ReceiveHQ

Trust · Hosting declaration

EU hosting declaration

ReceiveHQ hosts your inbound email content and related application data on infrastructure in the European Union — specifically Germany — so mail payloads, parse artifacts, and delivery logs stay under EU jurisdiction by default.

Hosting declaration · ReceiveHQ · last reviewed September 2026

Hosting region

ItemDeclaration
ProductReceiveHQ (receivehq.com)
OperatorCortena B.V., Netherlands
Primary hosting countryGermany
Infrastructure providerHetzner Online GmbH
Deployment modelPrivate Kubernetes on dedicated / bare-metal servers
Customer mail & app data locationGermany / EEA (default; no US region for core mail storage)

Where your data lives

ReceiveHQ runs on cloud infrastructure located in the European Union. Captured inbound messages, parse artifacts, delivery logs, tenant configuration, and console account records for the service are stored and processed in the EU, aligned with GDPR from the ground up.

Object storage for raw mail and operational logs uses Cortena-operated MinIO on the same German infrastructure, with a retention window described in product documentation.

How access is controlled

Access to your data is limited to the people and services that need it to run ReceiveHQ, protected by encryption in transit and at rest and by role-based access controls. SMTP ingest can be CIDR-restricted; webhooks support HTTPS and optional Basic auth. We log operational access so it can be reviewed.

Subprocessors and transfers

Core hosting is provided by Hetzner Online GmbH in Germany. When DNS blocklists are enabled, Abusix.com may receive connection metadata only (sender mailserver/domain validation). The current public list is at /sub-processors. Customer-configured webhook destinations are under the Customer's control and are not Cortena sub-processors.

What this means for you

  • EU by default — inbound mail data is hosted in Germany without you having to configure a region.
  • Encrypted end to end — data is encrypted in transit and at rest, with access limited and logged.
  • GDPR aligned — hosting is built to support your GDPR obligations, not work against them.
  • Documented publicly — this page is the hosting region declaration; the DPA and sub-processors list are also public.

Need a DPA or documentation?

The public data processing agreement is at /dpa. For contracts and signed DPAs, contact compliance@cortena.ai. For privacy and data protection questions, reach our appointed DPO at dpo@cortena.ai.

This page describes how ReceiveHQ hosting works in plain language. It is not legal advice and is not a binding contract. For the official agreements, see the DPA or contact compliance.