Controller. NetConsult FZCO, Building: Techno Hub 1, IFZA Properties, Unit D-08, Floor L2, Dubai, United Arab Emirates (“NetConsult”, “we”, “us”). SendWise is a product of NetConsult.
Effective date: 20 July 2026.
1. Scope
This Policy applies to the SendWise website, the SendWise web application, and the related APIs and services (together, the “Service”). SendWise is intended for users aged 18 or over; the Service is not directed to children under 18 and we do not knowingly collect personal data from them.
2. Information we collect
- Account information: name, email address, organization, password hash, and preferences you provide when you register or update your profile.
- Sender-account information: the authorization tokens, refresh tokens, SMTP credentials, and metadata (such as the connected email address and provider) that you provide when you connect a Gmail, Microsoft, or SMTP sender.
- Contacts and campaign data: contact lists, contact fields, message content, templates, schedules, sender configuration, engagement events (opens, clicks, bounces, complaints, replies), and related analytics you generate in the Service.
- Billing information: plan, invoices, and payment metadata. Card details are handled by our payment processor and are not stored by SendWise.
- Support and communications: messages, attachments, and metadata you send to us via email or the Contact page.
- Technical information: IP address, device and browser information, log data, timestamps, and diagnostic information used for security, abuse prevention, and reliability.
- Cookies and similar technologies: strictly necessary cookies for authentication and session management, and limited first-party analytics (NetConsult Web Analytics at wa.netconsult.ae) plus optional Microsoft Clarity session replay after you accept the cookie banner — used only to understand aggregate usage and improve the product. Analytics cookies are not set before you choose Accept on the banner.
3. Google user data and Gmail API
When you connect a Google account, SendWise requests only the OAuth scopes required to operate the features you enable, including the gmail.send scope, which allows SendWise to send email on your behalf from the Gmail account you connected.
Access. SendWise accesses your Google account only through Google OAuth, using the scopes you explicitly grant during the connection flow. We do not read, list, modify, or delete messages in your mailbox.
Use. Google user data obtained through the Gmail API is used solely to provide user-facing SendWise features that you have configured — specifically, sending campaign, sequence, and transactional messages you have created from the Gmail account you connected, and displaying the connection status of that account inside SendWise.
Storage. SendWise stores the OAuth access token and refresh token issued by Google for your connected account, together with metadata such as the connected email address, the granted scopes, and the connection status. Tokens are stored encrypted at rest and are transmitted only over TLS.
Sharing. SendWise does not sell, rent, or transfer Google user data to third parties, does not use Google user data for advertising, and does not use Google user data to train generalized or third-party AI or machine-learning models. Google user data is disclosed only: (i) to sub-processors that provide the infrastructure used to operate the Service under confidentiality obligations; (ii) to comply with applicable law or a valid legal request; or (iii) with your explicit consent.
Protection. Access to Google user data is restricted to a limited number of authorized personnel, is logged, and is protected by encryption in transit and at rest, environment isolation, and access controls.
Retention. SendWise retains Google OAuth tokens and connection metadata for as long as the connection is active. If you disconnect the Google account in SendWise, revoke access at myaccount.google.com/permissions, or delete your SendWise account, the associated OAuth tokens are deleted from active systems within thirty (30) days, subject to backup rotation described in Section 9.
Deletion. You can disconnect a Google sender at any time from the Senders section of SendWise, or by revoking access via your Google account. Deletion of your SendWise account triggers deletion of associated Google OAuth tokens as described above.
Limited Use. SendWise’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Microsoft and SMTP sender accounts
When you connect a Microsoft account, SendWise requests only the OAuth scopes required to send email on your behalf from the connected mailbox. When you connect an SMTP sender, SendWise stores the host, port, username, and password you provide, encrypted at rest and used only to relay messages you send through the Service. You can disconnect these senders at any time from the Senders section of SendWise.
5. How we use information
- To provide, operate, secure, and improve the Service.
- To send campaign, sequence, and transactional messages you configure.
- To authenticate users and protect against fraud, abuse, and unauthorized access.
- To send service, security, and billing communications relating to your account.
- To provide customer support and respond to your enquiries.
- To comply with legal, tax, and regulatory obligations.
SendWise does not sell personal data, does not use your contacts or campaign content for advertising, and does not use your Google user data to train generalized or third-party AI/ML models.
6. Legal bases (where applicable)
Where local law requires a legal basis for processing, we rely on: performance of the contract with you, our legitimate interests in operating and securing the Service, compliance with legal obligations, and, where required, your consent (which you may withdraw at any time).
7. Sharing and sub-processors
SendWise shares personal data only with the following categories of recipients, under appropriate confidentiality and data-protection obligations:
- Infrastructure and hosting providers that host the Service and store data.
- Email sender providers you connect (Google, Microsoft, or your SMTP host), which transmit the messages you send.
- Payment processors that handle billing on our behalf.
- Support, analytics, and error-monitoring tools used to operate the Service.
- Legal, regulatory, or governmental authorities where required by applicable law or valid legal process.
8. International transfers
SendWise operates from the United Arab Emirates and uses sub-processors that may process data in other jurisdictions. Where required, we rely on appropriate transfer mechanisms permitted by applicable law.
9. Retention and deletion
We retain account, campaign, and analytics data for as long as your account is active and as needed to provide the Service. When you delete your account, associated personal data (including sender OAuth tokens and SMTP credentials) is deleted from active systems within thirty (30) days, and from routine encrypted backups within ninety (90) days, except where retention is required by law or for the establishment, exercise, or defence of legal claims. You may request deletion at any time by contacting privacy@netconsult.ae.
10. Security
We apply appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS) and at rest for credentials and OAuth tokens, access controls, environment isolation, least-privilege administration, audit logging, and regular review of security practices. No system is perfectly secure, and you are responsible for the security of your own account credentials.
11. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on consent. To exercise any of these rights, contact privacy@netconsult.ae. You may also lodge a complaint with a competent supervisory authority.
12. Children
The Service is intended for users aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact privacy@netconsult.ae and we will take appropriate steps.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Service or by email. The “Last updated” date at the top of this page indicates when this Policy was last revised.
14. Contact
For privacy questions, requests, or complaints, contact us at privacy@netconsult.ae. Postal address: NetConsult FZCO, Building: Techno Hub 1, IFZA Properties, Unit D-08, Floor L2, Dubai, United Arab Emirates.
