Privacy Policy
This Privacy Policy explains how Sendigram Pty Ltd. ("Sendigram", "We", or "Us") collects, uses, and processes information about individuals ("You") when You interact with our Services.
1. Definitions
"Account" means the unique user account created by or on behalf of a Customer to access and use the Services.
"Application" means the Sendigram software platform, including any optional specific apps or features provided therein.
"CCPA" means the California Consumer Privacy Act of 2018, as amended (including by the California Privacy Rights Act), and any implementing regulations.
"Contact" means any individual (Data Subject) whose Personal Data is uploaded, stored, or Processed by a Customer within the Services (e.g., an email recipient or newsletter subscriber).
"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
"Customer" means the individual or legal entity that has registered for an Account and uses the Services to communicate with Contacts.
"Data Processing Agreement" (or "DPA") means the legally binding data processing agreement between Sendigram and the Customer governing the Processing of Personal Data on behalf of the Customer.
"Data Subject" means an identified or identifiable natural person.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data.
"Personal Data" (or "Personal Information") means any information relating to an identified or identifiable natural person (Data Subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. Personal Data falls into various categories, such as identifiers, sensitive personal information (e.g., contents of messages when We are not the recipient, race, health data, union membership, or, in some cases, information about a known child), legally protected information (e.g., citizenship, marital status, sex), biometrics, commercial history, employment-related data, nonpublic educational information, internet activity, or inferences drawn to create a consumer profile. This term expressly includes "Personal Information" as defined under the CCPA and other applicable privacy laws.
"Privacy Policy" (or "Policy") means this privacy policy document.
"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction. The terms "Process", "Processes", and "Processed" will be construed accordingly.
"Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Controller.
"Services" means the Site, the Application, and any other products or services provided by Sendigram.
"Site" means the Sendigram website(s) and associated web domains.
"Terms" means the Sendigram Terms of Service governing the use of the Services.
2. Scope of this Policy
If You are a Contact, please note that Sendigram is acting as a Controller only for the specific purposes described in Section 4 and Section 5 of this Policy. For all other Processing that involves your Personal Data (storage of content, sending of emails, creation of statistics on behalf of Customers, etc.), Sendigram does not act as a Controller, meaning that it has no influence and does not decide on such Processing of your Personal Data (please be reminded in this regard that Sendigram does not send electronic communications on its own behalf but only on behalf and under the instructions of its Customers, except where detailed in Section 3), and, therefore, this Policy may not apply. Sendigram will act for this other Processing as a Processor, and our Customers are acting as Controllers and are the sole entities that can ensure the proper exercise of your rights described in Section 13 of this Policy (deletion, access, limitation, etc.). To learn more about how our Customers Process your Personal Data as Controllers and how You can exercise your rights with them, please see their own privacy policies. If You want to know about how We Process Personal Data as a Processor, please refer to our Data Processing Agreement.
Sendigram offers optional specific apps/features through its Application, the list of which can be found in our Data Processing Agreement. These apps/features are provided by third-party providers that Sendigram does not control and for which it does not provide any specific warranty. Therefore, for Processing carried out for the provision and in the context of such apps/features, Sendigram is not liable, and the third-party providers act in accordance with the qualifications that their policies/terms and conditions provide. If You wish to use those features, We strongly recommend that You read the relevant privacy policy of each third-party provider to know more about the Processing of your Personal Data.
3. Sites and products covered by this Privacy Policy
This Privacy Policy applies to Sendigram Pty Ltd, our Site, and all of our Services. Our Site and Services may provide links to third-party websites and products. If You access those links or install and use those products, that interaction will not be covered by this Privacy Policy, as We have no control over third-party websites, products, or their policies. We specifically disclaim any and all liability, in contract or in tort, arising from your use of any link to any third-party website or your use of any third-party product.
The Personal Data You provide to third parties is not covered by this Privacy Policy. We encourage You to review the privacy policy of any company before submitting your Personal Data. Some third-party companies may choose to share Personal Data with Us; such sharing is governed by that third-party company's privacy policy.
By using our Site or Services, You acknowledge that You have read this Privacy Policy. Where consent is required by applicable law, We will request your consent separately. If You do not agree to the provisions of this Privacy Policy, You must not access or use our Site or Services or communicate with Us using your Personal Data.
4. Types of information We collect
This Privacy Policy covers Personal Data, non-personal data collection, and aggregate reporting.
Personal Data is information that is associated with your name or personal identity. We use Personal Data to deliver our Services and provide You with a better experience. Once You choose to provide Us with Personal Data, You can be assured that it will be used only to support your customer relationship with Us. We take the trust You place in Us seriously. We will not sell, rent, or lease your Personal Data to others.
Non-personal data is information about usage and service operation that is not associated with a specific personal identity. We collect and analyze non-personal data to evaluate how visitors use our Site or how users interact with our Services. Non-personal data We collect may include unique URLs visited within our domains, browser type and version, geographic location, IP address, time zone setting, operating system and platform, device type and device identifiers, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), your engagement with certain variable/dynamic elements of a page, and methods used to browse away from the page. Most non-personal data is collected via cookies or other analysis technologies. Our Site uses cookies and other technologies for data analysis and personalization. This non-personal data is required for Us to be able to provide our Services to You. If You decline to let Us collect this information, such as by disabling cookies, We may not be able to provide our Services to You.
You are responsible for any third-party Personal Data obtained, published, or shared through our Site or Services, and You confirm that You have the third party's consent to provide such data to Us.
5. How and when We collect your information
We store information sent by your web browser while visiting our Site or using our Application.
When You send Us requests for technical support or other messages, We save your email address, name, and message content for further correspondence related to your inquiry.
Your name, email address, and company name will be required to create an Account, which We will use to deliver our Services. When registering your Account, We also collect your physical address solely to prevent fraud and abuse, namely to reduce the number of cases of Accounts being created by scammers, fake users, multi-accounting, and other forms of abuse.
We may collect certain other information about You in connection with your registration for an Account with Us, which may include Personal Data such as a username and password.
When You purchase our Services, You provide your personal contact, billing, and shipping information to our payment processing partner, who retains the information needed for billing and shipping purposes and information on your product licenses.
The full list of the subprocessors can be found in our Data Processing Agreement.
We will take reasonable steps to destroy or de-identify Personal Data when it is no longer needed for any purpose allowed under the Australian Privacy Principles, unless otherwise required by law.
6. Cookies and other tracking tools
We may use cookies, tracking pixels, or other technologies to track usage and to support the operation of our Site and Services so You can have a better experience with Us.
Web browser cookies. Cookies are small files that are saved on your computer's hard drive when You visit websites. They communicate with servers, which may include our servers or servers of third-party companies authorized to collect data for Us, and allow your device to be recognized. You may set your web browser to decline some cookies or to notify You when cookies are being saved on your device. However, if You disable or decline all browser cookies, it may become impossible for You to use portions or certain features of our Site or Services.
Tracking pixels. Sendigram may use small electronic files known as tracking pixels that allow Us to count webpage visitors or users who opened an email and for other statistical purposes. Such files help Us learn of your interest in our Services or content and permit Us to collect information about your browsing and purchasing behavior.
Analytics tools. We use web analytics services, including, but not limited to, Google Analytics. Those services, in turn, may use cookies and other tracking technologies to track how visitors use our Site. The information web analytics services generate about Site usage is transmitted to those services and used to analyze visitors' use of the Site, produce statistical reports on Site activity, and provide other services related to the Site or internet use. Such services may also collect information about domain visitors' use of other websites.
The following are examples of services (subprocessors) We use for the purposes of improving the quality of the Services, fighting against scams, and protecting Personal Data:
- Google Analytics (Google LLC)
- Google Ads conversion tracking (Google LLC)
- Google Tag Manager (Google LLC)
- Remarketing with Google Analytics (Google LLC)
- Google reCAPTCHA
- Hotjar (Hotjar Ltd.), etc.
Detailed information about cookies used, categories of cookies, third-party providers, purposes, retention periods, and managing cookie preferences is available in our separate Cookie Policy.
Where required by applicable law, We request consent before using non-essential cookies or similar technologies.
7. How We use your information
We use the Personal Data and non-personal data collected about You for the following purposes:
To provide and improve our Services. This includes managing Account access, troubleshooting, protecting security, developing and introducing new features, services, or products, providing customer support, etc.
To comply with legal requirements. Your information may be used to comply with various regulations, laws, and requests from law enforcement or governmental entities; to enforce our rights or carry out obligations arising from agreements or contracts, etc.
To personalize content. This includes tailoring the information We show to You, including advertising, marketing, and promotional content.
To protect interests and rights. This includes protecting our property, rights, or safety and that of any third party; preventing and investigating activity that may be illegal or questionable, etc.
For analytics and research purposes. This helps Us gather statistical data, monitor the effectiveness of the content We create or communications We deliver, and analyze the way You use our Services so We can resolve any potential issues and improve our Site and Services for You.
To communicate with You. We may contact You about your purchase and/or use of our Services, respond to your inquiries, questions, or feedback, and facilitate the provision of our Services to You. We may also send You electronic newsletters with news, special offers, and other information that may interest You, unless You choose not to receive such communications by unsubscribing from our mailing list. Detailed unsubscribe instructions are included in every newsletter or other promotional letter We send You. We may use the services of third-party providers to help with operating our Site or business, such as to send out surveys, newsletters, and other communications on our behalf. Your information may be shared with such providers strictly for those limited purposes, as long as You have given Us consent to such communications.
We send commercial emails, including promotional offers, only with your express consent and in accordance with the Spam Act 2003.
7a. Use of our Services for email marketing and mass communications
We provide email marketing services that allow You to create, schedule, and send marketing emails, newsletters, and other bulk communications. When using these services, You acknowledge and agree to the following:
Recipient consent and responsibility. You are solely responsible for ensuring that your Contacts (email recipients) have provided valid consent to receive your communications. You must comply with all applicable anti-spam and data protection laws, including, but not limited to, the Spam Act 2003 (Australia), the CAN-SPAM Act (United States), the General Data Protection Regulation (GDPR) (EU), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA) (United States), and Lei Geral de Proteção de Dados (LGPD) (Brazil). You must not use our Services to send unsolicited emails, phishing messages, or any unlawful content.
Recipient data handling. To deliver bulk emails, You may upload and manage Contact lists within our Services. We Process the Contact information You provide (such as names and email addresses) only to send campaigns and generate reports. We do not sell or rent Contact lists, and We do not use this data for our own marketing purposes. We may retain engagement statistics (such as delivery rates, opens, clicks, bounces, and spam complaints) to provide reporting and improve service reliability.
Spam complaints, blacklisting, and abuse prevention. We actively monitor delivery metrics to prevent abuse. Excessive spam complaints, blacklisting incidents, or evidence of non-compliance may result in temporary suspension or permanent termination of your Account. To protect our infrastructure and other users, We reserve the right to block or filter campaigns that appear to violate applicable laws or industry standards.
Third-party providers. We may rely on third-party service providers to facilitate large-scale email delivery. Contact data transmitted to such providers will be limited to what is necessary to send your campaigns and generate performance statistics. These providers are contractually obligated to safeguard the data in accordance with applicable law.
User precautions. Before uploading or using Contact data in our Services, ensure You have obtained valid consent and provided clear unsubscribe options. You remain responsible for honoring unsubscribe and data deletion requests and for maintaining the accuracy and legality of your lists. We provide tools to help with compliance, but the ultimate responsibility for lawful sending rests with You.
8. Artificial intelligence (AI) and automated Processing
When You use or interact with features of our Services like chatbots, digital assistants, or other digital conversational experiences powered by artificial intelligence, We may Process your Personal Data using automated and manual (human) methods. For example, when We use automated Processing on your Personal Data to provide a more personalized and enhanced experience within our Services, You may see instantly tailored recommendations and insights to optimize your campaigns. Or, when We analyze Personal Data and transactions We have collected or received about You, We can provide You with personalized advice, predictions, recommendations, and experiences. Detailed information can be obtained from our Data Processing Agreement.
9. Legal basis for Processing data
We may Process your Personal Data if one of the following applies:
- You have given consent for one or more specific purposes;
- Provision of data is necessary for the performance of an agreement between You and Us or for any pre-contractual obligations;
- Processing is necessary for compliance with a legal obligation to which We are subject; or
- Processing is necessary for the purposes of the legitimate interests pursued by Us or by a third party.
In any case, We will gladly help clarify the specific legal basis that applies to the Processing of your data.
10. Who We share your information with
We will not sell, rent, or lease your Personal Data to others. We share customer information with companies working on our behalf, but only as described above in the "How We use your information" section. We disclose Personal Data to third parties only where necessary for the purposes described in this Privacy Policy, where required or permitted by applicable law, or where You have otherwise authorized Us to do so.
11. Keeping your information secure
We are committed to protecting the information You provide to Us. To prevent unauthorized access or disclosure, to maintain data accuracy, and to ensure the appropriate use of the information, We have in place appropriate physical and managerial procedures to safeguard the information We collect. However, there is no system that could guarantee absolute security of your information. While We do our best to protect the Personal Data You provide to Us from unauthorized access or use by third parties, We may not be able to warrant or ensure complete security of such information. Therefore, your use of our Site and our Services and your communications with Us are at your own risk. You take responsibility for protecting your login, password, and other such details, as well as for the security of any data You transmit over the internet to Us or with the help of our Services.
12. Data retention period
Personal Data will be Processed and stored for as long as required by the purpose it was collected for.
We may be allowed to retain Personal Data for a longer period whenever the user has given consent to such Processing, as long as such consent is not withdrawn. Furthermore, We may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data will be deleted. Therefore, the right of access, the right to erasure, the right to rectification, and the right to data portability cannot be enforced after the expiration of the retention period.
You can find more details in our Terms of Service and Data Processing Agreement.
13. Controlling your data
How You can opt out of marketing communications.
We may send You certain informational or promotional communications. Where required by law, such communications will be sent to You only with your consent. To opt out of receiving promotional emails from Us, You may follow the unsubscribe instructions provided in every letter. Some emails are necessary for Us to provide our Services to You or manage your Account. Such emails will be sent to You even after You unsubscribe from optional marketing communications.
How You can access, edit, or delete your Personal Data.
Keeping your Personal Data updated and accurate helps Us provide better service to You. You may email Us at any time to review the information We have on You, to update it, or to have Us delete it. Email address to use for this purpose: info@sendigram.com.
14. Data protection rights
You are entitled to the following personal data protection rights:
- The right to access. You have the right to request copies of your Personal Data from Us, to receive it in a structured, commonly used, and machine-readable format, and, if technically feasible, to have it transmitted to another Controller without any hindrance. This provision is applicable provided that the data is Processed by automated means and that the Processing is based on your consent, on a contract that You are part of, or on pre-contractual obligations thereof. The first copy of your data may be provided to You without a charge. We will charge You a small fee for this service for subsequent requests if We consider them to be exaggerated requests.
- The right to rectification. You have the right to request that We correct any information You believe is inaccurate. You also have the right to request that We complete the information You believe is incomplete.
- The right to erasure. You have the right to request that We erase your Personal Data under certain conditions.
- The right to restrict Processing. You have the right to request that We restrict the Processing of your Personal Data under certain conditions.
- The right to object to Processing. You have the right to object to our processing of your Personal Data under certain conditions.
- The right to data portability. You have the right to request that We transfer the data that We have collected to another organization, or directly to You, under certain conditions.
- The right to non-discrimination. We do not discriminate against users in any way for exercising their rights under any data protection law or regulation that applies to them, or for any other reason.
If You would like to exercise any of these rights, please contact Us via email at info@sendigram.com.
Considering the specific requirements related to the exercising of these data protection rights:
- We will respond to your request without undue delay and, in any event, within one month of receiving the request. Where permitted by applicable law, this period may be extended.
- We may provide You with the Personal Data We have collected about You up to twice a year.
- We may decline your request for Personal Data if We are unable to verify your identity. You are responsible for providing Us with enough information to enable Us to confirm that You are the person whose information You are requesting. When requests are made from a registered Sendigram Account, We consider such requests sufficiently verified.
- We may decline to send your Personal Data to another person or entity.
15. International transfers of Personal Data
All Personal Data processed by Us may be transferred, Processed, and stored anywhere in the world, including, but not limited to, the United States or other countries, which may have data protection laws that are different from the laws where You live.
If We transfer Personal Data which originates in the European Economic Area, Switzerland, and/or the United Kingdom to a country that has not been found to provide an adequate level of protection under applicable data protection laws, one of the safeguards We may use to support such transfer is the EU Standard Contractual Clauses.
For more information about the safeguards We use for international transfers of your Personal Data, please contact Us as set forth below.
16. EU/EEA and international data protection laws
We Process Personal Data in accordance with applicable data protection laws, including the GDPR where applicable:
- GDPR: The General Data Protection Regulation (GDPR), effective May 25, 2018, places additional obligations on companies handling data of EU residents. See more information here: https://gdpr.eu/
- UK Data Protection Act 2018: The Data Protection Act 2018 is the UK's implementation of the GDPR. See more information here: https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted
- CCPA: The California Consumer Privacy Act (CCPA), effective January 1, 2020, extends user privacy protection rights for California residents. See more information here: https://oag.ca.gov/privacy/ccpa
- LGPD: Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD) is a data protection law effective August 14, 2018, and is relatively similar to the EU's GDPR. See more information here: https://www.lgpdbrasil.com.br/
For users located in jurisdictions with privacy laws: We act as a Controller for Personal Data Processed through our Services. Users may have additional rights, including:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability; and
- withdrawal of consent.
If You are a resident of a country covered by the above laws and You would like to exercise any rights available to You under the law, You may contact Us at info@sendigram.com in accordance with the provisions of this Privacy Policy.
17. Global Privacy Control (GPC)
Where required by applicable law, We recognize Global Privacy Control (GPC) signals as a valid request to opt out of certain Processing activities. GPC settings may be transmitted by compatible browsers or browser extensions.
Where legally required, such signals will be handled according to applicable privacy requirements.
18. Additional information for Australian users
We comply with the Privacy Act 1988 and the Spam Act 2003. We send commercial electronic messages only with your express consent, include clear sender identification, and provide an easy unsubscribe option in every communication.
If You use our Services to send bulk or promotional communications to or from Australia, You must:
- Obtain valid, verifiable consent from all recipients before sending marketing or promotional emails;
- Include accurate sender identification and a clear, functioning unsubscribe facility in every message;
- Promptly honor unsubscribe requests and keep appropriate records of consent; and
- Use recipient data only for lawful and permitted purposes.
We provide tools to help You comply with these requirements, but the ultimate responsibility for compliance rests with You as the sender. Failure to comply may result in suspension or termination of your Account in addition to potential legal consequences under Australian law.
We handle Personal Data in accordance with the Australian Privacy Principles (APPs). You have the right to access and correct your Personal Data at any time and can contact Us to exercise these rights. When Personal Data is no longer needed for any purpose permitted under the APPs, including APP 11.2, We will take reasonable steps to destroy or de-identify it unless otherwise required by law.
19. United States privacy rights
U.S. laws approach privacy rights via federal privacy laws covering specific industries or data uses as well as individual state privacy laws providing general consumer privacy rights. For example, the CCPA, as well as state laws of Colorado, Iowa, Montana, Nevada, Nebraska, Oregon, Texas, Utah, and several other states, provide comprehensive consumer privacy laws applicable to residents of those states. If You reside in the United States, You may be entitled to some or all of the privacy rights listed below depending on the state laws applicable to You.
- Right to correction. You may have the right to request that We correct inaccurate Personal Data about You on our systems.
- Right to access and confirmation. You may have the right to request confirmation that We have collected Personal Data about You and that We provide You with access to that Personal Data. If You submit an access request, We will provide You with copies of the requested pieces of Personal Data in a portable and readily usable format. Please note that We may be prohibited by law from disclosing certain pieces of Personal Data, and We may be limited in the number or frequency of requests We must fulfill.
- Right to deletion. You may have the right to request that We delete your Personal Data that We collected and retained, with certain exceptions. We may permanently delete, de-identify, or aggregate the Personal Data in response to a request for deletion.
- Right to disclosure. You may request that We disclose details to You about our collection and use of your Personal Data, such as: (i) the categories of Personal Data We have collected about You; (ii) the categories of sources for the Personal Data We have collected about You; (iii) our business purpose for collecting, using, processing, sharing, or selling that Personal Data, as applicable; (iv) the categories of third parties with whom We share that Personal Data; and (v) if We "sold" or "shared" your Personal Data under certain laws, two separate lists stating: (a) sales or sharing, identifying the Personal Data categories that each category of recipient purchased; and (b) disclosures for a business purpose, identifying the Personal Data categories that each category of recipient obtained. Certain laws may limit the number or frequency of requests We must fulfill.
- Right to opt out. Some states entitle consumers to opt out of the sale or sharing of Personal Data or targeted advertising practices. We do not sell Personal Data. We do not share personal information for cross-context behavioral advertising unless permitted by applicable law and appropriate disclosures and choices are provided. Where required, users may exercise their opt-out rights through the Your Privacy Choices link available on our Site.
- Right to limit use of sensitive data. Some states provide a right to opt out or limit a company's use of sensitive Personal Data. We do not seek to collect sensitive Personal Data about any individual, and in no case do We disclose any sensitive Personal Data for the purpose of inferring characteristics about You or otherwise use your sensitive Personal Data without your consent.
- Right to non-discrimination. We will not discriminate against You for exercising your privacy rights. For example, unless permitted by law, We will not: (i) deny You goods or services; (ii) charge You different prices or rates for goods or services; (iii) provide You a different level or quality of goods or services; (iv) retaliate against You as an employee, applicant for employment, or independent contractor for exercising your privacy rights; or (v) suggest that You may receive a different price or rate for goods or services or a different level or quality of goods or services because You exercised a right under applicable privacy laws.
California's Shine the Light Act (Civil Code sections 1798.83–1798.84) entitles California residents to request certain disclosures regarding Personal Data sharing with affiliates and/or third parties for marketing purposes. If You are a California resident, You can request this information via email to support@sendigram.com.
A note for California residents: please be aware that the privacy rights listed above are not available with respect to data collected about You in a business-to-business context when You are acting as an employee to a Customer or potential Customer in the performance of your job duties.
20. Children's privacy
Our Services are not directed toward children under the age required by applicable privacy laws.
We do not knowingly collect Personal Data from children without appropriate authorization where required.
If You believe that a child has provided Personal Data to Us improperly, please contact Us.
Upon verification, We will take appropriate steps to delete such information where required.
21. Sensitive Personal Data
We do not intentionally collect sensitive Personal Data, such as government identification numbers, health information, biometric information, precise location information, or information revealing sensitive characteristics, unless:
- required for a specific service;
- voluntarily provided by You; or
- permitted by applicable law.
If sensitive Personal Data is Processed, it will be handled according to applicable legal requirements.
22. Changes to this Privacy Policy
We may change this Privacy Policy from time to time to reflect any changes in company policy, business practices, or legal requirements. The updated Privacy Policy will be published here, with the last updated date indicated at the bottom. We encourage You to check back here from time to time for any updates that may have been posted. Your continued use of our Site or Services, or your communication with Us regarding them, constitutes your acceptance of the Privacy Policy in effect at that time.
23. Contacting Us
With any requests, comments, or questions relating to this Privacy Policy, please email Us at info@sendigram.com.
You can always access the latest version of our Privacy Policy from our home page.
This Privacy Policy was last updated on: 01/08/2026