GDPR compliance
MailingPlatform is built and operated in the European Union, and helping you comply with the General Data Protection Regulation (GDPR) is a core part of how the service works. This page explains the roles, the tools we give you, and the measures we take ourselves.
The service is owned and operated by CMC, Bredagervej 49, 2770 Kastrup, Denmark, VAT no. DK42289760. For any GDPR-related inquiry, contact support@mailingplatform.net.
Roles: controller and processor
For the personal data in your subscriber lists, you are the data controller and we act as your data processor. We process subscriber data only to provide the service and only on your instructions. For data about you as our customer (account, billing, support), we are the data controller - see our privacy policy.
How we help you comply
Consent. Signup forms support double opt-in, and form submissions are recorded with source and timestamp, so you can document when and how consent was given. Website tracking through our script can be gated behind consent.
Unsubscribe. Every marketing email sent through the platform contains a working unsubscribe link, including RFC 8058 one-click unsubscribe headers. Unsubscribes take effect immediately and cannot be circumvented.
Right of access and portability (articles 15 and 20). You can view all data associated with a subscriber in the app and export subscriber data as CSV, either from the app or via the API.
Right to rectification (article 16). Subscriber details can be edited at any time in the app or via the API.
Right to erasure (article 17). Individual subscribers can be deleted with one click, in bulk, or via a single API call. Deletion removes the subscriber's associated data across the platform.
Right to object (article 21). Unsubscribed and complained addresses are added to suppression, and suppression lists prevent accidental re-mailing - even if an address is re-imported later.
Technical and organisational measures
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Subscriber data is stored and processed in EU data centers
- Row-level security enforces tenant isolation at the database layer on every query
- Integration credentials and API keys are stored encrypted in a vault; API keys are stored as hashes and cannot be read back
- Unsubscribe and web-version links are cryptographically signed (HMAC-SHA256) so they cannot be forged or enumerated
- API access is scoped and revocable, following the principle of least privilege
- Sensitive operations are audit-logged
- Access to production systems is restricted and follows least privilege
Sub-processors
We use the following sub-processors to operate the service:
| Provider | Purpose | Location |
| Stripe | Payment processing | EU / United States |
| Amazon Web Services (SES) | Email delivery infrastructure | EU / United States |
| Supabase | Database and application hosting | EU |
| Cloudflare | Content delivery, DNS and security | EU / United States |
| OpenAI | AI-assisted support and features | United States |
We will inform customers before adding or replacing sub-processors that process subscriber data.
International data transfers
Subscriber data is stored in the EU. Where a sub-processor processes personal data outside the EU/EEA, transfers are safeguarded by an adequacy decision (including the EU-U.S. Data Privacy Framework where applicable) or the European Commission's standard contractual clauses.
Data retention
| Data | Retention |
| Subscriber and account data | For as long as your account is active |
| Deleted accounts | Deleted from production systems upon account deletion; encrypted backups expire automatically on a rolling basis |
| Data export files | Deleted automatically 7 days after creation |
| Invoices and accounting records | 5 years from the end of the financial year, as required by the Danish Bookkeeping Act |
Breach notification
If we become aware of a personal data breach affecting your subscriber data, we will notify you without undue delay and provide the information you need for your own notification to the supervisory authority, and we will assist with investigation and remediation.
Data processing agreement
A data processing agreement (DPA) covering the nature and purpose of processing, data categories, sub-processors, technical and organisational measures and breach notification is available on request. Contact support@mailingplatform.net.
Your responsibilities as controller
- Obtain and document a valid legal basis (such as consent) for your subscribers
- Provide clear privacy information to your subscribers
- Respond to data subject requests from your subscribers - the tools above make this fast
- Notify your supervisory authority of breaches where required
- Carry out data protection impact assessments where required