Data Residency & Governance
Last updated: 26 June 2026
This statement describes how and where Embue stores and governs data. It supports our sender accreditation and the due-diligence expectations of care-sector organisations.
1. Data residency
All personal data we hold is stored and processed in the **United Kingdom**. Our infrastructure runs on Amazon Web Services in the **Europe (London) region (`eu-west-2`)**, and our email is delivered through Amazon SES in the same UK region. We chose a UK region deliberately, to keep subscriber and consent data within the UK.
2. Our infrastructure
Embue runs a **self-hosted application stack** on our own UK cloud infrastructure:
- **Content management** (articles, sections, pages) — Strapi, self-hosted.
- **Email list management and campaigns** — Listmonk, self-hosted. Subscriber lists, consent records and sending all run on our own infrastructure, not a third-party marketing platform.
- **Database** — PostgreSQL, hosted in the UK region.
- **Email transmission** — Amazon SES (UK region), sending from our authenticated domain `ukmail.networkembu.com`.
Reader-facing and email-sending systems are deployed on separate hosts so that bulk sending cannot affect the responsiveness of the website.
3. Sub-processors
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Amazon Web Services | Hosting and infrastructure | UK (London) | UK-region processing; AWS Data Processing Addendum |
| Amazon SES | Email delivery | UK (London) | As above |
| PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A.) | Payment processing | Luxembourg / EU; may process internationally | PayPal data-processing terms incorporating the UK International Data Transfer Addendum |
| Google (Google Analytics) | Website analytics, consent-gated | USA / global | Google Ads Data Processing Terms; UK International Data Transfer Addendum / Standard Contractual Clauses |
We maintain this list and update it when our processors change.
4. International transfers
Our default position is that personal data does **not** leave the UK. There are two limited exceptions:
- **Payment** — our payment provider, **PayPal** (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg), processes payment data in the EU and may process it internationally.
- **Website analytics** — where a visitor consents to analytics, **Google Analytics (GA4)** may process that data outside the UK, including in the United States. Analytics are loaded only after consent and can be declined.
Where data leaves the UK under either exception, the transfer is governed by the provider's data-processing terms, which incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. All other personal data remains in the UK.
5. Security measures
- Encryption of data in transit (TLS) and at rest where supported by the platform.
- Passwords stored only as salted hashes.
- Role-based access control; access to personal data limited to those who need it.
- Network isolation between public and administrative systems; administrative interfaces are not exposed to the public internet.
- Regular patching of the application stack and underlying infrastructure.
6. Data-breach procedure
If a personal-data breach occurs that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office without undue delay and, where required, within 72 hours of becoming aware, and we will inform affected individuals where the law requires.
7. Email-sending governance
We operate permission-based sending with full domain authentication — **SPF, DKIM and DMARC** are configured on our sending domain. Each kind of email rests on its proper basis: the **subscription digest** is a service message to paying subscribers; **optional newsletters** are sent only on **explicit opt-in**; and any **marketing to prospective customers** relies on the PECR **soft opt-in** with a clear opt-out (and an opt-out basis for business contacts). We honour unsubscribes immediately and automatically suppress addresses that bounce or complain; bounce and complaint feedback is captured and fed into our suppression list. This governance underpins our deliverability and our compliance with PECR and UK GDPR. See our Acceptable Use & Anti-Spam Policy.
8. Contact
Data-governance enquiries: **privacy@networkembu.com** · **EMBUE Group Limited**, **20-22 Wenlock Road, London, N1 7GU**.