Back to Tools
AhaSend logo

AhaSend

GDPR Compliant

Dutch transactional email API and SMTP relay on Hetzner infrastructure in Germany and Finland, with a complete published DPA and every sub-processor named by country.

🇳🇱Netherlands🇪🇺EU Hosted🇪🇺 EuropeanFreemium
AhaSend website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountryNetherlands
OwnershipEuropean-owned
Foreign Disclosure ExposureNone known
Data Hosting Location
European Union"Cloud Hosting & Infrastructure: Hetzner Online GmbH (Germany/Finland, and optionally USA if you chose to use our US-based SMTP relay) and DA International Group Ltd (operating as AlphaVPS, Bulgaria) to host our Services and associated data" (ahasend.com/privacy). The policy adds: "Our hosting providers, Hetzner Online GmbH (primary locations in Germany and Finland) and DA International Group Ltd (Bulgaria), are also based within the EEA. Data transfers to these providers are within the EEA and do not require the specific international transfer safeguards mentioned above for third countries." The pricing page describes "Multi-region EU infrastructure" on every plan including the free one. All read 2026-09-01.
EU Servers Available
Data Processing AgreementView DPA
Sub-processor ListView sub-processors
Schrems II Risk
Low Risk
SCCs in Place
Last Verified1 September 2026

How we reached this

Dutch legal entity: AhaSend B.V., named as both controller and processor in the privacy policy read 2026-09-01. COMPLIANT on the strongest documentation in this tranche: a complete Article 28 DPA published at ahasend.com/dpa with Annex 1 (details of processing), Annex 2 (technical and organisational measures) and Annex 3 (sub-processor list, with the online version declared authoritative), plus a privacy policy that names every sub-processor with its country and its purpose. Exposure NONE, following the Statable precedent: message content and recipient data sit on Hetzner (German company, Germany and Finland) and AlphaVPS (Bulgarian), so no US provider holds the email itself in the default configuration. The named US providers touch adjacent data only, and the vendor says which: Stripe for payments, PostHog for analytics, Cloudflare for website security, all three under the EU-US Data Privacy Framework. Two caveats recorded rather than buried. First, AhaSend offers an OPTIONAL US-based SMTP relay; a customer who selects it has message data processed on Hetzner's US infrastructure under Standard Contractual Clauses, which the policy states plainly. This listing rates the default configuration. Second, the site describes ISO 27001 as pending rather than held. Retention is customer-configurable from zero days, and account data is erased within 14 days of a deletion request, with billing records kept seven years under Dutch tax law.

About AhaSend

Transactional Email With the Paperwork Actually Done

AhaSend is a developer-facing sending service, competing with the transactional side of the large platforms. What makes it worth a close look here is not the API, which is conventional and well documented. It is that the compliance documentation is the best of any tool in this tranche, by a distance.

The Product

  • REST API and SMTP relay with official SDKs, a CLI and sandbox mode
  • Dedicated IPs with automated warm-up, dedicated IP pools, and bring-your-own-IP at the top tier
  • Inbound email routing and signed webhooks, so replies and events come back into your own system
  • Platform Partner features: sub-accounts, DNS whitelabeling, per-domain DKIM selectors and bring-your-own-DKIM keys, which is what you need if you are reselling sending inside your own product
  • Reputation Shield and typosquatting protection
  • Configurable retention, from zero days upward, so you can choose not to have message bodies stored at all

Pricing starts at a genuine free tier of 1,000 emails a month with no card, on the same multi-region EU infrastructure as the paid plans. Pro covers 25,000 and Max 100,000, with flat-rate billing plus per-thousand overage, in USD or EUR. There are no long-term contracts.

Named Sub-processors, With Countries

Most vendors write "we use third-party providers". AhaSend writes this:

Cloud Hosting and Infrastructure: Hetzner Online GmbH (Germany/Finland, and optionally USA if you chose to use our US-based SMTP relay) and DA International Group Ltd (operating as AlphaVPS, Bulgaria) to host our Services and associated data.

Then it names the US ones separately and says exactly what each does: Stripe for payments, PostHog for analytics, Cloudflare for website security, all three relying on the EU-US Data Privacy Framework, and Trackdesk in Czechia for the affiliate programme. It commits to erasing personal data within 14 days of an account deletion request, and explains that billing records are kept seven years because Dutch tax law requires it.

The DPA at ahasend.com/dpa is a real Article 28 agreement, not a compliance page: Annex 1 details of processing, Annex 2 technical and organisational measures, Annex 3 the live sub-processor list, with the online version declared authoritative.

Where the Exposure Actually Sits

Your message content and recipient data sit on Hetzner in Germany and Finland, and Hetzner is German. AlphaVPS is Bulgarian. So the default configuration keeps the email itself entirely inside EEA-owned infrastructure, which is rarer than it sounds in this category.

Two caveats, both stated by the vendor rather than found by us. First, the US providers are real but touch adjacent data: Stripe sees your billing details, PostHog sees product analytics, Cloudflare fronts the website. Second, AhaSend offers an optional US-based SMTP relay. If you choose it, your message data does go to Hetzner's US infrastructure, under Standard Contractual Clauses. That is a choice you make, not a default, and this listing rates the default.

ISO 27001 is listed as pending rather than held, which the site says itself.

Where It Fits

Compare with EmailLabs and MessageFlow in Poland, and with the transactional layer of Brevo and Mailjet. Among European senders, this is the one to point a developer at when the question is "where does the data actually go". See email deliverability.

Key Features

REST API and SMTP relay with official SDKs, CLI and sandbox mode
Dedicated IPs with automated warm-up, plus dedicated IP pools and BYOIP
Inbound email routing with signed webhook endpoints
Sub-accounts, DNS whitelabeling and per-domain DKIM selectors for platform partners
Configurable message retention starting at zero days
Reputation Shield and typosquatting protection
SPF, DKIM and DMARC authentication with automatic DKIM key rotation
OIDC single sign-on, 2FA enforcement, scoped API keys and IP allow lists

Pros & Cons

Names every sub-processor with its country and purpose, which almost no vendor this size does
Complete Article 28 DPA published with all three annexes, including the live sub-processor list
Message data sits on Hetzner and AlphaVPS, both EEA companies, so no US provider holds the email
Genuine free tier of 1,000 emails a month on the same EU infrastructure as paid plans
Retention is configurable down to zero days, so you can choose not to store message bodies
The optional US-based SMTP relay moves message data to Hetzner US if you select it
Stripe, PostHog and Cloudflare are US providers, though they touch billing, analytics and the website rather than email
ISO 27001 is described as pending, not held
Transactional sending only: no campaign builder, segmentation or automation
Smaller company than the incumbents, which larger buyers will treat as a resilience question

AhaSend GDPR & data protection: common questions

Is AhaSend GDPR compliant?

Yes. On the evidence we checked, AhaSend meets the requirements European businesses usually need. AhaSend is a European company headquartered in Netherlands, data is hosted within the European Union, and a Data Processing Agreement is published.

Where does AhaSend store data?

AhaSend states: ""Cloud Hosting & Infrastructure: Hetzner Online GmbH (Germany/Finland, and optionally USA if you chose to use our US-based SMTP relay) and DA International Group Ltd (operating as AlphaVPS, Bulgaria) to host our Services and associated data" (ahasend.com/privacy). The policy adds: "Our hosting providers, Hetzner Online GmbH (primary locations in Germany and Finland) and DA International Group Ltd (Bulgaria), are also based within the EEA. Data transfers to these providers are within the EEA and do not require the specific international transfer safeguards mentioned above for third countries." The pricing page describes "Multi-region EU infrastructure" on every plan including the free one. All read 2026-09-01.". Data is hosted within the European Union.

Does AhaSend offer a Data Processing Agreement (DPA)?

Yes. AhaSend publishes a DPA at https://ahasend.com/dpa. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.

What a DPA has to cover →

Is AhaSend a European company?

Yes. AhaSend is headquartered in Netherlands and, as far as we can establish, European-owned.

Who are AhaSend's sub-processors?

AhaSend publishes its sub-processor list at https://ahasend.com/dpa. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at AhaSend and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.