Wennov Connect
Security and compliance
Enterprise-grade control for identity, access, and audit.
Security and compliance you can verify
Access control, encryption, an audit trail and GDPR tooling — documented, not just promised.
Sending messages means processing your customers personal data. We built the platform on the assumption that you must be able to show an auditor who had access, what they changed and how long we keep data — not merely trust that everything is fine.
Access control
- Granular roles and permissions, per feature rather than just admin or user
- Two-factor authentication (2FA), which can be enforced for sensitive operations
- SSO and automatic user provisioning through SCIM for enterprise accounts
- IP allowlisting, separately for the dashboard and for API keys
- API keys with scopes, an expiry date and rotation without interrupting traffic
- A sign-in log with IP, browser and approximate location, plus an alert on login from a new address
- Active sessions visible and individually revocable
- An immutable audit log for every administrative action
Data protection
Data is encrypted in transit over TLS. Storage infrastructure uses full-disk encryption, and the most sensitive values — messaging provider credentials, SMTP passwords and DKIM private keys — carry an additional application-level AES-256 encryption layer. Passwords are stored as hashes and cannot be recovered. API keys and credentials are never written to logs. Infrastructure is hosted in the European Union, and transfers outside the European Economic Area rely on Standard Contractual Clauses.
GDPR compliance
The controller and processor distinction is handled explicitly: for your account data we are the controller, while for the contacts you upload you are the controller and we act as processor on your instructions. We provide a Data Processing Agreement (DPA) and the subprocessor list, with the purpose and location of each. Data subject requests — access, rectification, erasure, portability — are honoured within 30 days, and customers can export their data themselves at any time. Retention periods are published explicitly: campaign messages 60 days, direct messages 30 days, delivery events up to 90 days, audit logs 365 days.
Operational resilience
Message routing includes rate limits, circuit breakers that isolate a degraded provider, and automatic failover to an alternative route. Failed sends are visible in a dedicated queue with the reason for rejection and the option to replay them. Platform status and incidents are published on the status page.
Frequently asked questions
Where is data stored?
On infrastructure hosted in the European Union. For enterprise accounts, specific data residency requirements can be discussed.
Can you sign a DPA?
Yes. The Data Processing Agreement is available on request and covers responsibilities for security, confidentiality, subprocessors and data subject rights. Contact us for the signable version.
What happens to my data if I close the account?
Full account deletion is available in settings and becomes irreversible after 30 days, a window in which you can still change your mind. Billing documents are retained for 10 years as a tax obligation that an erasure request cannot override.
Can I enforce 2FA for the whole team?
Yes. 2FA can be enforced at account level, and sensitive operations can require an additional confirmation even from users who are already signed in.
How do I find out if someone changed an important setting?
The audit log records every administrative action with the user, the time and the changed value. It is retained for 365 days and can be exported.
What do you do to prevent abusive sending?
The platform applies rate limits, fraud-protection rules for OTP codes, and an acceptable use policy that spells out prohibited content and consent rules. Violations lead to sending being suspended.
Request the security documentation
We will send the DPA, the subprocessor list and the configuration details your technical team needs.
Contact usContact
Tell us your use case and we will recommend the best setup.
Email: office@wennov.ro
Phone: +40 731 177 744
Location: București, România