Privacy policy

1. Who we are and what this notice covers

The data controller is Everysoft S.r.l.s., registered office at Via San Giovanni Battista della Salle, 2 – 80136 Napoli (NA), Italy, VAT no. 09856651212, Naples Company Register – REA NA-1063019. SendApp is a trademark of Everysoft S.r.l.s.

This notice covers the data we process as controller: when you visit the sendapp.live website, write to us or fill in a form, create and manage a SendApp Agent account, ask for support, and when we invoice the service.

It does not cover the data that customers upload or manage in the SendApp Agent platform (contacts, conversations, files, data about their own customers). For that data the customer is the controller, or acts on behalf of its controller, and Everysoft processes it as a processor (Art. 28 GDPR) under the data processing agreement (DPA). For the cloud service, the platform privacy policy (app.sendapp.ai/privacy-policy) and the DPA (app.sendapp.ai/data-processing-agreement) apply.

2. How to contact us

For support and for any request about your personal data, write to info@sendapp.live. Please mention in the subject that it is a privacy request, so that we handle it through the dedicated procedure. The platform documents also show the company address, info@everysoft.me: you can use either.

3. What data we process

  • Browsing data: IP address, device and browser type, pages viewed, where the visit came from. Cookies and measurement tools are described in the cookie policy.
  • Data you send us through forms, chat or email: name, email, phone, company and the content of your request.
  • SendApp Agent account data: name, email, phone, company, login credentials and service usage data.
  • Billing data: company or personal name, address, VAT or tax number, amounts and payment history. Card details are processed directly by the payment providers and do not pass through our servers.
  • Data collected by SendApp Pixel on our website, only after your choice in the cookie banner: pages viewed, actions on the website, where the visit came from, device type, country.

4. Why we process it and on what legal basis

  • Answering your requests and preparing an offer or a demo: pre-contractual steps taken at your request (Art. 6(1)(b) GDPR).
  • Creating and managing the account, providing the service and support: performance of the contract (Art. 6(1)(b)).
  • Invoicing and tax and accounting obligations: legal obligation (Art. 6(1)(c)).
  • Security of the website and the service, prevention of abuse and fraud, defence of legal claims: legitimate interest (Art. 6(1)(f)).
  • Statistics on website use and measurement of our advertising campaigns with cookies and pixels: consent given in the banner (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code), as described in the cookie policy.
  • Marketing communications by email, WhatsApp or SMS: specific marketing consent (Art. 6(1)(a)), which you can withdraw at any time.

Cookie consent and consent to receive marketing communications are two separate things. Accepting statistics or advertising cookies in the banner does not allow us to write to you on WhatsApp, SMS or email. Only if you have also given marketing consent may we use the browsing data collected by SendApp Pixel to make those messages more relevant.

Providing the data needed for the account, the service and invoicing is necessary: without it we cannot provide the service. Everything else is optional.

5. How long we keep it

  • Requests sent through forms, chat or email: for as long as needed to handle them and any follow-up you asked for; then we delete or anonymise them, unless they are needed to protect our rights.
  • Account data: for the whole contractual relationship and, after it ends, for as long as needed to handle any disputes and to meet legal obligations.
  • Invoices and accounting records: for the period required by law (in Italy, as a rule, ten years).
  • Data processed on the basis of consent: until you withdraw consent, or earlier if no longer needed.
  • Cookies and measurement tools: for the durations stated in the cookie policy.

The expiry or cancellation of a plan does not by itself trigger automatic deletion of data. Deletion of data uploaded to the platform (deletion request with a 30-day procedure, deletion due within two years after the last renewal expires) is governed by the DPA and applies to the platform, not to this website.

6. Who we share it with

Providers that process data on our behalf as processors: hosting and infrastructure services, the email delivery service for the website forms (TurboSMTP), support and contact-management tools. They act on our instructions under a contract pursuant to Art. 28 GDPR.

Parties that process data under their own terms, as independent controllers: payment providers (Stripe, PayPal) for the activities they carry out in their own role, such as fraud prevention and anti-money-laundering obligations; Meta Platforms when we communicate with you on WhatsApp; the advertising platforms (Google, Meta, Microsoft, OpenAI) for the data collected by their tools on the website, under their own notices and as explained in the cookie policy.

Authorities and advisers (for example tax and legal advisers) where required by law or needed to protect a right.

We do not sell your personal data. The full, up-to-date list of providers, with the activities carried out, the data processed, the processing locations and the safeguards for transfers, is available on request at the address in section 2.

7. Transfers outside the European Economic Area

Some providers are established or process data outside the European Economic Area, mainly in the United States (for example Google, Meta, Microsoft, OpenAI, Stripe and PayPal). In those cases the transfer relies on an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework for certified companies, or on the Standard Contractual Clauses approved by the Commission. You can ask us about the safeguards applied and for a copy of the clauses at the address in section 2.

8. Your rights

You can ask for access to your data, rectification, erasure, restriction of processing and portability, and you can object to processing based on legitimate interest (Arts. 15-22 GDPR). You can object at any time to the use of your data for marketing and withdraw any consent already given, without affecting the lawfulness of processing carried out before the withdrawal.

Some rights are subject to conditions and limits set by law: for example, we cannot erase data we must keep for tax purposes. To exercise them, write to the address in section 2: we may ask for information to verify your identity. We reply without undue delay and normally within one month; where the request is complex or requests are numerous, this may be extended by two further months, in which case we tell you within the first month and explain why.

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the country where you live or work.

9. Changes to this notice

We may update this notice, for example when services or rules change. The version in force is published on this page with the last-updated date. If changes significantly affect platform customers, we also inform them through the means provided in the contract.

Last updated: 6 October 2026.