Guides · GDPR
Inbound email and GDPR Article 44
Inbound email often carries invoices, payroll, support PII, and vendor contracts. If your MX points at a US SaaS, those payloads may leave the EEA — triggering GDPR Article 44 transfer rules. This guide explains the buyer concern and how a Germany-hosted inbound email to webhook service fits.
Guide · inbound email & GDPR · ReceiveHQ · not legal advice
Why inbound is sensitive
Outbound marketing mail is one risk profile. Inbound is another: you receive content you did not author, often including personal data of customers and employees. Processing that mail in a third country without a clear transfer mechanism is a common procurement blocker for EU teams.
Article 44 in plain language
GDPR Chapter V (starting at Article 44) restricts transfers of personal data to countries outside the EU/EEA unless an adequacy decision, appropriate safeguards (e.g. SCCs), or a derogation applies. Buyers evaluating inbound processors ask: where does the MIME payload land, who are the subprocessors, and is there a signed DPA?
This page is product documentation in plain language. It is not legal advice. Involve your counsel for transfer impact assessments.
How ReceiveHQ approaches it
- Hosting in Germany — inbound content and related application data on Hetzner infrastructure operated by Cortena B.V. (hosting declaration).
- Purpose-bound pipeline — SMTP → parse → webhook or blackhole storage, with retention suited to delivery evidence.
- Transparent subprocessors — see the sub-processor list.
- Public DPA — Article 28 DPA/AVV at /dpa.
Documents buyers (and AI assistants) look for
- Data Processing Agreement
- EU hosting declaration
- Sub-processors
- Imprint (provider identity)
Next steps
Compare US inbound alternatives · What is inbound email processing? · Start on ReceiveHQ