NotifySetu Logo
NotifySetu
FeaturesPricingIntegrationsDocsBlogCustomersSecurity
Sign InStart Free
NotifySetu Logo
NotifySetu

Unified notification API platform for developers. Orchestrate Email, SMS, WhatsApp, Push, Voice & OTP across 15+ global providers.

All Systems Operational

Channels

  • Transactional Email
  • SMS Infrastructure
  • WhatsApp Cloud API
  • Web & Mobile Push
  • Voice & IVR
  • OTP Engine

Product

  • Platform Features
  • Tiered Pricing
  • Provider Integrations
  • Developer Console
  • System Status

Resources

  • Documentation
  • Quickstart Guide
  • API Reference
  • SDK Client Libraries
  • Engineering Blog
  • RSS Feed

Company

  • Customer Stories
  • Security & Trust
  • Contact Sales
  • Responsible Disclosure

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • GDPR Compliance
  • Cookie Policy
  • DPA Agreement

© 2026 NotifySetu. Owned and operated by INFOSKILLS TECHNOLOGY PVT LTD. All rights reserved.

Terms of Service•Privacy Policy•Refund Policy•GDPR•Cookies•DPA•Contact Us
Back to Home

GDPR & Data Protection Compliance

Last Updated: September 16, 2026 | Legal Entity: INFOSKILLS TECHNOLOGY PVT LTD

GDPR Commitment: NotifySetu is fully committed to compliance with the European Union General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and the UK GDPR. We provide robust data protection mechanisms, encrypted infrastructure, Standard Contractual Clauses (SCCs), and a formal Data Processing Addendum (DPA).

1. Controller vs. Processor Relationship

Under the GDPR framework:

  • You (The Customer): Act as the Data Controller with respect to end-recipient personal data (such as recipient email addresses, phone numbers, and notification content) that you transmit through the NotifySetu API. You determine the purposes and lawful basis for communicating with your recipients.
  • NotifySetu (INFOSKILLS TECHNOLOGY PVT LTD): Acts as a Data Processor. We process message payloads and recipient identifiers strictly on your documented instructions to execute notification delivery, automated channel failover, and analytics callbacks.

2. Lawful Basis & Purpose of Processing

We process personal data only where we have a lawful basis under GDPR Article 6:

  • Performance of Contract: To dispatch, deliver, and track notifications across configured channels (Email, WhatsApp, SMS, Push, Voice).
  • Legitimate Interests: To detect abuse, secure developer API tokens, mitigate phishing or spam threats, and optimize routing reliability.
  • Legal Obligations: For tax reporting, billing records with our Merchant of Record (Paddle), and statutory compliance.

3. Authorised Sub-processors & Cross-Border Transfers

To provide scalable, global notification delivery, we engage verified third-party sub-processors. All transfers of personal data outside the European Economic Area (EEA) or UK are governed by European Commission approved Standard Contractual Clauses (SCCs) and rigorous data processing agreements:

Sub-processorRole / ServiceTransfer Safeguard
Meta Platforms Ireland Ltd / Meta Inc.WhatsApp Business Cloud API message transmissionEU-US Data Privacy Framework / SCCs
Amazon Web Services (AWS)Cloud hosting, database persistence, and AWS SES email deliveryAWS GDPR DPA & SCCs
Twilio Inc.Global SMS, Voice, and OTP delivery channelsTwilio Binding Corporate Rules (BCR) & SCCs
Paddle.com Market LtdMerchant of Record, checkout, invoicing, and VAT complianceUK GDPR & EU Adequacy / SCCs

4. Technical & Organisational Measures (TOMs)

We implement state-of-the-art security controls in compliance with GDPR Article 32:

  • Encryption: AES-256 GCM encryption at rest for database records and API keys; TLS 1.3 encryption for all data in transit.
  • Access Control: Least-privilege role-based access control (RBAC), multi-factor authentication for internal systems, and automated key rotation.
  • Data Minimization: Transient notification logs are automatically scrubbed or aggregated after retention limits expire.

5. Data Subject Rights (DSR) Assistance

Under GDPR Articles 15–22, data subjects possess rights including access, rectification, erasure (“Right to be Forgotten”), restriction, data portability, and objection.

Because NotifySetu processes recipient data exclusively on behalf of our Customers, end users seeking to exercise their rights should contact the relevant customer directly. As a processor, NotifySetu provides API mechanisms and administrative support to help Customers fulfill verified DSR requests within 30 days.

6. Data Breach Notification Policy

In the event of a confirmed personal data breach affecting data processed by NotifySetu, we will notify affected Customers without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.

7. Data Protection Officer & Contact

For GDPR data subject requests, DPA execution inquiries, or privacy questions, contact our compliance office:

Legal Entity: INFOSKILLS TECHNOLOGY PVT LTD

Trading Name: NotifySetu

Privacy & Legal Support: support@notifysetu.com | contact@notifysetu.com

Billing Support: billing@notifysetu.com

Phone / WhatsApp: +91-9810659036 | +91-9910525949

Official Website: https://notifysetu.com

Data Processing Addendum: Review our standard Data Processing Addendum (DPA)