Legal · Updated 2026-04-01

Data Processing Agreement.

Pre-signed DPA, current sub-processor list, and security overview. Enterprise customers can request a counter-signed version with custom terms.

Sub-processors

VendorPurposeRegion
EU cloud providerCloud hosting & object storageEU
ResendTransactional emailUS
CloudflareBot protection and CDNGlobal

Security overview

  • Strict access controls with least-privilege for production systems.
  • Customer data hosted in the EU (EU data residency).
  • Data encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Mandatory 2FA for all employees with production access.
  • Regular security reviews of application code and dependencies.
  • Incident response: customers notified within 72 hours per GDPR Art. 33.

Sub-processor changes

We will notify customers at least 30 days before adding or replacing a sub-processor. You may object during that window.

Contact

Reach our Data Protection Officer through the contact page — choose “Customer support” and we'll route to the DPO.

Email signatures, finally treated as the brand asset they are.
Book a demo
Data processing agreement (DPA) | Mail Brand