GDPR SendGrid
In an indie stack, SendGrid is used for Transactional and marketing emails (Twilio). Entity cited: Twilio Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA SendGrid
Yes. Twilio Data Protection Addendum, which covers SendGrid.
Stated role
Processor or sub-processor of the customer's personal data, and independent controller for specified purposes of account, communications usage, and customer content.
Personal data
Account data, communications-usage data, customer content (body, subjects, recipients), sender and recipient information, deliverability, open, and bounce metadata, IP address, browser, system, and general location, payment information.
Sub-processors of SendGrid
Public Twilio list, with SendGrid rows.
Transfers outside the EU
Hosting / location
The Twilio sub-processor list places SendGrid routing and transmission on AWS in the United States and in the EU, marketing-campaign storage on AWS and Snowflake in the United States, and hosting at DataBank and Lumen in North America and Digital Realty in North America and in the EU.
EU–United States Data Privacy Framework
Twilio Inc. is registered. EU-U.S. Data Privacy Framework status: Active.
Cookies
The Twilio policy states that the SendGrid services collect engagement data via web beacons in emails (delivery, open, click, bounce, spam). Names of cookies set on a customer site: not disclosed.
Typical use, written by StackLégal and not by the vendor: Transactional and marketing emails (Twilio).
History
Last update: October 4, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is SendGrid a processor within the meaning of the GDPR?
Processor or sub-processor of the customer's personal data, and independent controller for specified purposes of account, communications usage, and customer content.
What DPA does SendGrid publish?
Yes. Twilio Data Protection Addendum, which covers SendGrid. https://www.twilio.com/en-us/legal/data-protection-addendum
Which further sub-processors does SendGrid publish?
Public Twilio list, with SendGrid rows. https://www.twilio.com/en-us/legal/sub-processors
Where does SendGrid state that it processes data, including outside the EU?
The Twilio sub-processor list places SendGrid routing and transmission on AWS in the United States and in the EU, marketing-campaign storage on AWS and Snowflake in the United States, and hosting at DataBank and Lumen in North America and Digital Realty in North America and in the EU.
Is SendGrid registered under the EU–United States Data Privacy Framework?
Twilio Inc. is registered. EU-U.S. Data Privacy Framework status: Active. https://www.dataprivacyframework.gov/participant/5394
Which personal data does SendGrid mention?
Account data, communications-usage data, customer content (body, subjects, recipients), sender and recipient information, deliverability, open, and bounce metadata, IP address, browser, system, and general location, payment information.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.