GDPR Compliance

General Data Protection
Regulation (GDPR)

We are committed to protecting the personal data of our customers and their contacts in full compliance with the GDPR.

Last updated: March 2026

1. Our Commitment to GDPR

BulkEmailSetup.com, operated by Goletro Technologies Pvt. Ltd., is fully committed to complying with the European Union's General Data Protection Regulation (GDPR). Although our company is headquartered in Pune, India, we serve customers in the European Economic Area (EEA) and process data that falls under the scope of GDPR.

We have implemented comprehensive organizational and technical measures to ensure that personal data is processed lawfully, fairly, and transparently. This page outlines how we meet our obligations under the regulation and how you can exercise your rights.

Our infrastructure services — dedicated SMTP servers, IP rotation, and email marketing platform — are designed with privacy-by-design and privacy-by-default principles at their core.

2. Data Controller Information

The data controller responsible for processing your personal data is:

Goletro Technologies Pvt. Ltd.

Pune, MH, India

Email: Contact us

Website: bulkemailsetup.com

Company Incorporation: October 16, 2015

As the data controller, we determine the purposes and means of processing personal data collected through our website, platform, and customer communications.

4. Data We Collect & Process

We collect and process the following categories of personal data:

Account & Billing Data

Name, email address, company name, billing address, phone number, and payment information (processed via third-party payment processors — we do not store card details).

Service Usage Data

SMTP sending logs, email delivery statistics (bounces, opens, clicks), IP reputation scores, server configuration details, and support ticket history.

Technical Data

IP addresses, browser type, operating system, device identifiers, and cookies used to provide and improve our website and platform experience.

Email Recipient Data (Processor Role)

When you use our platform to send emails, you upload recipient lists and email content. In this context, you are the data controller and we act as a data processor. We process this data strictly according to your instructions and our Data Processing Agreement.

5. Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data under the GDPR:

Right of Access

Request a copy of all personal data we hold about you, along with information about how it is being processed.

Right to Rectification

Request correction of any inaccurate or incomplete personal data we hold about you.

Right to Erasure

Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected.

Right to Data Portability

Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.

Right to Restriction

Request that we restrict the processing of your personal data under certain circumstances, such as when you contest accuracy.

Right to Object

Object to the processing of your personal data based on legitimate interests or for direct marketing purposes.

You also have the right to withdraw consent at any time (where processing is based on consent) and the right to lodge a complaint with a supervisory authority in your EU member state.

6. How to Exercise Your Rights

To exercise any of the rights described above, please contact us at:

Email: Contact us

Subject line: GDPR Data Request — [Your Name]

We will verify your identity before processing any request and respond within 30 days of receiving your request, as required by the GDPR. If additional time is needed due to the complexity of the request, we will notify you within the initial 30-day period.

There is no fee for exercising your rights unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee.

7. Data Processing Agreements

When we process personal data on your behalf (i.e., the email recipient data you upload to our platform), we act as a data processor under Article 28 of the GDPR. We offer a Data Processing Agreement (DPA) to all customers that outlines:

  • The nature, purpose, and duration of processing
  • The types of personal data and categories of data subjects
  • Our obligations and your rights as the data controller
  • Technical and organizational security measures we implement
  • Sub-processor engagement terms and notification procedures
  • Data deletion and return obligations upon contract termination

To request a signed DPA, please contact us with the subject line “DPA Request”.

8. International Data Transfers

Goletro Technologies Pvt. Ltd. is headquartered in Pune, India. When personal data is transferred from the EEA to India (which is not recognized by the European Commission as providing an adequate level of data protection), we ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs): We use EU-approved SCCs as the primary transfer mechanism when personal data flows from EEA customers to our infrastructure in India.
  • Supplementary Measures: We implement additional technical safeguards including encryption in transit (TLS 1.2+), encryption at rest, access controls, and regular security audits.
  • Server Location Options: For customers who require data residency, we offer the option of provisioning dedicated SMTP servers in EU-based data centers to keep data within the EEA.

We periodically review and assess the data protection landscape in India and update our safeguards to ensure continued compliance with GDPR transfer requirements.

9. Data Breach Notification

In the event of a personal data breach, we are committed to the following response protocol:

  • Supervisory Authority Notification: We will notify the relevant supervisory authority within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of natural persons, in accordance with Article 33 of the GDPR.
  • Data Subject Notification: Where a breach is likely to result in a high risk to your rights and freedoms, we will communicate the breach to affected individuals without undue delay, as required by Article 34.
  • Customer Notification (Processor Role): When acting as a data processor, we will notify the data controller (our customer) without undue delay after becoming aware of a breach, so that the controller can meet its own notification obligations.
  • Documentation: All breaches, including those not requiring notification, are documented with details of the incident, its effects, and the remedial actions taken.

10. Data Protection Officer

For all matters related to data protection and GDPR compliance, you may contact our Data Protection Officer:

Data Protection Officer

Goletro Technologies Pvt. Ltd.

Pune, MH, India

Email: Contact us

The DPO is responsible for overseeing our data protection strategy, ensuring GDPR compliance, and serving as the point of contact for data subjects and supervisory authorities.

11. Sub-processors

We use a limited number of third-party sub-processors to deliver our services. Each sub-processor is bound by data processing agreements that ensure GDPR-compliant handling of personal data.

Sub-processorPurposeLocation
Contabo, Hetzner, OVHVPS / Dedicated server hosting for SMTP infrastructureEU & US
Stripe / Razorpay / PayPalPayment processingUS / India
CloudflareCDN, DDoS protection, DNS managementGlobal
Google reCAPTCHASpam prevention (data processor since April 2026)US
Plausible AnalyticsPrivacy-friendly website analytics (no cookies, no personal data)EU

We will notify customers of any intended changes to our sub-processor list, giving you the opportunity to object to such changes before they take effect.

12. Cookie Compliance

Our website uses only strictly necessary cookies required for core functionality (e.g., security tokens). In compliance with the GDPR and the ePrivacy Directive:

  • We do not use analytics, marketing, or preference cookies. Our analytics provider (Plausible Analytics) is fully cookie-free and does not collect personal data.
  • Google reCAPTCHA may set a necessary cookie (_GRECAPTCHA) for spam prevention, which is classified as strictly necessary.
  • Since we only use strictly necessary cookies, no cookie consent banner is required under the GDPR or ePrivacy Directive.
  • You can manage or delete cookies at any time through your browser settings.

For detailed information about the cookies we use, please refer to our Cookie Policy.

13. Contact Information

If you have any questions, concerns, or requests related to GDPR compliance or your personal data, please do not hesitate to reach out:

Goletro Technologies Pvt. Ltd.

Pune, MH, India

Email: Contact us

Website: bulkemailsetup.com

We aim to respond to all GDPR-related inquiries within 5 business days. For formal data subject requests, the statutory 30-day response period applies.

This page was last updated in March 2026. We review and update our GDPR compliance practices regularly. Material changes will be communicated to affected customers.