Skip to content

GDPR & data residency

A form backend built for GDPR, not retrofitted for it

Most form backends are US companies, hosted on US infrastructure, run under US law. That's a real problem when the form you're building collects personal data from EU visitors — data residency, sub-processor transparency, and a signed DPA aren't optional extras, they're what your client's DPO will ask about first.

PostTo is hosted in Europe and operated by Lindgaard.net, a Norwegian company. Submission data stays within European borders by default, every field is encrypted at rest, and a Data Processing Agreement is available before you send your first submission.

Free plan, no credit card required.

How PostTo handles it

European hosting, European operator

PostTo runs on European infrastructure and is operated by a Norwegian company — no US parent, no default transatlantic transfer for baseline operation.

Encryption at rest, on every plan

Submission fields — subject, message, sender name, sender email — are AES-256 encrypted at rest, including on the free plan. This isn't a paid-tier upsell.

A DPA you can actually sign

The Data Processing Agreement names the processor, lists sub-processors, and commits to notifying you before any sub-processor changes, with a right to object.

Configurable retention, automatic purging

Set a retention period per endpoint. A daily job scrubs submission content once it expires — you don't have to remember to delete anything.

Manual erasure on request

A data-subject erasure request doesn't have to wait for the retention window. Purge any individual submission from the dashboard immediately.

AI classification is opt-in, not default

Baseline spam filtering (honeypot + heuristics) is fully first-party — no submission data ever leaves PostTo for it. Optional AI classification only runs if you explicitly enable it per endpoint, after a sub-processor consent notice.

Frequently asked questions

Is PostTo GDPR compliant?
PostTo is built to support your GDPR compliance: European hosting, encryption at rest, a signed DPA, configurable retention with automatic purging, and manual erasure. Whether your specific use of PostTo is fully compliant depends on your own processing activities — the DPA and Privacy Policy set out the details.
Where exactly is submission data stored?
On European infrastructure, operated by Lindgaard.net (Norway). Baseline operation — receiving, filtering, and delivering a submission — involves no transfer outside Europe.
Does enabling AI spam filtering send my data outside Europe?
Only if you opt in. AI classification is off by default per endpoint. When enabled, only borderline submissions (ones baseline filtering can't confidently score) are sent to Anthropic, a sub-processor listed in the DPA and covered by a DPA of its own. The check fails open — an API error never blocks delivery.
Can I get a copy of the DPA before signing up?
Yes — the DPA is public and linked from the footer of every page. Read it, share it with your legal team, and reach out if you need a signed copy for your own records.
What happens to submission data after the retention period?
A daily job automatically scrubs submission content once it passes the endpoint's configured retention period. You can also purge an individual submission manually at any time, e.g. in response to an erasure request.
What does it cost?
The free plan includes 50 submissions per month with the full dashboard, encryption at rest, and baseline spam filtering — no credit card required. Paid plans start at $9/month.

See it working in a few minutes

Create an endpoint, point your form at it, and see your first submission in the dashboard — all on the free plan.

Try PostTo free