StackLégal

Email

GDPR Brevo

In an indie stack, Brevo is used for Marketing and transactional emails. Entity cited: Sendinblue, a French SAS operating as Brevo, registered in Paris under number 498 019 298. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Brevo

Yes. The DPA is built into the terms of use.

Read the DPA

Stated role

Processor of contact and campaign data, the customer being the controller. Also controller for account management, billing, statistics, and the site processing described in the policy.

Personal data

Name, email, phone, IP address, email subject and content, open and click logs, device and browser data, contact attributes uploaded by the customer.

Sub-processors of Brevo

List built into the terms of use.

List published by the vendor

Transfers outside the EU

Hosting / location

The terms indicate OVH hosting in France and Google Cloud Platform in France and in Belgium. Transfers to the United States and to India are also mentioned.

EU–United States Data Privacy Framework

The participant with the public name Brevo, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. The French SAS is not the name on that entry.

Data Privacy Framework sheet

Cookies

The policy describes essential cookies that do not require consent, and other cookies and trackers listed on the cookies page.

Typical use, written by StackLégal and not by the vendor: Marketing and transactional emails.

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Brevo a processor within the meaning of the GDPR?

Processor of contact and campaign data, the customer being the controller. Also controller for account management, billing, statistics, and the site processing described in the policy.

What DPA does Brevo publish?

Yes. The DPA is built into the terms of use. https://www.brevo.com/legal/termsofuse/

Which further sub-processors does Brevo publish?

List built into the terms of use. https://www.brevo.com/legal/termsofuse/

Where does Brevo state that it processes data, including outside the EU?

The terms indicate OVH hosting in France and Google Cloud Platform in France and in Belgium. Transfers to the United States and to India are also mentioned.

Is Brevo registered under the EU–United States Data Privacy Framework?

The participant with the public name Brevo, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. The French SAS is not the name on that entry. https://www.dataprivacyframework.gov/participant/10010

Which personal data does Brevo mention?

Name, email, phone, IP address, email subject and content, open and click logs, device and browser data, contact attributes uploaded by the customer.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets email

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.