Legal
Data Processing Addendum
Last updated: July 15, 2026
1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and MailStrap LLC (“MailStrap”) and applies whenever MailStrap processes personal data contained in Customer content on the Customer's behalf. For that data the Customer is the controller (or a processor acting for another controller) and MailStrap is the processor. It is incorporated into our Terms of Service for every customer, no signature required; if your compliance process needs a countersigned copy, email hello@mailstrap.com.
2. Processing details
- Subject matter: hosting and processing of email, files, documents, contacts, calendars, campaign data, and e-signature documents.
- Duration: the term of the agreement, plus the deletion window below.
- Nature and purpose: providing the MailStrap service as configured and instructed by the Customer through the product.
- Data subjects: the Customer's users, employees, correspondents, subscribers, and signers.
- Categories of data: whatever the Customer chooses to store or transmit, typically contact details and communications content.
3. MailStrap's obligations
- Process personal data only on the Customer's documented instructions, given through the product and the agreement, unless law requires otherwise (in which case we inform the Customer unless prohibited).
- Ensure people authorized to process the data are bound by confidentiality.
- Implement the technical and organizational measures described on our Security page, encryption in transit, application-layer encryption of stored secrets, access controls, tenant isolation, and audit logging.
- Assist the Customer, taking into account the nature of processing, with data subject requests and with security and impact-assessment obligations.
- Notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer data.
- Delete Customer personal data on termination of the agreement (production immediately on account deletion; encrypted backups purge within 30 days), unless law requires retention.
- Make available information reasonably necessary to demonstrate compliance, and allow audits as described in section 6.
4. Subprocessors
The Customer gives general authorization for the subprocessors listed at /subprocessors. Each is bound by a written agreement imposing data protection obligations no less protective than this DPA. We will post changes to that list at least 14 days before a new subprocessor processes Customer data; if the Customer reasonably objects on data protection grounds and we cannot accommodate them, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
5. International transfers
Processing takes place in the United States. Where the transfer of EU/UK personal data requires a transfer mechanism, the parties rely on the EU Standard Contractual Clauses (Module 2, controller-to-processor), which are incorporated by reference, with the Customer as data exporter and MailStrap as data importer.
6. Audits
On written request, no more than once per year unless a breach has occurred, we will provide summaries of our security practices and available third-party reports. Where those are insufficient to demonstrate compliance, the Customer may conduct a reasonable audit with 30 days notice, during business hours, without access to other customers' data.
7. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on data protection matters, this DPA controls. This DPA is governed by the same law as the Terms (Colorado, United States). Contact: MailStrap LLC, Colorado, United States, hello@mailstrap.com.

