Skip to main content

GDPR Compliance

If any of your recipients are located in the European Union — for example diaspora customers, EU-based staff, or travelers — your messaging falls under the EU General Data Protection Regulation (GDPR), regardless of where your business is based. AfriRoute is built to support GDPR compliance for these flows alongside African data protection laws.

How AfriRoute Supports GDPR​

GDPR PrincipleHow AfriRoute Helps
Lawful basis (Art. 6)Consent capture and enforcement at send time
Data minimization (Art. 5)Store only the fields needed to deliver; PII redaction in logs
Right to access (Art. 15)Contact + message-history export API
Right to erasure (Art. 17)Hard-delete endpoint for contacts and history
Security (Art. 32)TLS in transit, AES-256 at rest, ISO 27001 / SOC 2
Breach notification (Art. 33)Customer notification within 72 hours of a confirmed breach
International transfers (Ch. V)EU data region in Frankfurt; SCCs in our DPA

Controller vs Processor​

Under GDPR, you are the data controller and AfriRoute is the data processor. We process EU personal data only on your documented instructions. Our Data Processing Addendum incorporates the European Commission's Standard Contractual Clauses (SCCs) for any transfer of EU data outside the EEA.

Request the signed DPA from [email protected].

For marketing to EU residents you almost always need explicit, opt-in consent under the ePrivacy Directive. Record it and let AfriRoute enforce it:

curl -X POST https://api.afriroute.ai/api/v1/contacts \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"phone": "+353871234567",
"region": "EU",
"consent": {
"marketing": true,
"source": "double_opt_in_email",
"captured_at": "2026-05-15T12:00:00Z"
}
}'

Promotional sends to EU contacts without recorded consent are rejected with CONSENT_REQUIRED.

Right of Access​

Export everything AfriRoute holds about a data subject:

curl "https://api.afriroute.ai/api/v1/contacts/+353871234567/export" \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"
{
"phone": "+353871234567",
"consent": { "marketing": true, "captured_at": "2026-05-15T12:00:00Z" },
"messages": [
{ "message_id": "msg_001", "sent_at": "2026-05-16T09:00:00Z", "status": "delivered" }
],
"generated_at": "2026-05-28T10:00:00Z"
}

Right to Erasure​

curl -X DELETE https://api.afriroute.ai/api/v1/contacts/+353871234567/data \
-H "Authorization: Bearer $AFRIROUTE_API_KEY"

PII is hard-deleted; only anonymized aggregate records required for accounting are retained.

Data Residency for EU Subjects​

Pin EU personal data to the Frankfurt region so it is stored and processed within the EEA:

curl -X PATCH https://api.afriroute.ai/api/v1/settings/data-residency \
-H "Authorization: Bearer $AFRIROUTE_API_KEY" \
-d '{ "eu_subjects_region": "eu-frankfurt" }'

Sub-processors​

AfriRoute uses a limited set of carrier and infrastructure sub-processors. The current list is published at afriroute.ai/legal/subprocessors; customers are notified before any addition.

Your GDPR Checklist​

  1. Sign the AfriRoute DPA (includes SCCs).
  2. Capture explicit consent for EU marketing and store it.
  3. Enable EU data residency.
  4. Wire up access and erasure requests to the export and delete endpoints.
  5. Maintain your own Record of Processing Activities (RoPA).

GDPR questions? [email protected]

Last Updated: May 2026