m
    MailingPlatform
    PlatformDeliverabilityPricingSecurity & GDPR
    Sign inStart free →
    PlatformDeliverabilityPricingSecurity & GDPR
    Sign inStart free →
    Legal

    GDPR compliance

    Version 2.0Updated July 25, 2026

    MailingPlatform is built and operated in the European Union, and helping you comply with the General Data Protection Regulation (GDPR) is a core part of how the service works. This page explains the roles, the tools we give you, and the measures we take ourselves.

    The service is owned and operated by CMC, Bredagervej 49, 2770 Kastrup, Denmark, VAT no. DK42289760. For any GDPR-related inquiry, contact support@mailingplatform.net.

    Roles: controller and processor

    For the personal data in your subscriber lists, you are the data controller and we act as your data processor. We process subscriber data only to provide the service and only on your instructions. For data about you as our customer (account, billing, support), we are the data controller - see our privacy policy.

    How we help you comply

    Consent. Signup forms support double opt-in, and form submissions are recorded with source and timestamp, so you can document when and how consent was given. Website tracking through our script can be gated behind consent.

    Unsubscribe. Every marketing email sent through the platform contains a working unsubscribe link, including RFC 8058 one-click unsubscribe headers. Unsubscribes take effect immediately and cannot be circumvented.

    Right of access and portability (articles 15 and 20). You can view all data associated with a subscriber in the app and export subscriber data as CSV, either from the app or via the API.

    Right to rectification (article 16). Subscriber details can be edited at any time in the app or via the API.

    Right to erasure (article 17). Individual subscribers can be deleted with one click, in bulk, or via a single API call. Deletion removes the subscriber's associated data across the platform.

    Right to object (article 21). Unsubscribed and complained addresses are added to suppression, and suppression lists prevent accidental re-mailing - even if an address is re-imported later.

    Technical and organisational measures

    • All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
    • Subscriber data is stored and processed in EU data centers
    • Row-level security enforces tenant isolation at the database layer on every query
    • Integration credentials and API keys are stored encrypted in a vault; API keys are stored as hashes and cannot be read back
    • Unsubscribe and web-version links are cryptographically signed (HMAC-SHA256) so they cannot be forged or enumerated
    • API access is scoped and revocable, following the principle of least privilege
    • Sensitive operations are audit-logged
    • Access to production systems is restricted and follows least privilege

    Sub-processors

    We use the following sub-processors to operate the service:

    ProviderPurposeLocation
    StripePayment processingEU / United States
    Amazon Web Services (SES)Email delivery infrastructureEU / United States
    SupabaseDatabase and application hostingEU
    CloudflareContent delivery, DNS and securityEU / United States
    OpenAIAI-assisted support and featuresUnited States

    We will inform customers before adding or replacing sub-processors that process subscriber data.

    International data transfers

    Subscriber data is stored in the EU. Where a sub-processor processes personal data outside the EU/EEA, transfers are safeguarded by an adequacy decision (including the EU-U.S. Data Privacy Framework where applicable) or the European Commission's standard contractual clauses.

    Data retention

    DataRetention
    Subscriber and account dataFor as long as your account is active
    Deleted accountsDeleted from production systems upon account deletion; encrypted backups expire automatically on a rolling basis
    Data export filesDeleted automatically 7 days after creation
    Invoices and accounting records5 years from the end of the financial year, as required by the Danish Bookkeeping Act

    Breach notification

    If we become aware of a personal data breach affecting your subscriber data, we will notify you without undue delay and provide the information you need for your own notification to the supervisory authority, and we will assist with investigation and remediation.

    Data processing agreement

    A data processing agreement (DPA) covering the nature and purpose of processing, data categories, sub-processors, technical and organisational measures and breach notification is available on request. Contact support@mailingplatform.net.

    Your responsibilities as controller

    • Obtain and document a valid legal basis (such as consent) for your subscribers
    • Provide clear privacy information to your subscribers
    • Respond to data subject requests from your subscribers - the tools above make this fast
    • Notify your supervisory authority of breaches where required
    • Carry out data protection impact assessments where required

    Related pages

    • Privacy policy
    • Security policy
    • Cookie policy
    • Terms & conditions
    m
    MailingPlatform

    Email & automation for commerce, on infrastructure you don't have to think about.

    Product
    PlatformDeliverabilityPricingStart free
    Solutions
    Shopify storesWooCommerceNewsletters
    Compare
    Switch from KlaviyoSwitch from MailchimpSwitch from ActiveCampaignSwitch from OmnisendSwitch from BrevoSwitch from MailerLite
    Resources
    BlogHelp centerAPI docsDeliverability guideSupportSign in
    Company
    Security & GDPRPrivacy policyTerms of serviceData processing
    © 2026 MailingPlatform. Built and hosted in the EU.
    GDPR READYEU DATARFC 8058