StackLégal

Email

GDPR Resend

For “GDPR Resend”, Plus Five Five, Inc. is the processor of email data, and an independent controller for the account, billing, and service usage. The DPA places the primary operations and storage in the United States. The “Resend” participant has status Active - Re-certification under Review.

In an indie stack, Resend is used for Transactional emails. Entity cited: Plus Five Five, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Resend

Yes. Public DPA.

Read the DPA

Stated role

Processor of the customer's email data. Independent controller for account, billing, and service-usage data.

Personal data

Email, first name and last name, postal address, IP address and usage data, cookies, message metadata and content, recipient name and attachments, open and click tracking data (device, browser, location).

Sub-processors of Resend

Public list.

List published by the vendor

Transfers outside the EU

Hosting / location

The DPA states that the primary processing operations are in the United States. Stored data is stored in the United States.

EU–United States Data Privacy Framework

The participant “Resend”, legal name PLUS FIVE FIVE, is registered. Exact EU-U.S. Data Privacy Framework status: Active - Re-certification under Review.

Data Privacy Framework sheet

Cookies

Resend states that it uses only essential cookies, including Supabase login cookies, plus Stripe cookies for payment and fraud prevention.

Typical use, written by StackLégal and not by the vendor: Transactional emails.

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Resend a processor within the meaning of the GDPR?

Processor of the customer's email data. Independent controller for account, billing, and service-usage data.

What DPA does Resend publish?

Yes. Public DPA. https://resend.com/legal/dpa

Which further sub-processors does Resend publish?

Public list. https://resend.com/legal/subprocessors

Where does Resend state that it processes data, including outside the EU?

The DPA states that the primary processing operations are in the United States. Stored data is stored in the United States.

Is Resend registered under the EU–United States Data Privacy Framework?

The participant “Resend”, legal name PLUS FIVE FIVE, is registered. Exact EU-U.S. Data Privacy Framework status: Active - Re-certification under Review. https://www.dataprivacyframework.gov/participant/8907

Which personal data does Resend mention?

Email, first name and last name, postal address, IP address and usage data, cookies, message metadata and content, recipient name and attachments, open and click tracking data (device, browser, location).

Stacks that cite Resend

These pages assemble the sheets of a common stack and state what to write in the privacy policy.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets email

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.