Data processing agreement
This data processing agreement ("DPA") forms part of the terms & conditions (the "terms") between CMC, Bredagervej 49, 2770 Kastrup, Denmark, CVR 42289760 ("MailingPlatform", "we", "us") and the customer who has created an account for the MailingPlatform service (the "customer", "you"). It sets out the terms on which we process personal data on your behalf, as required by article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
This DPA applies automatically to every customer account and does not need to be signed to take effect. If you need a countersigned copy for your records, contact support@mailingplatform.net. In case of conflict between this DPA and the terms, this DPA prevails with respect to the processing of personal data.
1. Definitions
"Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
"Customer data" means the personal data that you upload to, collect through or otherwise make available in the service, including data about your subscribers, contacts and customers.
"Sub-processor" means a third party engaged by us to process customer data on our behalf.
"Service" means the MailingPlatform email marketing and automation service available at mailingplatform.net and app.mailingplatform.net, including its API and integrations.
2. Roles of the parties
For customer data, you are the controller and we are the processor. You decide which personal data is collected, on what legal basis, and for which purposes. We process customer data only to provide the service and only on your documented instructions.
For data about you as our customer (account, billing, support and usage data), we are the controller. That processing is described in our privacy policy and is not covered by this DPA.
3. Details of the processing
| Subject matter | Provision of the service: storing subscriber data, sending emails on your behalf, tracking delivery and engagement, running automations and segments, and syncing data with the e-commerce platforms you connect |
| Duration | For as long as you have an account, plus the deletion period in section 12 |
| Nature and purpose | Hosting, storage, transmission by email, analysis of delivery and engagement events, segmentation, automation and export, all in order to deliver email marketing and related services to you |
| Categories of data subjects | Your subscribers, newsletter recipients, website visitors and customers, and other individuals whose personal data you choose to process in the service |
| Categories of personal data | Name, email address, phone number, language, country and other profile fields you add; subscription status and consent records (source, timestamp, IP address); email delivery and engagement events (sent, delivered, bounced, opened, clicked, unsubscribed, complained); order, cart and browsing data synced from your connected store; tags, segments and custom fields |
| Special categories of data | None. You agree not to use the service to process special categories of personal data (article 9 GDPR) or data relating to criminal convictions (article 10 GDPR) |
4. Your instructions
We process customer data only on your documented instructions, including with regard to transfers to a third country, unless we are required to do so by EU or member state law that applies to us. In that case we will inform you of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
Your instructions are given through the terms, this DPA and your use of the service (for example when you import subscribers, create a campaign, configure an automation or call the API). Additional instructions can be agreed in writing. We will inform you if, in our opinion, an instruction infringes the GDPR or other EU or member state data protection law; we are not obliged to carry out a legal assessment on your behalf.
5. Confidentiality
We ensure that persons authorised to process customer data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to customer data is limited to personnel who need it to provide, support or secure the service, and follows the principle of least privilege.
6. Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by article 32 GDPR. The measures in force at the date of this DPA are described in annex 2 and in our security policy.
We may update these measures over time, provided that the overall level of protection is not reduced.
7. Sub-processors
You give us general authorisation to engage sub-processors for the processing of customer data. The sub-processors engaged at the date of this DPA are listed in annex 3, together with their purpose and location.
Before we add or replace a sub-processor that processes customer data, we will inform you at least 30 days in advance by email or in-app notification. You may object on reasonable, documented data protection grounds within that period. If we cannot address your objection, you may terminate your subscription before the change takes effect. Termination on this ground is your sole remedy, and neither party has further claims arising from the change.
We impose data protection obligations on each sub-processor by written contract that are no less protective than those in this DPA. We remain fully liable to you for the performance of a sub-processor's obligations.
8. Assistance to the controller
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects. The service lets you look up, edit, export and delete individual subscribers, in bulk and via the API, and every marketing email includes a working unsubscribe mechanism, including RFC 8058 one-click unsubscribe headers.
If a data subject contacts us directly about customer data, we will not respond on the substance but will refer the data subject to you and inform you of the request without undue delay.
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation). We may charge a reasonable fee for assistance that goes beyond the standard functionality of the service.
9. Personal data breach
If we become aware of a personal data breach affecting customer data, we will notify you without undue delay after becoming aware of it. The notification will, to the extent known at the time, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where it is not possible to provide all information at once, it will be provided in phases without undue further delay.
We will cooperate with you and take reasonable steps to assist in the investigation, mitigation and remediation of the breach. The notification is sent to the account owner's email address; you are responsible for keeping it up to date.
10. International transfers
Customer data is stored and processed in data centres in the European Union. Where a sub-processor processes customer data outside the EU/EEA, the transfer is safeguarded by an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework where the recipient is certified) or by the European Commission's standard contractual clauses, together with supplementary measures where required.
11. Audits and information
We make available to you all information necessary to demonstrate compliance with the obligations in this DPA and article 28 GDPR. In the first instance we do this through our published documentation, this DPA, our security policy and written answers to your reasonable questions.
Where this is not sufficient to demonstrate compliance, you or an independent auditor mandated by you and bound by confidentiality may audit our processing of customer data. Audits are limited to once per 12 months unless required by a supervisory authority or following a personal data breach, require at least 30 days written notice, take place during normal business hours, must not unreasonably disrupt our operations or compromise the security of other customers' data, and are conducted at your expense. We will contribute to audits by providing relevant information and access to relevant personnel.
12. Deletion and return of customer data
You can export customer data at any time from the app or via the API. When you delete a subscriber, the subscriber's associated data is removed across the service.
When your account is deleted, whether by you or by us in accordance with the terms, we delete customer data from our production systems. Residual copies in encrypted backups expire automatically on a rolling basis and are not restored to production except to recover from a service failure. We may retain customer data to the extent required by EU or member state law, in which case we continue to protect it under this DPA and process it for no other purpose.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the terms. Nothing in this DPA limits either party's liability towards data subjects or supervisory authorities under the GDPR.
14. Term and termination
This DPA takes effect when you accept the terms or start using the service and remains in force for as long as we process customer data on your behalf. Sections 5, 12 and 13 survive termination.
15. Changes to this DPA
We may update this DPA to reflect changes in law, in the service or in our sub-processors. If we make material changes, we will notify you by email or in-app notification at least 30 days before they take effect. The current version is always available at mailingplatform.net/dpa.
16. Governing law and venue
This DPA is governed by Danish law. Any dispute arising out of or in connection with this DPA shall be brought before the Danish courts, with the City Court of Copenhagen as the agreed venue of first instance, unless mandatory law provides otherwise.
Annex 1: contact details
| Processor | CMC, Bredagervej 49, 2770 Kastrup, Denmark, CVR 42289760 |
| Data protection contact | support@mailingplatform.net |
| Controller | The customer identified by the account details in the service. Notifications under this DPA are sent to the account owner's email address |
Annex 2: technical and organisational measures
- All data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256)
- Customer data is stored and processed in EU data centres
- Row-level security enforces tenant isolation at the database layer on every query
- Integration credentials and API keys are stored encrypted in a vault; API keys are stored as hashes and cannot be read back
- Unsubscribe, tracking and web-version links are cryptographically signed (HMAC-SHA256) so they cannot be forged or enumerated
- API access is scoped and revocable, following the principle of least privilege
- Access to production systems is restricted to authorised personnel and follows least privilege
- Sensitive operations are audit-logged
- Encrypted backups are taken automatically and expire on a rolling basis
- Deployments go through version control and automated checks; secrets are never stored in source code
- Personnel with access to customer data are bound by confidentiality obligations
Annex 3: sub-processors
| Provider | Purpose | Location |
| Amazon Web Services (SES) | Email delivery infrastructure | EU / United States |
| Supabase | Database and application hosting | EU |
| Cloudflare | Content delivery, DNS and security | EU / United States |
| Stripe | Payment processing (customer billing data only, no subscriber data) | EU / United States |
| OpenAI | AI-assisted support and features | United States |
The current list is also published on our GDPR compliance page.