Legal · Compliance

GDPR compliance

How MailOps meets its obligations under the EU General Data Protection Regulation.

Last updated: September 25, 2026

1.Roles & responsibilities

For message and audience data, you are the controller and MailOps acts as processor, handling data only on your documented instructions. For operator account data, MailOps is the controller.

A Data Processing Agreement (DPA) incorporating the EU Standard Contractual Clauses is part of every subscription.

2.Data subject rights

We support the full set of GDPR rights:

  • Access & portability — machine-readable export of all data held
  • Rectification — correct inaccurate data
  • Erasure — delete data and add the address to the suppression list
  • Restriction & objection — halt processing while a request is reviewed

Tenant administrators can export or erase a contact's data self-service from the GDPR page in the admin console; verified requests are logged to the audit log.

3.Submitting a request

Data subjects, or anyone authorized to act on their behalf, can submit a request by emailing dpo@mailops.eu from the address the request concerns. Identity verification may be required. The DPO responds within 30 days.

4.Transfers, subprocessors & DPO

Data is hosted in the EU (fr-par / eu-west-1). Any onward transfer relies on SCCs. Subprocessors: SendGrid, AWS (SES/SNS), Scaleway, and the LLM provider for redacted bounce metadata only — the current list is maintained on this page.

Data Protection Officer: dpo@mailops.eu · Supervisory authority complaints may be lodged with your local EU authority.