
SendPulse
Partially CompliantMultichannel marketing platform covering email, SMS, chatbots, CRM and courses, operated by SendPulse Inc. of New York despite its Ukrainian engineering roots.
Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.
Freemium
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | United States |
| Ownership | Non-European |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | Unknown |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | High Risk |
| SCCs in Place | |
| Last Verified | 1 September 2026 |
How we reached this
Listed as United States, not Ukraine. The source map places SendPulse under Ukraine and its engineering heritage is genuinely Ukrainian, but the privacy policy read 2026-09-01 is unambiguous about the entity: "When we say 'we,' 'us', 'our,' and 'SendPulse,' we are referring to SendPulse Inc., 220 E 23rd St #401, New York, NY 10010." A New York corporation, so ownershipOrigin NON_EU and exposure US_CLOUD_ACT. Credit where due: the policy commits to GDPR rights in specific terms, including access under Article 15 within 30 days and correction, amendment or deletion on request, and it extends those rights explicitly to the customer's subscribers rather than only to the account holder, which many vendors do not. What is absent is everything this directory rates hosting on: no server location is stated anywhere in the privacy policy or on the security page, which describes redundancy and daily backups without a geography; no sub-processor list; no DPA at a public URL. Hence hosting UNKNOWN and Schrems II risk HIGH. The policy also covers Google API and Gmail data under Google's Limited Use requirements, indicating the product reaches into connected mailboxes.
About SendPulse
Very Broad, at a Low Price
SendPulse covers more ground than almost anything else in this directory, and does it cheaply. Email marketing and SMTP, SMS, web push, a chatbot builder spanning Telegram, WhatsApp, Instagram and Facebook Messenger, a free CRM, landing pages, and a platform for selling online courses.
For a solo founder or a small team that would otherwise be paying for four tools, the breadth is the entire argument, and it is a good one. The trade-off is the usual one: none of the individual modules is as deep as a specialist, and the CRM in particular is basic next to Pipedrive or Teamleader.
On the Country
The source map lists SendPulse under Ukraine. The engineering heritage is genuinely Ukrainian and the company is well known there.
The operating entity is not. From sendpulse.com/legal/pp:
When we say "we," "us", "our," and "SendPulse," we are referring to SendPulse Inc., 220 E 23rd St #401, New York, NY 10010.
A New York corporation. So this directory lists SendPulse as United States. That is not a judgement about the product or the people who build it, and this site lists non-European software all the time. It is simply what the privacy policy says the entity is, and it decides who can be compelled to hand over your subscriber list.
What the Documents Do and Do Not Say
The privacy policy commits to GDPR rights in specific terms: access under Article 15 within 30 days, correction, amendment and deletion on request from you or from any of your subscribers, at no charge, unless prohibited by law. Extending those rights explicitly to your subscribers rather than only to the account holder is better than a lot of vendors manage.
What it does not contain is a hosting region. There is no statement of where servers are, no sub-processor list, and no DPA at a public URL. The security page describes redundancy and daily backups without saying where any of it sits. The policy also covers Google API and Gmail data handling under Google's Limited Use requirements, which tells you the product reaches into connected mailboxes.
Combined with US incorporation, that puts this row at PARTIAL with hosting UNKNOWN and US CLOUD Act exposure.
Where It Fits
If breadth at a low price is what you need and jurisdiction is not the binding constraint, SendPulse is hard to beat on value. If you want the same shape from an EU-registered company, Yespo is the closest comparison and names its hosting down to the city, and Brevo covers email, SMS and CRM from France. See email marketing.
Key Features
Pros & Cons
Categories
SendPulse GDPR & data protection: common questions
Is SendPulse GDPR compliant?
Partly. SendPulse meets some of the requirements, with caveats worth reading before you commit. SendPulse is based in United States, outside the EU/EEA.
Where does SendPulse store data?
We could not locate a clear statement of where SendPulse hosts data. Ask the vendor directly, or check their privacy policy and sub-processor list before signing.
Does SendPulse offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for SendPulse. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover βIs SendPulse a European company?
No. SendPulse is based in United States, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.
Is SendPulse subject to the US CLOUD Act?
Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.
Schrems II compliance checklist βRelated Tools

Brevo
All-in-one marketing platform with email, SMS, CRM, and automation. French company, EU data hosting.

MailerLite
Email marketing and automation platform from Lithuania. EU data processing.

rapidmail
German email marketing with data exclusively hosted in Germany.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at SendPulse and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.