EU data protection

Inno Message is EU GDPR compliant

Inno Message is designed and operated in compliance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) — so you can run customer conversations with EU residents with confidence.

EU GDPR compliant Data Processing Agreement Standard Contractual Clauses Data subject rights tooling
GDPR at a glance. Inno Message acts as a data processor for the conversation and contact data you handle through the platform, and as a data controller for your account and billing data. We process customer data only on your instructions, secure it with encryption and access controls, support every data subject right, cover international transfers with Standard Contractual Clauses, and commit to all of this in a Data Processing Agreement.
Article 5 principles

GDPR principles, built into the product

How the core principles of data protection map to the way Inno Message works.

Lawfulness & transparency

Personal data is processed on a lawful basis, and our Privacy Policy explains clearly what we collect and why.

Purpose limitation

Conversation data is processed only to deliver the Services you configure — never for unrelated purposes.

Data minimisation

We collect only what the platform needs to route, store, and resolve your conversations.

Storage limitation

Retention controls let you decide how long conversations and contacts are kept, with deletion on request.

Integrity & confidentiality

Encryption in transit and at rest, role-based access, and audit logging protect data against misuse.

Accountability

Documented processing records, a signed DPA, and a vetted sub-processor list demonstrate compliance.

Data subject rights

Answer every rights request from one place

As the controller of your customers' data, you respond to their GDPR requests. Inno Message gives you the tools to do it quickly — in the app or through the API.

Right of access (Art. 15)
Search and export a contact's full conversation history from the inbox or via the API.
Right to rectification (Art. 16)
Edit contact profiles and attributes directly in the app or through the API.
Right to erasure (Art. 17)
Delete an individual contact and their conversations, or remove data in bulk.
Right to restriction (Art. 18)
Block or pause processing for a contact while a request is being resolved.
Right to data portability (Art. 20)
Export data in structured, machine-readable formats (JSON / CSV).
Right to object (Art. 21)
Honour opt-outs and unsubscribes across channels with channel-level consent controls.
Automated decisions (Art. 22)
AI agents can hand off to a human at any point, and human-in-the-loop review is configurable.
Our processor commitments

Article 28, in writing

Our Data Processing Agreement sets out what we commit to when we process personal data on your behalf.

  • Process personal data only on your documented instructions
  • Personnel bound by confidentiality obligations
  • Technical and organisational security measures under Article 32
  • Sub-processors engaged under written terms, with advance notice of changes
  • Assistance with data subject requests and impact assessments (DPIAs)
  • Personal data breach notification without undue delay
  • Deletion or return of personal data when the service ends
  • Information and audit support to demonstrate compliance
Request our DPA

International transfers

Inno Message is operated from Singapore. Transfers of personal data out of the EEA are covered by the European Commission's Standard Contractual Clauses, supported by encryption in transit and at rest.

Security of processing (Art. 32)

TLS 1.2+ in transit, AES-256 at rest, role-based least-privilege access, audit logs, encrypted backups, and continuous monitoring.

Security overview

Breach notification

A documented incident response process. If a breach affects your data, we notify you without undue delay so you can meet your 72-hour obligation to regulators.

Sub-processors

We use a small set of vetted providers under written data protection terms, and give advance notice of changes.

View sub-processors

Privacy by design (Art. 25)

Data protection is part of how features are designed and reviewed — with privacy-protective defaults and minimal data collection.

Records & accountability

We maintain records of processing activities (Art. 30) and supporting documentation for your due-diligence and vendor reviews.

Read the Privacy Policy
GDPR FAQ

GDPR questions, answered

Is Inno Message GDPR compliant?
Yes. Inno Message is designed and operated in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679). We act as a data processor for the conversation data you handle through the platform and as a controller for account data, and we back our processor obligations with a Data Processing Agreement.
Do you sign a Data Processing Agreement (DPA)?
Yes. Every customer can execute our Data Processing Agreement, which covers the requirements of GDPR Article 28 — processing only on your documented instructions, confidentiality, security measures, sub-processor controls, breach notification, audit support, and deletion or return of data at the end of the service.
How are transfers of personal data outside the EU handled?
Inno Message is operated by Innovate Solution Global Pte. LTD., headquartered in Singapore. Where personal data from the EEA is transferred outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses together with supplementary measures such as encryption in transit and at rest.
Can we delete or export our customers' data?
Yes. You can export conversation and contact data and delete individual contacts or entire conversation histories, which lets you respond to access, portability, and erasure requests from your own customers. Retention controls let you limit how long data is kept.
How do you handle a personal data breach?
We maintain a documented incident response process. If a personal data breach affects your data, we notify you without undue delay and provide the information you need to meet your own notification obligations to supervisory authorities and data subjects.
Is there an official GDPR certificate?
No widely adopted official GDPR certification exists for SaaS providers. GDPR compliance is demonstrated through contractual commitments (the DPA), records of processing, technical and organisational security measures, and the ability to support data subject rights — all of which we provide.

Privacy and data protection requests: hello@innomessage.com

Need a DPA or a GDPR questionnaire answered?