GDPR compliance
How MailOps meets its obligations under the EU General Data Protection Regulation.
Last updated: August 12, 2026
1.Roles & responsibilities
For message and audience data, you are the controller and MailOps acts as processor, handling data only on your documented instructions. For operator account data, MailOps is the controller.
A Data Processing Agreement (DPA) incorporating the EU Standard Contractual Clauses is part of every subscription.
2.Data subject rights
We support the full set of GDPR rights. Requests about recipients in your audience can be handled self-service from the Contacts page (rectify, suppress); machine-readable exports run through the API only. For anything else, use the request form below — the DPO responds within 30 days.
- Access & portability — machine-readable export of all data held
- Rectification — correct inaccurate data
- Erasure — delete data and add the address to the suppression list
- Restriction & objection — halt processing while a request is reviewed
3.Data subject request
Submit a request on behalf of a data subject. This is a mock — the form toasts a confirmation instead of sending.
4.Transfers, subprocessors & DPO
Data is hosted in the EU (fr-par / eu-west-1). Any onward transfer relies on SCCs. Subprocessors: SendGrid, AWS (SES/SNS), Scaleway, and the LLM provider for redacted bounce metadata only — the current list is maintained on this page.
Data Protection Officer: dpo@mailops.internal · Supervisory authority complaints may be lodged with your local EU authority.