Yespo
Partially CompliantOmnichannel CDP and marketing automation platform, formerly eSputnik, Ukrainian-built and now registered in Warsaw, hosted on AWS in Dublin with no cross-border transfer for EU users.
Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.
Freemium
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | Poland |
| Ownership | European-owned |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | European Union"All personal data is hosted within the European Union, Ireland, Dublin on the servers of Amazon Web Services Inc. There is no cross-border data transfer in accordance with GDPR for the EU users" (yespo.io/privacy-policy, read 2026-09-01). Country, city and provider all named. |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | Low Risk |
| SCCs in Place | |
| Last Verified | 1 September 2026 |
How we reached this
Formerly eSputnik; esputnik.com now redirects to yespo.io. The source map listed it under Ukraine, and both the name and the registration have moved on. The privacy policy read 2026-09-01 names the operating entity as "Retention Yes, a limited liabilities company, REGON 9512528950, whose registered office is located in Poland, WARSZAWA, ADAMA BRANICKIEGO 21", so hqCountry is Poland and ownership EU_OWNED on that registration. The Ukrainian origin and engineering heritage are real and are recorded in the listing text rather than in the country field, because registration is what determines the supervisory authority. (Note the identifier is published as REGON but is formatted as a ten-digit NIP; quoted here as published.) Hosting is unusually precise for this directory: European Union, Ireland, Dublin, on Amazon Web Services, with the vendor stating there is no cross-border transfer for EU users. Schrems II risk LOW follows from no transfer occurring. Exposure is US_CLOUD_ACT because the named provider is Amazon Web Services Inc., a US company, so the CLOUD Act reaches the party physically holding the data even though the data stays in Dublin. Same shape as Bouncer and theMarketer. PARTIAL because no sub-processor list and no DPA were located at a public URL.
About Yespo
The Broadest Channel Coverage on This Site
Yespo does more channels than anything else in this directory. Email, SMS, web push, mobile push, in-app messaging, Viber and Telegram, all orchestrated from one customer profile with a CDP underneath and AI-driven product recommendations on top.
Viber and Telegram matter more than a Western European reader might assume. In Ukraine, Poland and much of Central and Eastern Europe, they are primary messaging channels rather than curiosities, and almost no Western platform supports them. If you market into those countries, this is close to a category of one.
The Name and the Country Have Both Changed
The tool appeared on the source map as eSputnik, filed under Ukraine. Both parts of that are now out of date.
eSputnik rebranded to Yespo, and esputnik.com redirects to yespo.io. The privacy policy names the operating entity as Retention Yes, a limited liabilities company, REGON 9512528950, registered office in Poland, Warszawa, Adama Branickiego 21.
So the product is Ukrainian in origin and engineering heritage, and Polish by registration today. This directory records the second, because that is what the documents say and it is what determines which supervisory authority you deal with. The Ukrainian heritage is worth knowing, not worth hiding, and it explains the channel mix.
The Hosting Statement Is Unusually Precise
All personal data is hosted within the European Union, Ireland, Dublin on the servers of Amazon Web Services Inc. There is no cross-border data transfer in accordance with GDPR for the EU users.
Country, city and provider, all named. That is more precision than the large majority of tools on this site offer, including many that are more obviously European.
The trade-off is in the same sentence: the provider is Amazon Web Services Inc., an American company. Your data does not leave Dublin, and the vendor is correct that there is no cross-border transfer. But the CLOUD Act reaches the entity holding it, so this row carries US CLOUD Act exposure for the same reason Bouncer and theMarketer do. It is the most common shape of this trade in the whole directory: EU location, US provider.
No sub-processor list and no DPA were located at a public URL, which is why the row reads PARTIAL rather than better.
Where It Fits
Against Ecomail and theMarketer for regional e-commerce automation, and Omnisend for omnichannel. Nothing else here does Viber and Telegram. See marketing automation.
Key Features
Pros & Cons
Yespo GDPR & data protection: common questions
Is Yespo GDPR compliant?
Partly. Yespo meets some of the requirements, with caveats worth reading before you commit. Yespo is a European company headquartered in Poland, data is hosted within the European Union.
Where does Yespo store data?
Yespo states: ""All personal data is hosted within the European Union, Ireland, Dublin on the servers of Amazon Web Services Inc. There is no cross-border data transfer in accordance with GDPR for the EU users" (yespo.io/privacy-policy, read 2026-09-01). Country, city and provider all named.". Data is hosted within the European Union.
Does Yespo offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for Yespo. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover →Is Yespo a European company?
Yes. Yespo is headquartered in Poland and, as far as we can establish, European-owned.
Is Yespo subject to the US CLOUD Act?
Indirectly. Yespo itself is European-owned and headquartered in Poland, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is.
Schrems II compliance checklist →Related Tools

Brevo
All-in-one marketing platform with email, SMS, CRM, and automation. French company, EU data hosting.

MailerLite
Email marketing and automation platform from Lithuania. EU data processing.

rapidmail
German email marketing with data exclusively hosted in Germany.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at Yespo and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.