ISO 27001 GDPR Compliant Meta Business Partner 190+ Countries 10,000+ Businesses ISO 27001 GDPR Compliant Meta Business Partner 190+ Countries 10,000+ Businesses

GDPR Compliance at BulkSMSHub

BulkSMSHub is built with GDPR and UK GDPR compliance at its core. We are ISO 27001:2022 certified and SOC 2 Type II audited.

📅 Last Updated: April 6, 2026  |  Applies to: EU GDPR, UK GDPR, Swiss nFADP

✅ BulkSMSHub acts as both a Data Controller (for customer account data) and a Data Processor (for personal data you upload to the platform). We are fully compliant with the EU General Data Protection Regulation (GDPR) and UK GDPR.

Our GDPR Compliance Framework

🔐

ISO 27001:2022

Information security management system certified by an accredited third-party auditor. Annual recertification required.

📊

SOC 2 Type II

Annual audit of security, availability, processing integrity, confidentiality and privacy controls by independent auditors.

👥

DPO Appointed

Qualified Data Protection Officer appointed and registered with the relevant supervisory authority.

📄

Data Processing Agreements

GDPR-compliant DPAs available for all customers processing EU/UK personal data. Request via dpo@bulksmshub.com.

🌎

EU Data Residency

EU-based data processing available for enterprise customers. Data stored exclusively in Frankfurt, Germany (AWS eu-central-1).

🔢

Privacy by Design

GDPR Article 25 compliance. Privacy considerations built into every product feature from the design stage.

Lawful Basis for Processing

BulkSMSHub processes personal data under the following lawful bases per GDPR Article 6:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the platform services you have contracted for.
  • Legitimate Interest (Art. 6(1)(f)): Security monitoring, fraud prevention, platform improvement and B2B marketing communications.
  • Legal Obligation (Art. 6(1)(c)): Tax records, financial reporting and compliance with court orders.
  • Consent (Art. 6(1)(a)): Marketing communications to individuals (newsletter, promotional emails). Consent is recorded with timestamp and can be withdrawn at any time.

Data Processing Agreement (DPA)

Under GDPR Article 28, when BulkSMSHub processes personal data on your behalf (as your data processor), you must have a valid Data Processing Agreement in place. Our DPA:

  • Includes all mandatory Article 28(3) clauses
  • Covers sub-processor disclosure and management
  • Includes Standard Contractual Clauses (SCCs) for international data transfers
  • Specifies technical and organisational security measures
  • Provides for data breach notification within 24 hours of discovery

To request a signed DPA, email dpo@bulksmshub.com with your company name and registered address. Enterprise customers can also access the DPA directly from the platform dashboard under Account Settings > Legal.

International Data Transfers

BulkSMSHub transfers data internationally where necessary to provide our global services. All transfers from the EEA/UK are safeguarded by:

  • Standard Contractual Clauses (SCCs): European Commission-approved SCCs incorporated into our DPA for all sub-processors outside the EEA.
  • UK International Data Transfer Agreement (IDTA): For UK-specific requirements post-Brexit.
  • Adequacy Decisions: For transfers to countries recognised as having adequate data protection (Singapore — partial adequacy under review).
  • Transfer Impact Assessments (TIAs): Conducted for all high-risk transfers, available on request from our DPO.

Sub-Processors

We maintain a register of all sub-processors used to deliver our services. Key sub-processors include: Amazon Web Services (EU data centres), Google Cloud Platform, Stripe (payment processing), SendGrid (email delivery), Cloudflare (CDN and security). The full sub-processor list is available to customers under a signed DPA.

We provide 30 days advance notice of any new sub-processors, giving customers the right to object.

Data Subject Rights Management

BulkSMSHub provides tools to help you fulfil GDPR data subject rights on behalf of your end customers:

  • Right to Access: Export all data for a specific contact number or email via the dashboard or API.
  • Right to Erasure: Delete all data for a specific contact, including message history and opt-in records.
  • Opt-Out Suppression: Automatically suppress opted-out contacts from future campaigns.
  • Data Portability: Export contact lists and campaign data in CSV/JSON format.
  • Consent Management: Record, store and manage consent with timestamps for audit purposes.

Security Measures (GDPR Article 32)

  • AES-256 encryption at rest for all data
  • TLS 1.3 for all data in transit
  • Role-based access control and MFA enforced for all platform access
  • Regular penetration testing by independent security firms
  • 24/7 security monitoring and incident response
  • Data breach notification within 24 hours of discovery, GDPR Article 33 compliance within 72 hours

Data Protection Officer

Our appointed DPO can be contacted at:

General Email: sales@bulksmshub.com
Postal Address: BulkSMSHub Pte. Ltd., 1 Raffles Place #20-61, Singapore 048616
EU Representative: Available on request for Article 27 purposes
UK Representative: BulkSMSHub UK, 20 Fenchurch Street, London EC3M 3BY

Need a Data Processing Agreement?

Request your signed GDPR DPA within 2 business days. Enterprise customers get priority turnaround.

💬