
AhaSend
GDPR CompliantDutch transactional email API and SMTP relay on Hetzner infrastructure in Germany and Finland, with a complete published DPA and every sub-processor named by country.

GDPR Compliance Data
Not independently verified| GDPR Status | GDPR Compliant |
| HQ Country | Netherlands |
| Ownership | European-owned |
| Foreign Disclosure Exposure | None known |
| Data Hosting Location | European Union"Cloud Hosting & Infrastructure: Hetzner Online GmbH (Germany/Finland, and optionally USA if you chose to use our US-based SMTP relay) and DA International Group Ltd (operating as AlphaVPS, Bulgaria) to host our Services and associated data" (ahasend.com/privacy). The policy adds: "Our hosting providers, Hetzner Online GmbH (primary locations in Germany and Finland) and DA International Group Ltd (Bulgaria), are also based within the EEA. Data transfers to these providers are within the EEA and do not require the specific international transfer safeguards mentioned above for third countries." The pricing page describes "Multi-region EU infrastructure" on every plan including the free one. All read 2026-09-01. |
| EU Servers Available | |
| Data Processing Agreement | View DPA |
| Sub-processor List | View sub-processors |
| Schrems II Risk | Low Risk |
| SCCs in Place | |
| Last Verified | 1 September 2026 |
How we reached this
Dutch legal entity: AhaSend B.V., named as both controller and processor in the privacy policy read 2026-09-01. COMPLIANT on the strongest documentation in this tranche: a complete Article 28 DPA published at ahasend.com/dpa with Annex 1 (details of processing), Annex 2 (technical and organisational measures) and Annex 3 (sub-processor list, with the online version declared authoritative), plus a privacy policy that names every sub-processor with its country and its purpose. Exposure NONE, following the Statable precedent: message content and recipient data sit on Hetzner (German company, Germany and Finland) and AlphaVPS (Bulgarian), so no US provider holds the email itself in the default configuration. The named US providers touch adjacent data only, and the vendor says which: Stripe for payments, PostHog for analytics, Cloudflare for website security, all three under the EU-US Data Privacy Framework. Two caveats recorded rather than buried. First, AhaSend offers an OPTIONAL US-based SMTP relay; a customer who selects it has message data processed on Hetzner's US infrastructure under Standard Contractual Clauses, which the policy states plainly. This listing rates the default configuration. Second, the site describes ISO 27001 as pending rather than held. Retention is customer-configurable from zero days, and account data is erased within 14 days of a deletion request, with billing records kept seven years under Dutch tax law.
About AhaSend
Transactional Email With the Paperwork Actually Done
AhaSend is a developer-facing sending service, competing with the transactional side of the large platforms. What makes it worth a close look here is not the API, which is conventional and well documented. It is that the compliance documentation is the best of any tool in this tranche, by a distance.
The Product
- REST API and SMTP relay with official SDKs, a CLI and sandbox mode
- Dedicated IPs with automated warm-up, dedicated IP pools, and bring-your-own-IP at the top tier
- Inbound email routing and signed webhooks, so replies and events come back into your own system
- Platform Partner features: sub-accounts, DNS whitelabeling, per-domain DKIM selectors and bring-your-own-DKIM keys, which is what you need if you are reselling sending inside your own product
- Reputation Shield and typosquatting protection
- Configurable retention, from zero days upward, so you can choose not to have message bodies stored at all
Pricing starts at a genuine free tier of 1,000 emails a month with no card, on the same multi-region EU infrastructure as the paid plans. Pro covers 25,000 and Max 100,000, with flat-rate billing plus per-thousand overage, in USD or EUR. There are no long-term contracts.
Named Sub-processors, With Countries
Most vendors write "we use third-party providers". AhaSend writes this:
Cloud Hosting and Infrastructure: Hetzner Online GmbH (Germany/Finland, and optionally USA if you chose to use our US-based SMTP relay) and DA International Group Ltd (operating as AlphaVPS, Bulgaria) to host our Services and associated data.
Then it names the US ones separately and says exactly what each does: Stripe for payments, PostHog for analytics, Cloudflare for website security, all three relying on the EU-US Data Privacy Framework, and Trackdesk in Czechia for the affiliate programme. It commits to erasing personal data within 14 days of an account deletion request, and explains that billing records are kept seven years because Dutch tax law requires it.
The DPA at ahasend.com/dpa is a real Article 28 agreement, not a compliance page: Annex 1 details of processing, Annex 2 technical and organisational measures, Annex 3 the live sub-processor list, with the online version declared authoritative.
Where the Exposure Actually Sits
Your message content and recipient data sit on Hetzner in Germany and Finland, and Hetzner is German. AlphaVPS is Bulgarian. So the default configuration keeps the email itself entirely inside EEA-owned infrastructure, which is rarer than it sounds in this category.
Two caveats, both stated by the vendor rather than found by us. First, the US providers are real but touch adjacent data: Stripe sees your billing details, PostHog sees product analytics, Cloudflare fronts the website. Second, AhaSend offers an optional US-based SMTP relay. If you choose it, your message data does go to Hetzner's US infrastructure, under Standard Contractual Clauses. That is a choice you make, not a default, and this listing rates the default.
ISO 27001 is listed as pending rather than held, which the site says itself.
Where It Fits
Compare with EmailLabs and MessageFlow in Poland, and with the transactional layer of Brevo and Mailjet. Among European senders, this is the one to point a developer at when the question is "where does the data actually go". See email deliverability.
Key Features
Pros & Cons
Categories
AhaSend GDPR & data protection: common questions
Is AhaSend GDPR compliant?
Yes. On the evidence we checked, AhaSend meets the requirements European businesses usually need. AhaSend is a European company headquartered in Netherlands, data is hosted within the European Union, and a Data Processing Agreement is published.
Where does AhaSend store data?
AhaSend states: ""Cloud Hosting & Infrastructure: Hetzner Online GmbH (Germany/Finland, and optionally USA if you chose to use our US-based SMTP relay) and DA International Group Ltd (operating as AlphaVPS, Bulgaria) to host our Services and associated data" (ahasend.com/privacy). The policy adds: "Our hosting providers, Hetzner Online GmbH (primary locations in Germany and Finland) and DA International Group Ltd (Bulgaria), are also based within the EEA. Data transfers to these providers are within the EEA and do not require the specific international transfer safeguards mentioned above for third countries." The pricing page describes "Multi-region EU infrastructure" on every plan including the free one. All read 2026-09-01.". Data is hosted within the European Union.
Does AhaSend offer a Data Processing Agreement (DPA)?
Yes. AhaSend publishes a DPA at https://ahasend.com/dpa. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.
What a DPA has to cover →Is AhaSend a European company?
Yes. AhaSend is headquartered in Netherlands and, as far as we can establish, European-owned.
Who are AhaSend's sub-processors?
AhaSend publishes its sub-processor list at https://ahasend.com/dpa. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.
Related Tools

Bouncer
Polish email verification and deliverability platform that cleans lists, blocks bad addresses at the signup form, and runs inbox placement tests, all on AWS Frankfurt.

EmailLabs
Polish SMTP and email API service focused on deliverability, from Vercom S.A., the group that also owns MessageFlow.

Re:Shark
Amsterdam outbound platform that automates the deliverability plumbing, configuring DNS, DMARC and DKIM, rotating domains and warming inboxes, on EU-only servers.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at AhaSend and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.