Data residency
Recipient personal information processed by Thumela is stored and processed in South Africa. Transmission to recipients’ mail providers is inherent to delivery. AWS af-south-1 (Cape Town) is the sending sub-processor.
The processing path
- Your server calls the Thumela API.
- Thumela processes the request and stores message metadata in Johannesburg.
- Amazon SES in Cape Town sends the email; SNS/SQS in the same region carries delivery events.
- The recipient’s mail provider accepts the message and may process or store it outside South Africa.
Thumela does not control the last provider’s storage location. Local processing is a defined boundary, not a promise that an email never crosses a border.
What is stored
Recipient addresses are encrypted at rest. Message bodies remain in process memory for sending and retry. Message records and events are purged after 90 days; suppression entries remain to prevent later sends.
You remain responsible for the recipient data you put in your own application, logs and integrations.
Read the full residency statement and security statement for the current controls and limits. The privacy notice covers the launch waitlist.

