Compliance

Compliance at Sendexa

Our commitment to security, privacy, and regulatory compliance across all our communication APIs and services.

GDPR Compliant
ISO 27001 (Planned)
SOC 2 (In Progress)
Privacy by Design

Our Commitment

At Sendexa, compliance is not just a checkbox—it's a fundamental part of our culture. We are committed to protecting your data and ensuring our services meet the highest standards of security and regulatory compliance.

1. Compliance Overview

Sendexa is committed to maintaining the highest standards of security, privacy, and regulatory compliance. Our compliance framework is designed to protect your data and ensure our services meet global regulatory requirements.

1.1 Our Compliance Philosophy

  • Privacy by Design: Privacy is integrated into our products from the ground up.
  • Proactive Compliance: We stay ahead of regulatory changes and update our practices accordingly.
  • Transparency: We are open about our data processing practices and compliance posture.
  • Continuous Improvement: We regularly review and enhance our compliance measures.

📋 Scope:Our compliance program covers all aspects of our business, including data processing, security, vendor management, and regulatory reporting.

2. Security & Compliance Standards

We align our practices with globally recognized security and compliance standards:

SOC 2 Type II

SOC 2 Type II

In Progress

Security, Availability, Processing Integrity, Confidentiality, Privacy

ISO 27001

ISO 27001

Planned

Information Security Management System

GDPR

GDPR

Compliant

EU General Data Protection Regulation

HIPAA

HIPAA

Planned

Health Insurance Portability and Accountability Act

In Progress:We are actively working towards SOC 2 Type II certification and plan to achieve ISO 27001 and HIPAA compliance in the near future.

3. GDPR Compliance

We are fully committed to GDPR compliance and protecting the personal data of EU citizens:

Data Subject Rights

  • Right to access, rectify, and erase personal data
  • Right to data portability
  • Right to object and restrict processing
  • Right to withdraw consent

Data Protection Measures

  • Data Processing Agreements (DPA) available
  • Standard Contractual Clauses for international transfers
  • Data Protection Impact Assessments (DPIA)
  • Privacy by design and by default

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance and data protection practices. Contact our DPO at dpo@sendexa.co

Learn more about our GDPR compliance →

4. CCPA & US Privacy

We comply with the California Consumer Privacy Act (CCPA) and other US privacy regulations:

Consumer Rights
  • Right to know what data is collected
  • Right to delete personal data
  • Right to opt-out of data sales
  • Right to non-discrimination
Data Practices
  • Clear privacy notices
  • No sale of personal data
  • Opt-out mechanisms
  • Data subject access requests

If you are a California resident, you have specific rights regarding your personal data. Please review our Privacy Policy for more information.

View our Privacy Policy →

5. Data Protection

5.1 Data Classification

  • Public Data: Non-sensitive information that can be freely shared.
  • Internal Data: Business information not intended for public disclosure.
  • Confidential Data: Sensitive business information requiring strict protection.
  • Restricted Data: Personal data subject to regulatory requirements (GDPR, CCPA, etc.).

5.2 Data Lifecycle Management

  • Collection: We collect only necessary data with proper consent.
  • Storage: Data is stored securely with appropriate access controls.
  • Usage: Data is used only for specified, legitimate purposes.
  • Retention: Data is retained only as long as necessary.
  • Disposal: Data is securely deleted when no longer needed.

Data Minimization:We practice data minimization—collecting only the data necessary to provide our services.

6. Security Measures

We implement multiple layers of security to protect your data:

Data Encryption

AES-256 encryption at rest and TLS 1.3 for data in transit.

Access Control

Role-based access control (RBAC) with multi-factor authentication.

Network Security

Enterprise-grade firewalls, DDoS protection, and threat monitoring.

Data Privacy

Privacy by design, data minimization, and regular privacy reviews.

Vulnerability Management

Regular security scanning, penetration testing, and rapid patching.

Audit Trails

Comprehensive logging and monitoring of all access and activities.

6.1 Infrastructure Security

  • Services hosted on secure cloud infrastructure with enterprise-grade security.
  • Regular security patches and updates to all systems.
  • Network segmentation and firewall protection.
  • DDoS protection and mitigation capabilities.

6.2 Application Security

  • Secure development lifecycle (SDLC) with security reviews.
  • Regular vulnerability scanning and penetration testing.
  • Code reviews and security testing in CI/CD pipeline.
  • API security with rate limiting and authentication.

7. Audits & Assessments

7.1 Internal Audits

  • Regular internal security audits conducted quarterly.
  • Compliance reviews to ensure adherence to policies.
  • Privacy impact assessments for new features.
  • Vendor security assessments for third-party services.

7.2 External Assessments

  • Annual third-party penetration testing.
  • External security audits by certified firms.
  • Independent compliance assessments.
  • Customer security questionnaire responses.

7.3 Continuous Monitoring

  • 24/7 monitoring of infrastructure and applications.
  • Automated security scanning and alerts.
  • Regular threat intelligence monitoring.
  • Security Information and Event Management (SIEM).

8. Incident Response

8.1 Incident Response Plan

  • Comprehensive incident response plan with clearly defined roles.
  • Immediate containment and investigation procedures.
  • Communication protocols for internal and external reporting.
  • Post-incident review and improvement process.

8.2 Data Breach Notification

  • 72-Hour Notification: We notify regulatory authorities within 72 hours of becoming aware of a breach.
  • Affected Users: We promptly notify affected users without undue delay.
  • Detailed Reporting: We provide comprehensive breach reports as required.

Ready to Respond:Our incident response team is on standby 24/7 to quickly respond to any security incidents and minimize impact.

9. Third-Party Compliance

We ensure our third-party vendors and partners meet our compliance standards:

Vendor Assessment

All vendors undergo rigorous security and compliance assessments before engagement. We evaluate their security practices, data handling, and regulatory compliance.

Contractual Requirements

We require all vendors to comply with data protection laws and maintain appropriate security measures. Data Processing Agreements are in place with all data processors.

Ongoing Monitoring

We continuously monitor vendor compliance through regular reviews, audits, and security assessments to ensure ongoing compliance.

10. Reporting & Disclosure

10.1 Security Reporting

We take security reports seriously. If you discover a security vulnerability:

  • Report it immediately to security@sendexa.co
  • Provide detailed information including affected systems, impact, and reproduction steps.
  • We will investigate and respond to your report promptly.
  • We have a responsible disclosure policy and appreciate security researchers.

10.2 Compliance Reports

  • SOC 2 Type II and ISO 27001 reports available upon request (under NDA).
  • GDPR documentation including DPIAs and DPA available.
  • Security questionnaires completed promptly for customers.
  • Compliance certifications available for review.

10.3 Transparency Reports

  • We publish transparency reports on data requests and security incidents.
  • Reports detail the types and volume of requests received.
  • We maintain transparency in our data handling practices.

11. Contact Us

For compliance-related inquiries, security reports, or questions about our compliance programs, please contact us:

Email
compliance@sendexa.co

Compliance & Regulatory

Security
security@sendexa.co

Security Vulnerabilities

Phone
+233 555 539 152

Compliance Hotline

Address

Akatsi
Volta Region, Ghana

📋 For compliance inquiries, contact our team at compliance@sendexa.co

Questions About Our Compliance?

Our compliance team is available to answer questions about our security practices, regulatory compliance, and how we protect your data.