GDPR

We are fully GDPR compliant

How SESMetric meets the General Data Protection Regulation requirements, the lawful bases we rely on, our subprocessors, and how to exercise your rights.

Last updated · 2026-05-26

1. Lawful basis for processing

We rely on the following GDPR Article 6 lawful bases:

  • Art. 6(1)(b) — performance of a contract: operating your account, delivering mail you send, billing you.
  • Art. 6(1)(f) — legitimate interest: fraud detection, abuse prevention, deliverability protection.
  • Art. 6(1)(c) — legal obligation: tax records, lawful requests from authorities.
  • Art. 6(1)(a) — consent: analytics cookies (denied by default under Consent Mode v2).

2. Your rights

Under GDPR you have the following rights. To exercise any of them go to /dashboard/settings or email privacy@finketech.com. We respond within 30 days.

Right to access

Request a copy of the personal data we hold about you.

Right to rectification

Correct any inaccurate or incomplete data.

Right to erasure

Delete your account and the personal data tied to it.

Right to restriction

Limit how we process your data while a dispute is resolved.

Right to portability

Export your data in a structured, machine-readable format.

Right to object

Object to processing based on legitimate interest.

Withdraw consent

Where processing relies on consent, you can withdraw it any time.

Lodge a complaint

File with your local supervisory authority if we fall short.

3. Data controller & DPO

The data controller is Finke Technologies, Inc. (the operator of SESMetric). Email the Data Protection contact at privacy@finketech.com for GDPR-related inquiries.

4. Subprocessors

We share data only with the subprocessors listed below, each bound by a written data-processing agreement. International transfers rely on Standard Contractual Clauses where applicable.

ProviderRoleRegion
Amazon Web ServicesApplication hosting + databaseUS
PolarSubscription billingUS / EU
PostmarkOutbound system mailUS
VercelStatic site + edge runtimeUS / EU
Google Analytics 4Aggregated traffic measurementUS

5. Data export & deletion

Export your account data and event logs from /dashboard/settings. Account deletion is self-service. After you delete an account, data is hard-deleted within 30 days and rotated out of backups within 90 days.

Manage my data

6. International transfers

Most of our infrastructure is hosted in the United States. Where data leaves the EEA we rely on Standard Contractual Clauses with each receiving subprocessor and apply supplementary measures (TLS in transit, encryption at rest, access controls).

7. Breach notification

We notify affected customers within 72 hours of becoming aware of a personal-data breach likely to result in a risk to their rights and freedoms, in line with Article 33. Updates land in your account inbox and on sesmetric.com/status.

SESMetric is a product of Finke Technologies, Inc.