Skip to content

GDPR compliance

How the platform helps you send messages lawfully

Updated on August 5, 2026

Sending SMS messages to individuals falls under the GDPR and under the rules on commercial communications. This page explains what your obligations are and what the platform gives you to meet them.

Who is responsible for what

For the contacts you upload, you are the data controller and we are the processor. That means you decide who receives messages and on what legal basis, while we carry out the sending and provide the technical means to stay compliant.

The basis for sending

Before sending a commercial message you need the recipient’s consent, obtained clearly and separately, or an existing contractual relationship. A reminder for an appointment the client made themselves is sent in performance of the contract, which is a distinct basis from marketing.

Consent must be provable: who gave it, when, and for what.

What the platform provides

  • Unsubscribe registry. A recipient who replies STOP is excluded from your sending automatically and permanently.
  • Consent records on each contact, with the date it was registered.
  • Export and erasure per contact, for access or deletion requests from data subjects.
  • Quiet hours, so messages never arrive at night.
  • Sending history, showing what was sent, to whom, and when.

What remains your responsibility

  • Collecting consent properly and being able to prove it.
  • Including the sender identity and an unsubscribe route in commercial messages.
  • Not using lists for a purpose other than the one they were collected for.
  • Answering data subject requests within the legal deadlines.

Sub-processors

We use a mobile network operator for actual message delivery. The list of providers involved and the data processing agreement are available on request at contact@bdcdesign.ro.