
Security and trust
Better Email is a Danish company. Customer data is stored and processed in the EU, access runs through your own identity provider, and every action in the platform is logged.
01/Overview
Key facts
- Data location
- EU
- Storage and processing in the EU. AI inference in the EU on request.
- Uptime commitment
- 99.9%
- Monthly, for authentication, editing and export, under the Enterprise SLA.
- Identity
- SSO · SCIM · MFA
- SAML and OIDC through WorkOS, MFA enforced by your IdP.
- Audit log
- Org-wide
- Sign-ins, roles, approvals, exports and AI actions, all searchable.
- Encryption
- TLS 1.2+ / AES-256
- In transit and at rest, including backups.
- Sub-processor changes
- 30 days
- Advance notice and a right to object for DPA customers.
- Breach notification
- 72 h
- Without undue delay; 24 hours for customers on the Enterprise SLA.
- Data export
- Any time
- Campaigns as HTML, self-service. Personal data on request within 7 working days.
02/By region
For customers in the EU and the US
EU / UK
Buying in the EU or the UK
Data residency, GDPR roles, transfers, sector rules.
- 01All customer data is stored and processed in the EU. See the sub-processor list for each provider and location.
- 02A standalone Data Processing Agreement with EU Standard Contractual Clauses and the UK Addendum for the few US providers we use.
- 03AI features can run on your own provider. Bring your own Amazon Bedrock, Anthropic or other AI account, choose an EU region such as Frankfurt, and content never leaves the EU. Details below.
- 04A DORA statement for banks and insurers, and an accessibility statement aligned with the European Accessibility Act.
- 05Supervisory authority: Datatilsynet, Denmark. Danish law, Copenhagen venue.
US
Buying in the US
Identity, availability, questionnaires, privacy law.
- 01SSO through Okta, Microsoft Entra ID or Google Workspace, SCIM provisioning, and MFA enforced by your identity provider.
- 02A published Enterprise SLA with 99.9% monthly uptime and response targets by severity, and a public status page.
- 03CAIQ-Lite answers and a security overview on request. Reference calls with enterprise customers can be arranged.
- 04CCPA and CPRA: we do not sell personal information. Ad measurement on this website runs only with consent, and the cookie settings in the footer act as the “Do Not Sell or Share” control.
- 05Hosting stays in the EU for US customers too. Cloudflare's edge network keeps the app fast from any location, and campaigns export straight to your sending platform.
03/Controls
What is in place
Every control below is live for every customer today.
- Identity and access
- Auditability
- Data and infrastructure
Identity and access
Single sign-on
SAML 2.0 and OIDC through WorkOS. Works with Okta, Microsoft Entra ID, Google Workspace and any standards-based identity provider.
Multi-factor authentication
MFA is enforced through your identity provider. Admins can reset MFA for a user, and users manage their own device sessions.
SCIM provisioning
Joiners, movers and leavers update automatically from your directory. Deprovisioning removes access the moment the account is disabled.
Roles and business-unit isolation
Admin, Designer, Editor and Reviewer roles, plus group-based access to folders, design systems and integrations, so brands and markets stay separated inside one organisation.
Auditability
Organisation-wide audit log
Searchable and filterable: sign-ins, permission denials, membership and MFA changes, role changes, design system pushes, exports and approvals.
Per-campaign timeline
Every campaign carries its own workflow history and an export trail showing who exported what, when, to which platform, and with what result.
Attested approvals
Approvals are recorded against an exact revision. The export gate can be set to off, warn or block, so nothing unapproved reaches your sending platform.
Betty works under delegation
Our AI assistant acts under a revocable delegation of the user's own permissions, with a bot identity and provenance on every action it takes.
Data and infrastructure
Hosted in the EU
Application and database on Heroku (EU region), files on AWS S3 (eu-west-1), realtime backend on Convex (EU), edge and CDN on Cloudflare with EU storage. Product analytics and error tracking stay in the EU too (PostHog EU, Sentry EU).
Encrypted in transit and at rest
TLS 1.2 or higher on every connection. Databases, file storage and backups are encrypted at rest with AES-256.
Secrets in a vault
Integration credentials for your sending platform are stored in an encrypted secret vault and never shown again in the interface after entry.
Least-privilege operations
Production access is limited to named engineers, granted per need and reviewed. DDoS protection and web application filtering through Cloudflare on every request.
Backups
Daily automated backups of all customer data, encrypted and stored in the EU. Restores are tested as part of our business continuity plan.
Retention and deletion
Activity logs are kept for 30 days. Export is self-service at any time, and personal data export requests are fulfilled within 7 working days. After termination, data is deleted 3 months later unless you instruct us otherwise.
04/AI and your content
Does our content leave the EU?
- Default provider
- Anthropic Claude through Better Email's own API account. OpenAI is used for campaign analysis and translation.
- Training on your content
- Prohibited. Both providers are used under API terms that exclude customer content from model training.
- Where inference runs
- United States by default, under EU Standard Contractual Clauses and the UK Addendum. Run it on your own provider and region instead, for example Amazon Bedrock in the EU (see below).
- Retention at the provider
- Inputs and outputs are not kept beyond the provider's abuse-monitoring window of up to 30 days, and are never used to train models.
- Email client previews
- Rendered by EmailPreviewServices (United States) under SCCs. Only the campaign HTML you choose to preview is sent.
- Switching it off
- AI features can be disabled per workspace. Email client previews are used only when you request one.
- 01
Bring your own provider
If your organisation already has an AI agreement, Betty can run on it. Connect your own Amazon Bedrock account, your own Anthropic account, or another approved provider. Inference then runs under your contract and in your region. You see the model, the region and the spend, and you can rotate or revoke the key at any time. The audit trail records every action Betty takes whichever provider is behind her.
- 02
EU-only inference
With Bedrock in an EU region such as Frankfurt, prompts, campaign content and generated output stay in the EU. Together with EU hosting, nothing in the processing chain leaves the EU, and nothing changes for your users.
05/Availability and continuity
Uptime and recovery
01
99.9% monthly uptime
For authentication, campaign editing and export, measured monthly and excluding maintenance announced 5 business days ahead. Response targets by severity are in the Enterprise SLA; remedies for a missed month are agreed in the order form.
02
Public status page
Live component status and incident history at status.better.email, with email subscriptions for incidents.
03
Business continuity
Documented business continuity and disaster recovery plan, reviewed annually: daily backups, a 24 hour recovery point objective for the database (near zero for files) and a 4 hour recovery time objective. The plan is available on request.
04
Exit and portability
Campaigns export as HTML to your sending platform at any time. After termination you get a 60 day transition period with a named contact, your design systems and assets delivered within 10 business days of asking, and 3 months before deletion.
06/Vulnerability management
How issues get found and fixed
Secure development
Every change goes through peer review and automated tests before deployment. Dependencies are scanned continuously and patched on a fixed cadence, faster for critical advisories.
Monitoring
Error tracking, performance and uptime monitoring with on-call alerting. Cloudflare filters malicious traffic and rate-limits abuse at the edge.
Incident response
A documented incident process with severity levels, internal escalation and customer communication. Affected customers are notified without undue delay and within 72 hours of a confirmed personal data breach.
Responsible disclosure
A public policy with safe harbour for good-faith research, a monitored [email protected] mailbox, security.txt, and acknowledgement within 2 business days.
To report a vulnerability, see the disclosure policy or write to [email protected].
07/Certifications
Certifications and testing
Today
GDPR and the controls above
Article 28 DPA, EU data residency, SSO, SCIM, MFA, audit logging, encryption and a public sub-processor list. Our infrastructure providers (AWS, Heroku, Cloudflare, WorkOS) hold SOC 2 Type II and ISO 27001.
Roadmap
ISO 27001
On our roadmap. Ask us for the current status and timing.
On request
Third-party penetration test
A summary letter from the most recent independent penetration test of the application and its infrastructure is available on request under NDA.
The security overview maps our controls to the SOC 2 Trust Services Criteria.
08/Company
About Better Email ApS
Registration documents are on the Impressum. Case studies with named contacts are under Case Studies.
- Legal entity
- Better Email ApS, CVR 42361194, Italiensvej 2, 5th, 2300 København S, Denmark
- Offices
- Copenhagen (HQ) and Hamburg
- Track record
- Founded in 2021 by a team that has built email production tooling for enterprise teams since 2017
- Ownership
- Founder-owned and founder-funded, with no external investors
- Customers
- Enterprise and mid-size marketing teams across the EU, the UK and the United States, including regulated industries, retail, energy, entertainment and consumer brands. References available on request
- Continuity
- Business continuity, disaster recovery and exit plans documented and reviewed annually
- Insurance
- Business and cyber liability insurance in place. Certificate on request
09/Documents
Documents
Public
Data Processing Agreement
GDPR Article 28 terms, SCCs, technical and organisational measures. Read online, countersigned copy on request.
OpenEnterprise SLA
99.9% monthly uptime, how it is measured, support hours, and response targets by severity.
OpenSub-processor list
Every provider, what they process, where, and the transfer mechanism. 30 days notice of changes.
OpenPrivacy Policy
Roles, legal bases, retention periods, international transfers and your rights.
OpenTerms of Service
The agreement that governs use of the platform, including availability and data terms.
OpenDORA statement
What we provide to financial entities for their ICT third-party risk obligations.
OpenAccessibility statement
WCAG 2.2 AA for the platform and this website, known limitations, and how to report an issue.
OpenResponsible disclosure
How to report a vulnerability. Acknowledged within 2 business days, safe harbour for good-faith research.
OpenOn request
Security overview and questionnaire answers
Our standard answers in CAIQ-Lite format, plus completion of your own questionnaire.
Business continuity and disaster recovery plan
Recovery objectives, backup and restore procedures, key-person cover and test cadence.
Exit plan
Data export formats, timelines, deletion and transition assistance at the end of the agreement.
Architecture and data flow overview
System boundaries, where each category of data lives, and which sub-processor touches it.
Insurance certificate
Current certificate of insurance, including cyber liability cover.
Penetration test summary
Summary letter from the most recent independent test, shared under NDA.
Does our content leave the EU?
Not for storage or processing. It can for two optional features: AI assistance (Anthropic and OpenAI, US, under SCCs, no training) and email client previews (EmailPreviewServices, US, under SCCs). Both can be switched off, and AI can run on your own provider in an EU region instead, for example Amazon Bedrock in Frankfurt.
We already use Amazon Bedrock (or another AI provider). Can Betty run on that?
Yes. Connect your own Amazon Bedrock account, a direct Anthropic account, or another provider your organisation has approved. Inference then runs under your contract and in the region you choose. Nothing changes for your users, and the audit trail still records every action Betty takes.
Do you have SOC 2 or ISO 27001?
No. We provide a control-by-control security overview, CAIQ-Lite answers and a penetration test summary on request, and our infrastructure providers (AWS, Heroku, Cloudflare, WorkOS) hold SOC 2 Type II and ISO 27001. Ask us about certification timing.
Is the DPA available before we sign?
Yes. The DPA is published at /legal/dpa and applies to every customer through the Terms. Send your company details to [email protected] for a countersigned PDF.
What personal data do you hold about our subscribers?
Usually none. Campaigns are built in Better Email and sent by your own sending platform. Subscriber data stays there; only merge-tag field names sync to us. If you upload a test list or paste personal data into content, it is processed under the DPA.
What happens if you go out of business or we leave?
You keep exporting campaigns as normal through a 60 day transition period, we deliver your design systems and assets within 10 business days of asking, and data is deleted 3 months after termination. The exit plan describes each step and is available on request.
Security review
Have a questionnaire? Send it over
We answer standard questionnaires and your own, and we can sign your NDA first.
Contacts
- Security
- [email protected]
- Data protection
- [email protected]
- Support
- [email protected]
- Status
- status.better.email