No permanent contact database, no shared spreadsheets, no data left behind once a campaign is sent. Here's exactly how that works.
A contact file is only ever uploaded at the moment an employee is actively sending a campaign — never in advance, never "just in case."
Uploads travel over encrypted connections to our processing layer, where they're validated and matched against the active campaign only.
Contacts are used to send that one campaign's card — never for any other purpose, never combined with another employee's list.
Once a campaign finishes sending, the uploaded file and every parsed contact row are permanently deleted. Only aggregate statistics remain.
Corporate Comms manages campaigns and templates; employees can only send, not administer.
HR sees participation and delivery stats for the whole company — never individual contact lists.
Every campaign records who sent, when, and how many recipients — without storing who those recipients were.
Every send is tied to a verified work email, so campaigns can't be triggered by anyone outside the company.
Uploaded files are processed transiently to send the active campaign, then permanently deleted — they are not archived or backed up long-term.
No. HR and admins only ever see aggregate campaign statistics, never individual recipient data.
Any uploaded contact data tied to that campaign is deleted the same way as a completed send.
Yes, uploads and transfers use encrypted connections. Once processing completes, the underlying data no longer exists to protect.
We're happy to walk through the architecture in more detail.
Request Pricing →