Inno Message is EU GDPR compliant
Inno Message is designed and operated in compliance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) — so you can run customer conversations with EU residents with confidence.
GDPR principles, built into the product
How the core principles of data protection map to the way Inno Message works.
Lawfulness & transparency
Personal data is processed on a lawful basis, and our Privacy Policy explains clearly what we collect and why.
Purpose limitation
Conversation data is processed only to deliver the Services you configure — never for unrelated purposes.
Data minimisation
We collect only what the platform needs to route, store, and resolve your conversations.
Storage limitation
Retention controls let you decide how long conversations and contacts are kept, with deletion on request.
Integrity & confidentiality
Encryption in transit and at rest, role-based access, and audit logging protect data against misuse.
Accountability
Documented processing records, a signed DPA, and a vetted sub-processor list demonstrate compliance.
Answer every rights request from one place
As the controller of your customers' data, you respond to their GDPR requests. Inno Message gives you the tools to do it quickly — in the app or through the API.
- Right of access (Art. 15)
- Search and export a contact's full conversation history from the inbox or via the API.
- Right to rectification (Art. 16)
- Edit contact profiles and attributes directly in the app or through the API.
- Right to erasure (Art. 17)
- Delete an individual contact and their conversations, or remove data in bulk.
- Right to restriction (Art. 18)
- Block or pause processing for a contact while a request is being resolved.
- Right to data portability (Art. 20)
- Export data in structured, machine-readable formats (JSON / CSV).
- Right to object (Art. 21)
- Honour opt-outs and unsubscribes across channels with channel-level consent controls.
- Automated decisions (Art. 22)
- AI agents can hand off to a human at any point, and human-in-the-loop review is configurable.
Article 28, in writing
Our Data Processing Agreement sets out what we commit to when we process personal data on your behalf.
- Process personal data only on your documented instructions
- Personnel bound by confidentiality obligations
- Technical and organisational security measures under Article 32
- Sub-processors engaged under written terms, with advance notice of changes
- Assistance with data subject requests and impact assessments (DPIAs)
- Personal data breach notification without undue delay
- Deletion or return of personal data when the service ends
- Information and audit support to demonstrate compliance
International transfers
Inno Message is operated from Singapore. Transfers of personal data out of the EEA are covered by the European Commission's Standard Contractual Clauses, supported by encryption in transit and at rest.
Security of processing (Art. 32)
TLS 1.2+ in transit, AES-256 at rest, role-based least-privilege access, audit logs, encrypted backups, and continuous monitoring.
Security overviewBreach notification
A documented incident response process. If a breach affects your data, we notify you without undue delay so you can meet your 72-hour obligation to regulators.
Sub-processors
We use a small set of vetted providers under written data protection terms, and give advance notice of changes.
View sub-processorsPrivacy by design (Art. 25)
Data protection is part of how features are designed and reviewed — with privacy-protective defaults and minimal data collection.
Records & accountability
We maintain records of processing activities (Art. 30) and supporting documentation for your due-diligence and vendor reviews.
Read the Privacy PolicyGDPR questions, answered
Is Inno Message GDPR compliant?
Do you sign a Data Processing Agreement (DPA)?
How are transfers of personal data outside the EU handled?
Can we delete or export our customers' data?
How do you handle a personal data breach?
Is there an official GDPR certificate?
Privacy and data protection requests: hello@innomessage.com

