GDPR Compliance

Last Updated: 21st September 2026

This page explains how SalesBlink complies with the General Data Protection Regulation (GDPR) and the UK GDPR.

Who we are

SalesBlink is operated by FUTUREBLINK Inc., a Delaware corporation (file number 10627023) with a mailing address at 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States.

Our role: controller and processor

Which set of obligations applies to us depends on whose data is involved, and the distinction matters for how you exercise your rights.

  • We are a processor for the data you put into the platform — your prospect and contact records, your campaign content, and the mail in the mailboxes you connect. You decide what to upload and who to contact. We process it on your instructions, under our Data Processing Agreement.
  • We are a controller for your own account data: your user records, billing details, support conversations, security logging, and product usage analytics. That processing is governed by our Privacy Policy.

Our representatives in the EU and the UK

We are established in the United States. Under Article 27 of the GDPR and of the UK GDPR we have designated a representative in each territory, who can be contacted by data subjects and supervisory authorities on data protection matters:

Data Processing Agreement

Our DPA sets out the terms on which we process personal data on your behalf, including the processing scope, our security commitments, sub-processor obligations, breach notification, and deletion. It incorporates the European Commission's Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum.

Read the Data Processing Agreement. If you need a countersigned copy, email dpo@salesblink.io.

Sub-processors

We publish a complete list of the third parties that process personal data on our behalf, what each is used for, what data each handles, and where processing takes place. We give at least 30 days' notice before adding or replacing a sub-processor, and customers may object on reasonable data protection grounds within 15 days.

View the sub-processor list.

International transfers

Because we are established in the United States, personal data originating in the EEA or the UK is transferred outside those territories. Every such transfer is made under the Standard Contractual Clauses, with you as data exporter and us as data importer, together with the UK Addendum where the data originates in the United Kingdom. We maintain a transfer impact assessment and will provide a copy on request.

We and our sub-processors process data in multiple regions, including the European Economic Area and the United States. We will confirm the processing region for any individual sub-processor on request.

How long we keep data

  • Trial accounts — deleted within six months of the end of the trial where no paid plan is purchased.
  • Paid accounts — deleted one year after a subscription lapses without renewal.
  • Message content and attachments — deleted at the same time as the account.
  • Operational and analytics logs — retained for 90 days.
  • Backups — retained for 30 days, so deleted data clears backups within 30 days.

You can ask us to delete your data sooner at any time, without waiting for these periods to elapse.

Your rights, and how to exercise them

Under the GDPR and UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority.

If you are a SalesBlink customer: you can search, export, correct and delete data directly in your account, including deleting the account itself. For anything the product does not cover, email dpo@salesblink.io.

If you received an email sent through SalesBlink: the sender is the controller of your data, not us. We hold that data on their instructions and are not permitted to disclose or delete it on our own initiative. You can unsubscribe using the link in the message, and you should direct access or deletion requests to the sender. If you contact us instead, we will pass your request to the relevant customer promptly and tell you we have done so.

If you send email through SalesBlink

When you use SalesBlink for outreach, you are the controller of the prospect data you process. That means you are responsible for having a lawful basis for contacting your recipients, for giving the transparency information the GDPR requires where you have obtained their data from a source other than themselves, for honouring unsubscribe and objection requests, and for complying with the electronic marketing rules that apply where your recipients are located. Our platform provides unsubscribe handling and suppression, but the legal responsibility for who you contact and why rests with you.

Security

Our full technical and organisational measures are set out in section 7 of the Data Processing Agreement. In summary: TLS is enforced in transit; databases, object storage and backups are encrypted at rest; access is role-based, restricted to named individuals, protected by multi-factor authentication for production systems, and reviewed quarterly; data stores are not exposed to the public internet; rate limiting is applied to authentication and API endpoints; backups are taken daily and restore-tested annually.

We do not currently hold a SOC 2 Type II attestation or ISO/IEC 27001 certification. We are happy to share our security documentation and complete a security questionnaire on request.

Data breaches

If a personal data breach affects data we process on your behalf, we will notify you without undue delay and in any event within 48 hours of becoming aware of it, with the information you need to meet your own notification obligations.

Get in touch

For any data protection question — a DPA, a data subject request, a security questionnaire, or the processing region for a specific sub-processor — contact dpo@salesblink.io or write to us.