Privacy & GDPR

How Tratto handles data residency, analytics, and your rights under GDPR

Tratto is built on EU infrastructure by default, not retrofitted for compliance. This page covers what that means in practice, and what to expect if you're evaluating Tratto for a GDPR-sensitive workload.

EU-Native Infrastructure

Tratto runs on Google Cloud's EU region. Your data (contacts, email content, event logs) is stored and processed there, not exported to the US and synced back.

The Tratto marketing site loads no analytics scripts by default. Google Analytics 4 (via Google Tag Manager) only activates after a visitor explicitly accepts the cookie banner, and is configured to avoid collecting personally identifiable information.

One-Click Unsubscribe (RFC 8058)

Every email sent through Tratto carries List-Unsubscribe and List-Unsubscribe-Post headers, so mail clients that support one-click unsubscribe (Gmail, Outlook, and others) can act on it without a landing page. Unsubscribing moves a contact to unsubscribed status immediately: see Contacts for the API.

Unsubscribing suppresses future sends immediately. It does not delete the contact record: see below.

Italy's Data Protection Authority (Garante Privacy), Order No. 284 of 17 April 2026 (doc. web no. 10241943), sets out obligations for anyone using tracking pixels in email. If you send campaigns or flows through Tratto, three obligations apply to you as the sender:

  1. Clear, transparent notice: recipients must be told that opens and clicks are tracked.
  2. Free, specific consent: general newsletter sign-up consent isn't enough, tracking needs its own consent.
  3. Granular revocation: recipients must be able to withdraw tracking consent easily, without being forced to unsubscribe from everything.

What Tratto does technically: the open pixel (a transparent 1×1 GIF) and click tracking only fire for emails tied to a known contact (campaigns, flows), never for pure transactional sends like a password reset, where there's no engagement purpose to justify it. The open event never carries the recipient's address, only an internal identifier resolved server-side.

The notice and specific consent toward your own recipients are your responsibility, not Tratto's: you're the controller for your campaigns (see below). Tratto today offers a single opt-out mechanism, full list unsubscribe, not a separate "keep emailing me but stop tracking me" toggle. If that's a blocker for your compliance workflow, write to [email protected].

Controller vs. Processor

Who's responsible for a data subject request depends on who sent the email:

  • Tratto sent it directly: waitlist confirmations, account/product emails, our own marketing. Tratto is the data controller. See Data Subject Rights below.
  • A Tratto tenant sent it: a business using Tratto's API to send their own transactional or marketing email. Tratto is the data processor acting on that tenant's behalf; the tenant is the data controller for their own recipients. See If a Tenant Sent You an Email below.

If you're not sure which applies, check who the email is from: that's the controller.

Data Subject Rights (Tratto as Controller)

For emails Tratto sends directly (waitlist, account, our own marketing), you can request access to, rectification of, or deletion of your data by writing to [email protected].

If a Tenant Sent You an Email

If you received a transactional or marketing email sent by one of Tratto's customers through our API, Tratto processed that email on their behalf but does not control it: the sending business is the data controller and is responsible for honoring your access, rectification, or erasure request within the timeframe required by applicable law (GDPR: generally one month). Contact the sender directly, not Tratto.

Note for tenants: the Contacts API currently supports suppressing a contact (status: unsubscribed), not deleting the record: there's no self-service erasure endpoint yet. If one of your recipients submits a GDPR erasure request, Tratto doesn't yet give you a self-service way to fully purge that contact's data. Talk to us at [email protected] if this is a blocker for your compliance workflow.


Questions about a specific compliance requirement? Write to [email protected].


Edit this page on GitHub

Last updated on