# Security & Compliance

> EU infrastructure we own in Prague, GDPR-ready data handling, roles, scoped API keys, two-factor authentication, passkeys and configurable data retention.

Secure by default. Private by design. EU infrastructure we own, GDPR-ready data handling and controls for every team: roles, scoped keys, two-factor authentication, passkeys and configurable retention.

## At a glance

- **EU** owned data center in Prague
- **GDPR** compliant, no third-party sending stack
- **2FA** TOTP, email codes and passkeys
- **1–365** day custom retention windows

## The right access for every teammate

Invite your team to as many workspaces as you need. Admins manage settings, members and billing. Members get to work on email without touching them.

- Admin and Member roles
- Invite codes that expire in 24 hours
- Separate workspaces per brand or client

## Keys with the least privilege

Create full-access or send-only API keys, lock them to a single sending domain, and regenerate them without changing anything else.

- Send-only scope for apps and agents
- Per-domain restrictions
- Last-used timestamps to spot stale keys

## Keep only what you need

Choose how long message contents, activity, logs and analytics are stored. Shorter windows mean less personal data at rest.

- Per data type windows
- Plan defaults that respect privacy
- Custom windows with the retention add-on

## Features

- **Passkeys**: Phishing-resistant sign-in with WebAuthn.
- **Two-factor authentication**: Authenticator apps with recovery codes.
- **Email codes**: One-time codes on every login without 2FA.
- **Workspaces**: Isolate brands, clients and environments.
- **Workspace verification**: New senders are reviewed before reaching the world.
- **Encrypted secrets**: Integration tokens are stored encrypted.

## FAQ

### Where is my data stored?

Emailit runs on infrastructure we own in a data center in Prague, Czech Republic, in the European Union. We do not resell a third-party sending service.

### Is Emailit GDPR compliant?

Yes. We act as a processor for your recipient data, keep it in the EU and give you retention controls to minimize what is stored. A data processing agreement is available on request.

### How long do you keep my data?

Defaults depend on your plan: message contents for 7 to 30 days, activity for 30 to 365 days and logs for 7 to 30 days. The Data Retention add-on lets you set custom windows from 1 to 365 days.

## Links

- Documentation: https://emailit.com/docs/security/
- Pricing: https://emailit.com/pricing/
- Sign up: https://dash.emailit.com/register

---

Source: https://emailit.com/products/security/
