abuse prevention, limited audit after closure), and consent where we ask for optional cookies.
You as controller, SendRSS as processor
The publisher is the controller of their subscribers. They decide to embed the widget, which list people join, what the letter says, when RSS mail or a broadcast goes out, and whether to export or erase.
SendRSS is the processor for:
- Subscriber email, status, cadence settings
- Hashed, truncated IPs (never raw IPs)
- Confirm and unsubscribe tokens
- Delivery events (sent, bounce, complaint)
- Feed items used to compose a letter you asked us to send
- Widget, template, and broadcast content you save
We process that data only on documented instructions: the actions you take in the product (save, send, export, unsubscribe, purge, close account). We do not use your list for our own marketing. We do not sell it.
If you are in the EEA or UK, you must have a lawful basis to collect and mail. SendRSS requires double opt-in as a product rule. That does not replace your own notice, records of consent, or local e-privacy rules. You are responsible for telling readers who you are and how to reach you.
What we process (summary)
- Publishers — account, feeds, widgets, tickets. SendRSS is the controller.
- Subscribers — email, status, hashed IP, delivery events. The publisher is the controller; SendRSS is the processor.
- Site visitors — essential cookies, and optional extras only if allowed. SendRSS is the controller.
We do not process special-category data by design. Do not put it in a letter or ticket if you can avoid it.
Lawful basis (processor work)
As processor, our basis is your instruction plus our contract with you (terms). You must not instruct us to spam, to skip confirm, or to process a bought list. We may refuse instructions that would make the processing unlawful.
Your instructions and this DPA
Using SendRSS is your instruction to us to:
- Store list and mail configuration you save
- Send confirmations, RSS letters, and broadcasts you trigger, within plan and abuse limits
- Honour unsubscribe and erasure from the mail we send
- Produce CSV or JSON when you click export
- Delete operational data when you purge a subscriber or close the account
We will not process subscriber data for our own purposes, sell it, or disclose it except to subprocessors needed for the service, to you, or where the law requires. Confidentiality applies to people who handle the systems. We will assist with reasonable data-subject requests that concern data we hold, and with deletion after the account is closed, as described here.
If the law requires us to disclose data, we will limit the disclosure where we can. We do not sell data in response to a commercial request.
Subprocessors
We use specialised providers to host the application, store files you upload, deliver email, and (for paid plans) act as merchant of record. They process only what is needed for that job. A publisher with an account may ask support@sendrss.com for the current subprocessors that handle subscriber email.
International transfers, where they occur, use the provider’s applicable safeguards (for example standard contractual clauses). You instruct us to use those providers by using the service.
Security
- Double opt-in; pending addresses are not mailed
- IPs truncated, then hashed; raw IPs never stored
- Unsafe HTML stripped before storage or email
- No open pixels and no click-wrapping for profiling
- High-volume broadcasts may be held for review
- Account closure purges lists, subscribers, events, widgets, feeds, and sessions
Keep the account sign-in to people you trust.
Retention
See privacy. Processor data lasts until you erase the person, delete the list, or close the account, except where we must keep a minimal record (for example a hashed closure audit, or a delivery log required to handle a complaint already in flight).
Rights
Readers (your subscribers)
They can confirm, unsubscribe, or erase from the footer of mail we send. Erase deletes that address and related events for that list. They can also write to the publisher. If they write to SendRSS, we may point them to the publisher or, where we still hold the row as processor, carry out erasure they are entitled to from the mail link.
Access, portability, restriction, and objection for subscriber data are primarily exercised through the publisher. We do not start a separate marketing relationship with those readers.
Publishers (SendRSS as controller)
You may access and export account data (JSON), export subscribers (CSV), correct your profile, and close the account. You may object to optional cookies. To exercise other rights on account data, email support@sendrss.com from the account address.
You may complain to a supervisory authority in your EEA member state or to the UK ICO. We would rather fix the issue first.
Exports
An export is a copy of the publisher’s own list. Preparing the file is processor work. After download, the publisher holds that copy as they hold the list in SendRSS. We do not sell data; giving you your own list is not a sale.
If a reader asks what happened to an export, we can say that someone with access to the account may have downloaded a copy. Further questions belong with the publisher. See terms.
Personal data breaches
If we become aware of a breach affecting personal data we process, we will notify the relevant controller without undue delay and cooperate on information needed for any legal notice. A breach in the publisher’s own systems or in a file they exported is for the publisher to handle.
Automated decisions
SendRSS does not make legally significant automated decisions about readers (no credit score, no advertising profile). Pending vs confirmed is the result of whether they used the confirm link.
Children
The product is for publishers and adult readers. Do not use SendRSS to collect addresses from children.
Changes
The date at the top is the current version. We will keep this page aligned with how the product actually works.