Legal
Privacy Policy
Last updated 21 Jul 2026
This policy explains how SMSJet processes the personal data of its customers and of message recipients, in accordance with Regulation (EU) 2016/679 (GDPR).
Who we are
SMSJet is a message-sending service for business customers — companies and professionals who integrate messaging into their own systems and workflows — across two channels: SMS and WhatsApp. The data controller can be reached at [email protected] for any request concerning personal data.
Data we process
- Customer account data: name, email address and preferred language.
- Billing records: issued invoices and EUR balance movements.
- Message data: recipient phone number, message text (stored encrypted at rest), sender, number of parts and applied price.
- For WhatsApp messages: the name and language of the template used, the text resulting from substituting its variables (stored encrypted at rest), the recipient’s WhatsApp number and the message identifier assigned by Meta.
- Send outcomes recorded at send time (accepted, rejected, failed) and, for WhatsApp, the later status updates Meta reports (sent, delivered, read, failed).
- Technical logs related to API and dashboard usage.
Purposes and legal bases
We process data only for specific purposes, each resting on a legal basis provided by the GDPR.
- Providing the SMS- and WhatsApp-sending service: performance of the contract.
- Billing and accounting: compliance with legal obligations.
- Abuse prevention and platform security: legitimate interest of the controller.
Sub-processors
Messages are delivered through SMS connectivity providers, which receive only the data strictly needed for delivery: the recipient number, the sender and the message text. The platform is hosted on infrastructure providers that process data on our behalf under agreements compliant with Art. 28 GDPR.
On the WhatsApp channel, messages travel through Meta’s WhatsApp Business Platform. The WhatsApp Business Account and the sending number belong to the customer, not to us: we act as a technology provider sending on their behalf through our own Meta application, and the customer remains party to the relationship with Meta and the recipient of its billing. Meta’s platform reports back the delivery status of the messages we send on the customer’s behalf. We do not read, analyse or repurpose message content: we process it solely to deliver it and to show it to the customer in their own log.
The up-to-date list of sub-processors is available on request by writing to [email protected].
Retention
Account data and billing records are kept for the life of the account and, after it is closed, for the retention periods required by tax and civil law.
The message log is kept for the time needed to provide billing transparency and send-outcome reporting, after which it is deleted or anonymised.
Your rights
As a data subject you may exercise at any time the rights set out in Arts. 15–22 GDPR: access, rectification, erasure, restriction of processing, data portability and objection. To do so, simply write to the contact address given in this policy.
You also retain the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali.
Contact
For any question about this policy or about how your data is handled, write to us at [email protected]. We answer requests concerning personal data without undue delay and in any case within the time limits set by the GDPR.
