Skip to main content

Data Processing Addendum

How mailkube processes personal data on your behalf, and the terms that govern that processing.

Effective date: Determined upon acceptance for each Organization

Version 1.3, last updated September 12, 2026.

In respect of each Organization, this Addendum has no effect until the Terms of Service are accepted for that Organization at its creation, with effect from the date of that acceptance, at which point it forms part of the Agreement in respect of that Organization. That date is recorded in the Organization’s account. No separate signature is required.

This Data Processing Addendum (“DPA”, “Addendum”) forms part of the Terms of Service (“Terms”) between Mail Tactic Corporation, operating the Service under the mailkube name (“Mailkube”, “we”, “us”), and the Customer (“you”) as defined in Section 1, in respect of each Organization for which the Terms are accepted. It governs the processing of personal data that Mailkube carries out on the Customer’s behalf when the Service is used for that Organization.

1. Definitions

Capitalized terms not defined here have the meaning given in the Terms or in Applicable Data Protection Law.

Applicable Data Protection Law means the following laws, and only those laws, in each case to the extent that each applies to the processing of personal data under this Addendum: the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”); the UK GDPR; the Swiss Federal Act on Data Protection (“FADP”); and, where the Customer is a business subject to it, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).

Mailkube means Mail Tactic Corporation, a Delaware C Corporation (file no. 10537478), the entity identified in Exhibit B, operating the Service under the mailkube name.

Customer means, in respect of each Organization created in the Service, the person who is the Customer for that Organization under Section 1 of the Terms: from the date on which business details are submitted for that Organization, the legal entity identified in those details, and, before that date or where no business details are submitted, the individual who owns that Organization, acting in their own name and on their own account. An Organization is not itself a party to this Addendum; it is the scope within which this Addendum applies. Acceptance of the Terms in respect of an Organization creates a separate Addendum between Mailkube and that Organization’s Customer, covering the processing Mailkube carries out for that Organization.

Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach have the meanings given in the GDPR.

Sub-processor means any processor engaged by Mailkube to process Customer Personal Data on Mailkube’s behalf.

Customer Personal Data means the personal data described in Exhibit A that Mailkube processes as a processor on the Customer’s behalf.

EU SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time, completed as set out in Section 8.

UK Addendum means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B.1.0, completed as set out in Section 8.

Standard Contractual Clauses or SCCs means the EU SCCs, the UK Addendum, and the EU SCCs as modified for transfers subject to the FADP, in each case as and to the extent they apply under Section 8.

Agreement means the Terms, the Privacy Policy, and this Addendum, together, as stated in the Terms.

2. Roles and Scope of Processing

Mailkube acts in two distinct roles:

  • As processor of Customer Personal Data (the Customer’s audience and contact data, described in Exhibit A). The Customer is the controller of that data.
  • As controller of account, billing, and usage data, as set out in Section 12 and governed by the Privacy Policy.

Mailkube processes Customer contact and audience data as a processor on the Customer’s documented instructions, and does not use it for its own marketing, profiling, or product development. Mailkube acts as a controller, and not as a processor, when it protects the security, integrity, and sending reputation of the Service, including the abuse prevention and deliverability measures described in Exhibit A and in the Acceptable Use Policy, which it carries out across the Service as a whole rather than on any Customer’s instructions.

The Customer’s complete documented instructions are: the Terms, this Addendum, and the Customer’s configured use of the Service. Any further instructions require agreement between the parties.

Customer obligations. The Customer warrants that it has a lawful basis and any consents required for the personal data it submits, for the engagement tracking it enables, and for any recipient IP address, country, or user-agent it elects to have recorded under Exhibit A, that its instructions comply with Applicable Data Protection Law, and that it is responsible for the accuracy and lawfulness of the contact data it provides. The Customer will indemnify Mailkube against claims, losses, and costs arising from personal data the Customer submits to the Service without a lawful basis, or from instructions that infringe Applicable Data Protection Law. This indemnity is subject to the limitations and exclusions of liability in the Terms, as described in Section 13.

California Consumer Privacy Act. Where the Customer is a business and Mailkube processes personal information subject to the CCPA on the Customer’s behalf, Mailkube acts as a service provider. Mailkube does not sell or share that personal information, and does not retain, use, or disclose it for any purpose other than performing the Service under the Agreement, except as the CCPA permits. Mailkube will not retain, use, or disclose that personal information outside the direct business relationship between Mailkube and the Customer, except as the CCPA permits. Mailkube will not combine that personal information with personal information it receives from another source, except as the CCPA permits. Mailkube processes that personal information only for the business purposes described in Exhibit A, and will comply with all applicable requirements of the CCPA and its implementing regulations. The Customer may take reasonable and appropriate steps to ensure that Mailkube uses that personal information in a manner consistent with the Customer’s obligations under the CCPA. Mailkube will enable the Customer to comply with consumer requests made under the CCPA, through the assistance described in Section 6. Mailkube will inform the Customer if it determines that it can no longer meet its obligations under the CCPA, and the Customer may take reasonable and appropriate steps to stop and remediate unauthorised use. Mailkube certifies that it understands these restrictions and will comply with them. The terms business, service provider, sell, share, and personal information have the meanings given in the CCPA.

3. Processor Obligations

Mailkube will:

  • Process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers of personal data to a third country, unless required to process by Union or Member State law to which Mailkube is subject. In that case, Mailkube will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
  • Ensure that all persons authorised to process Customer Personal Data, whether employees or contractors, are bound by written contractual confidentiality obligations or an appropriate statutory duty of confidentiality. Those obligations survive the end of their engagement.
  • Immediately inform the Customer if, in Mailkube’s opinion, an instruction infringes Applicable Data Protection Law.
  • Maintain records of the processing activities carried out on behalf of the Customer, as required by Article 30(2) GDPR, and make them available to the Customer on request.
  • Assist the Customer, taking into account the nature of the processing and the information available to Mailkube, with data protection impact assessments and prior consultation with a supervisory authority (Articles 35 and 36 GDPR), bounded as described in Section 6.

4. Security

Mailkube implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Exhibit C describes the measures in place as at the date of this Addendum. Mailkube may update those measures over time provided the level of protection is not degraded.

5. Sub-processors

The Customer gives Mailkube general authorisation to engage Sub-processors, subject to this Section.

Mailkube imposes on each Sub-processor, by written contract, the same data protection obligations as those set out in this Addendum, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures. Where the CCPA applies to the processing, Mailkube also imposes on each Sub-processor, by written contract, the same restrictions on that personal information that this Addendum imposes on Mailkube as a service provider. Where a Sub-processor is established in a third country, or has a parent entity in a third country, the transfer is covered by an adequacy decision of the European Commission under Article 45 GDPR, or that contract includes the Standard Contractual Clauses or another lawful transfer mechanism. Mailkube remains fully liable to the Customer for any failure by a Sub-processor to meet its obligations.

The current Sub-processors that process Customer Personal Data are:

  • OVH (infrastructure hosting). Contracting entity established in the United States, within the French OVHcloud group. Processing takes place in the European Union. The transfer to the contracting entity is covered by the Standard Contractual Clauses executed as part of that entity’s data processing agreement.
  • Cloudflare acts as reverse proxy and TLS termination and CDN (including R2 object storage) and DNS, processing connection data (IP addresses, request metadata) in transit and storing content at rest. Contracting entity established in the United States. Storage is configured to the European Union. Transfers are safeguarded by the Standard Contractual Clauses.
  • Sentry (error monitoring). Contracting entity established in the United States. Processing takes place in Sentry’s European Union region. Transfers are safeguarded by the Standard Contractual Clauses.
  • Atlassian (support ticketing via Jira), processing personal data contained in support requests raised through the Service, which may include Customer Personal Data. Contracting entity established outside the European Union. Transfers are safeguarded by the Standard Contractual Clauses.

The list in this Section is the authoritative current list of Sub-processors. The sub-processor page restates it, and states for each Sub-processor the contracting entity, the location of processing, and the safeguard applying to any transfer.

Mailkube will give notice of any intended addition or replacement of a Sub-processor by email to the Customer’s organization owners and admins at least 14 days before the change takes effect. The Customer may object in writing to privacy@mailkube.com within the notice period. If an objection is not resolved through good-faith discussion, the Customer may terminate the affected services or the Agreement before the new Sub-processor starts processing, with a pro-rata refund of any prepaid, unused fees. Continued use of the Service after the notice period is deemed approval of the change.

Relationship to the Standard Contractual Clauses. Where the SCCs apply under Section 8, the general authorisation in this Section is the Customer’s prior written consent to Mailkube’s engagement of Sub-processors for the purposes of Clause 9 of the EU SCCs, and the 14-day notice period in this Section is the notice period agreed under Clause 9. Copies of Sub-processor agreements that Mailkube must make available under Clause 9(c) may have commercial terms and information unrelated to data protection removed beforehand, and are provided on the Customer’s request.

6. Assistance with Data Subject Rights

Mailkube provides, at no additional cost, self-service export tools within the Service, which the Customer may use to fulfil data-subject access and portability requests: exports of contacts, of suppression entries, and of per-recipient sending logs, each generated as CSV. Deletion and rectification requests for contact and audience data are fulfilled by the Customer through the contact management dashboard and API; the applicable retention periods in Section 11 then apply.

Suppression entries are created automatically from delivery reports so that prior bounces are honoured. They can be listed and exported, but they cannot be edited or removed by the Customer, and they are erased when the associated domain or the organization is deleted, as described in Section 11.

Delivery reports and the message metadata derived from them cannot be erased for an individual recipient on request: they record what the Service did with a message, they are relied on to protect its security, integrity, and sending reputation, and editing them per recipient would defeat that purpose. Engagement events are erased on the Customer’s instruction rather than on Mailkube’s own assessment, because Mailkube processes them only as a processor; a recipient who wants them erased should direct the request to the sender, and Mailkube will assist that Customer under this Section. All of it is erased in any event by the retention periods in Section 11, which apply without exception. The body of a message scheduled for future transmission likewise cannot be erased for an individual recipient before dispatch; it is deleted as Section 11 describes.

Where the Customer requests assistance that the self-service tools do not provide, Mailkube provides reasonable cooperation, taking into account the nature of the processing and the information available to Mailkube, insofar as this is possible. Assistance that requires material or disproportionate effort may be provided against reasonable, cost-based compensation. A self-service export of all account data is not yet available; until it is, Mailkube commits to assist with such requests on the same basis.

Requests received directly. If Mailkube receives a request from a data subject that relates to Customer Personal Data, Mailkube will, to the extent legally permitted, promptly notify the Customer and forward the request. Mailkube will not respond to the request substantively itself unless the Customer instructs it to or the law requires it, and may direct the data subject to the Customer.

Relationship to the Standard Contractual Clauses. Where the SCCs apply under Section 8, the assistance described in Clause 10 of the EU SCCs is provided in accordance with this Section. This Section and Exhibit C together set out the measures by which that assistance is provided, and its scope and extent, for the purposes of Clause 10(b). Mailkube does not make that assistance conditional on the compensation described above where doing so would prevent or delay compliance with that Clause.

7. Personal Data Breach

Mailkube will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice is given by email to the Customer’s organization owners and admins, sent from privacy@mailkube.com.

The notice will describe, to the extent then known: the nature of the breach, including where possible the categories and approximate number of data subjects and of personal-data records concerned; the likely consequences of the breach; the measures taken or proposed to address it; and a contact point for more information (privacy@mailkube.com). Where the information cannot all be provided at once, it may be given in phases as it becomes available.

Mailkube provides this assistance taking into account the nature of the processing and the information available to Mailkube, insofar as this is possible.

Data for which Mailkube is controller. For the account, billing, and usage data described in Section 12, Mailkube is the controller and notifies the competent supervisory authority, and where required the affected individuals, in accordance with Articles 33 and 34 GDPR and with Module One of the EU SCCs where it applies.

8. International Transfers

8.1 Location of processing. Customer Personal Data is stored at rest in the European Union, and operational access to it is performed from within the European Union.

Two categories of Customer Personal Data leave that boundary in the ordinary course of providing the Service, in each case under the safeguards described in Section 5. Connection metadata, meaning the recipient IP address and request headers that reach the content-delivery Sub-processor at the point of presence nearest the recipient when a tracked open or click is fetched, is handled by that Sub-processor on every such fetch. Mailkube itself records the recipient IP address, the country it resolves to, and the browser or mail client user-agent only where the Customer has enabled the corresponding per-domain setting described in Exhibit A, and records none of them otherwise. Personal data that a Customer includes in a support request is handled by the support-ticketing Sub-processor. The transfer to Mailkube itself is addressed in Section 8.2.

8.2 Status of the parties. Mail Tactic Corporation is incorporated in the United States (Delaware), as stated in Exhibit B. Where the Customer is established in the European Economic Area, the United Kingdom, or Switzerland, the provision of the Service therefore involves a transfer of personal data to a data importer in a third country, and the safeguards in this Section apply to that transfer. Transfers to Sub-processors that are established in a third country, or that have a parent entity in a third country, are separately protected as described in Section 5: by a European Commission adequacy decision where one covers the country concerned, and otherwise by the Standard Contractual Clauses concluded between Mailkube and the Sub-processor.

8.3 Incorporation of the EU SCCs. The EU SCCs are incorporated into this Addendum by reference and are entered into by the parties as described in Section 14. Module One (controller to controller) applies to the account, billing, and usage data for which Mailkube is an independent controller under Section 12, and to the personal data Mailkube processes as an independent controller for the security, integrity, and sending-reputation purposes described in Sections 2 and 12. Module Two (controller to processor) applies where the Customer is a controller of Customer Personal Data. Module Three (processor to processor) applies where the Customer is itself a processor and Mailkube processes Customer Personal Data as its sub-processor.

8.4 Completion of the EU SCCs. For each Module that applies: the optional docking clause in Clause 7 does not apply; in Clause 9, where that Clause forms part of the applicable Module, Option 2 (general written authorisation) applies and the notice period is the 14 days set out in Section 5; the optional language in Clause 11 does not apply; the competent supervisory authority for Clause 13 and Annex I.C is determined as set out in Section 8.5; in Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland; and in Clause 18(b), disputes are resolved before the courts of Ireland. Exhibit A and Exhibit B contain the information required by Annex I, and Exhibit C contains the information required by Annex II. The Sub-processor list in Section 5, together with the sub-processor page, sets out the Sub-processors Mailkube has engaged under the general authorisation in Clause 9. Where an option or an item of bracketed text in the EU SCCs is not addressed here, the alternative more protective of data subjects applies.

8.5 Competent supervisory authority. For the purposes of Clause 13 and Annex I.C of the EU SCCs, the competent supervisory authority is determined as follows.

Where the Customer, as data exporter, is established in an EEA Member State, it is the supervisory authority of that Member State.

Where the Customer is not established in an EEA Member State but falls within the territorial scope of the GDPR under Article 3(2), and has appointed a representative under Article 27(1) GDPR, it is the supervisory authority of the Member State in which that representative is established.

Where the Customer is not established in an EEA Member State but falls within the territorial scope of the GDPR under Article 3(2) without having to appoint a representative under Article 27(2) GDPR, it is the supervisory authority of one of the Member States in which the data subjects whose personal data is transferred under the EU SCCs, in relation to the offering of goods or services to them or whose behaviour is monitored, are located. The Customer may notify Mailkube in writing of the Member State it selects for this purpose, and that Member State is the one indicated in Annex I.C.

8.6 Governing law and forum of the Clauses. The choice of Irish law and Irish courts in Section 8.4 applies to the SCCs and to any dispute arising out of them, and it applies notwithstanding the governing-law provision of the Terms. It does not change the law governing the Terms or the remainder of this Addendum.

8.7 United Kingdom transfers. Where a transfer is subject to the UK GDPR, the UK Addendum applies and is entered into by the parties as described in Section 14. Table 1 is completed with the party details in Exhibit B. Table 2 is completed by reference to the EU SCCs and the Module that applies under Section 8.3. Table 3 is completed with Exhibit A, Exhibit B, Exhibit C, and the Sub-processor list in Section 5. In Table 4, neither party may end the UK Addendum as set out in Section 19 of that Addendum. For those transfers the Information Commissioner is the competent supervisory authority in place of the authority determined under Section 8.5, and the references to Irish law and Irish courts in Sections 8.4 and 8.6 are read as references to the law and the courts of England and Wales.

8.8 Swiss transfers. Where a transfer is subject to the FADP, the EU SCCs apply with the following modifications. References to the GDPR are read as references to the FADP to the extent the transfer is governed by it. The Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the FADP. The term “EU Member State” is not read so as to prevent a data subject in Switzerland from bringing proceedings in their place of habitual residence under Clause 18(c). Where and for as long as the FADP protects the data of legal entities, the EU SCCs are read as protecting that data as well.

8.9 Supplementary measures. The following measures apply in addition to the SCCs.

The location of storage and of operational access described in Section 8.1 means that the Customer Personal Data Mailkube holds at rest is not made available outside the European Union, and that no person outside the European Union holds standing operational access to it. That statement concerns the persons who operate the Service on Mailkube’s behalf. Access by a Sub-processor to the systems on which Customer Personal Data is hosted is governed by Section 5 and by the Standard Contractual Clauses concluded with that Sub-processor. The two exceptions stated in Section 8.1 are limited to connection metadata and to the content of support requests, and each is covered by the Standard Contractual Clauses concluded with the Sub-processor concerned.

If Mailkube (including Mail Tactic Corporation itself) or a Sub-processor receives a legally binding request from a public authority for Customer Personal Data, Mailkube will, unless legally prohibited, notify the Customer, will challenge requests that are overbroad or unlawful where reasonably possible, and will disclose only the minimum required.

Where it is permitted to do so, Mailkube will direct the requesting authority to seek the data from the Customer instead, and may give the authority the Customer’s contact details for that purpose. Mailkube does not disclose Customer Personal Data to any public authority in the absence of a valid and binding legal obligation, and has not created any facility that would give a public authority direct access to Customer Personal Data.

As at the version date of this Addendum, Mailkube has received no request from a government intelligence or security agency for Customer Personal Data.

Mailkube has documented an assessment of the laws of the countries relevant to these transfers and of the effectiveness of these measures, and makes it available to the Customer on request. The parties will reassess it if circumstances change, and will consult on whether a transfer should be suspended if the assessment no longer supports it.

8.10 Execution as a separate instrument. Where a law applicable to the Customer requires the SCCs to be executed as a separate signed instrument for a particular transfer, Mailkube will, on the Customer’s request, promptly execute those clauses completed with the details of the transfer and with any amendments reasonably required to reflect the applicable annexes and that law.

8.11 Alternative transfer mechanism. If the SCCs or the UK Addendum cease to be a valid transfer mechanism, or a supervisory authority requires transfers made under them to be suspended, Mailkube may, on notice to the Customer, put an alternative lawful transfer mechanism in place for the affected transfers.

9. EU Representative (Article 27)

Mail Tactic Corporation has appointed Prighter EU Rep GmbH, Vienna, Austria, as its representative in the European Union pursuant to Article 27 GDPR, as the point of contact for data subjects and supervisory authorities on matters relating to the processing of personal data. The representative may be addressed in addition to or instead of Mail Tactic Corporation, which remains reachable at privacy@mailkube.com. Contact details are on our EU Representation page.

10. Audits

Mailkube will make available to the Customer all information necessary to demonstrate compliance with the obligations in this Addendum, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates. Audits are subject to confidentiality obligations.

How an audit is satisfied. An audit is satisfied in the first instance by Mailkube providing written information and documentation, including its records of processing under Section 3, the description of measures in Exhibit C, and any third-party audit report or certification Mailkube holds at the time. An inspection at Mailkube’s premises or facilities takes place where the Customer considers that the material provided is insufficient to demonstrate compliance, or where a Personal Data Breach, an indication of non-compliance, or a supervisory authority requires it.

Frequency and manner. Audits are conducted on at least 30 days’ prior written notice, during business hours, and no more than once in any 12-month period, unless a Personal Data Breach has occurred, there are indications of non-compliance, or a supervisory authority requires otherwise. The scope, duration, and security procedures of an inspection are agreed between the parties in advance. An inspection must not unreasonably disrupt Mailkube’s business or the operation of the Service, and is conducted remotely where that is reasonably sufficient.

Scope. An audit is limited to Mailkube’s processing of that Customer’s Customer Personal Data and to the systems and controls relevant to it. Because the Service is multi-tenant, an audit does not extend to, and Mailkube will not disclose, other customers’ data, information that would compromise the security of the Service or of other customers, or information Mailkube is bound to keep confidential by law. Where Mailkube withholds information on that basis, it will provide equivalent assurance by another means, and will explain in writing why the information was withheld.

The auditor. An auditor mandated by the Customer must be independent of Mailkube, must not be a competitor of Mailkube, and must be bound by written confidentiality obligations requiring it to use information obtained in the audit solely for the purpose of the audit, to disclose that information only to those of its personnel who need it for that purpose and who are themselves bound to confidentiality, and not to disclose it otherwise except as required by law. Mailkube may object to a proposed auditor on reasonable grounds, stated in writing within 15 days of being notified of the auditor, in which case the Customer may mandate a different auditor. Mailkube may require the auditor to enter into a non-disclosure agreement directly with Mailkube before an inspection begins.

Costs. The written information and documentation described above is provided at no charge. Where the Customer requires an inspection, the Customer bears its costs, including compensation for the time spent by Mailkube’s personnel, charged at Mailkube’s then-current standard rates and capped at five working days per audit. Mailkube will give the Customer a good-faith written estimate of those costs before an inspection is scheduled. Where an audit reveals a material breach by Mailkube of this Addendum, Mailkube bears the costs of that audit and refunds any amount the Customer has paid for it.

Where the SCCs apply under Section 8, the audits described in Clause 8.9 of the EU SCCs are carried out in accordance with this Section, and Mailkube will make the information referred to in that Clause, including the results of any audits, available to the competent supervisory authority on request.

11. Deletion and Return on Termination

At the Customer’s choice, Mailkube returns or deletes Customer Personal Data at the end of the provision of the Service. Return is satisfied by the Customer retrieving its data through the self-service export tools, at no charge, during the applicable retention window described below, with assistance available under Section 6. Where the Customer can no longer generate an export within the Service, including because its subscription has lapsed or its access has been suspended or terminated under the Terms, the Customer may instead request an export by writing to privacy@mailkube.com before the applicable deletion period below expires. Mailkube then provides the requested Customer Personal Data in a commonly used, machine-readable format, at no charge, and defers the deletion of that data for as long as is necessary to do so. Deletion then proceeds as set out below.

Where the SCCs apply under Section 8, any certification of deletion that the EU SCCs require Mailkube to provide, including under Clause 8.5 and Clause 16(d), is provided to the Customer on the Customer’s request. A certification provided while an erasure archive described below is still held states that the personal data has been deleted from Mailkube’s production systems, and identifies that archive, the basis on which it is retained, and the date by which it will be deleted.

Personal data is erased from Mailkube’s production systems within the following periods:

  • 90 days after organization deletion;
  • 90 days after domain deletion;
  • for a lapsed subscription, the period defined by the Customer’s plan, up to a maximum of 90 days. That period is currently 45 days on every plan, and 45 days also applies where a plan defines no period.

On a lapsed subscription, contacts, engagement and delivery logs, reports, audit data, and data belonging to domains that are no longer active are erased. Suppression entries attached to domains that remain configured are retained until the domain or the organization is deleted, because they are needed to honour prior bounces.

During the subscription term, per-recipient sending logs, comprising engagement and delivery-log data and message metadata including subject lines, are deleted from the primary store, and cease to be accessible in the dashboard and in exports, at the end of a rolling window defined by the Customer’s plan, currently between 7 and 90 days depending on plan. Aggregate analytics that contain no recipient-level personal data are retained on the plan’s analytics window, currently between 1 and 12 months depending on plan. Audit data is retained for the plan’s audit window. Each category of data is deleted at the earlier of its own window or the applicable period above, except in the analytics store described immediately below, which is governed by its own maximum.

Analytics store. A copy of the Customer’s event data is retained in a separate analytics store that serves the dashboard. That copy comprises delivery and engagement events, including recipient addresses and, where the Customer has enabled the settings described in Exhibit A, the recipient IP address, country, and user-agent recorded with an open or click; submission and authentication metadata, including the originating IP addresses recorded when a message is accepted and when an SMTP session authenticates; and copies of suppression records, webhook-delivery records, and scheduled-message records. The webhook-delivery records hold a copy of each payload as it was sent to the Customer’s endpoint, so they repeat whatever the corresponding event carried, and they are retained on the webhook-delivery period rather than the event period. That copy is not used for any purpose other than reporting to the Customer, remains subject to the measures in Exhibit C, is retained for at most twelve months from the event it records, and is then deleted. It is deleted when an Organization is erased under this Section. Where a domain is deleted without the Organization being erased, the copy relating to that domain persists no longer than that same twelve-month maximum.

Message body and HTML content. Body content is not retained after transmission. Where a message is scheduled for future transmission, its body is deleted when the message is dispatched, cancelled, or fails, and in any event no later than the maximum scheduling period the Service permits, currently 30 days from submission. The message metadata described above is retained on its own window independently of the body.

Statutory exception. Invoices and billing records (which include VAT and business-address information) are retained for the period required by tax law and are not erased under this Section.

Erasure archives. Before an Organization or a domain is erased under this Section, Mailkube writes one encrypted archive drawn from the data being erased to a segregated, non-public store, as described in Exhibit C. That archive is retained solely for the establishment, exercise, or defence of legal claims. It is not used for any other processing, remains subject to the measures in Exhibit C, is retained for at most 90 days from its creation, and is then permanently deleted. That period is aligned to the 90-day preservation period that United States law applicable to Mailkube sets for a provider of electronic communication services. Separately, where a law applicable to Mailkube requires it to preserve personal data that would otherwise be erased under this Section, including on a preservation request from a governmental authority or where legal proceedings relating to that data are reasonably anticipated, Mailkube preserves that data only to the extent and for as long as that law requires.

Backups. Residual copies of personal data may persist in routine backups after erasure from production systems. Those copies are not used for any processing, remain subject to the measures in Exhibit C, and are overwritten in the ordinary course of the backup cycle.

12. Mailkube as Controller

For account, billing, and usage data, including the data of the Customer’s authorized and team users, Mailkube is an independent controller and not a joint controller with the Customer. That data is governed by the Privacy Policy rather than this Addendum.

Abuse prevention, security, and sending reputation. Mailkube is also an independent controller, and not a processor, of the personal data it processes to protect the security, integrity, and sending reputation of the Service, as stated in Section 2. That processing is carried out across the Service as a whole rather than on any Customer’s instructions, and the data involved comprises delivery diagnostics, suppression entries, submission and authentication metadata, and the risk signals and ban records derived from them, in each case only to the extent used for those purposes. It is described for data subjects in the notice for email recipients.

Engagement events are outside that scope. Open and click events, and any recipient IP address, country, or user-agent recorded with them, are Customer Personal Data that Mailkube processes solely as a processor, on the Customer’s instruction, for the Customer’s own reporting. Mailkube does not use them to protect the security, integrity, or sending reputation of the Service, and no abuse-prevention, reputation, or ban decision reads them. The Customer decides whether tracking runs at all, and what each event records.

The same data remains Customer Personal Data, processed by Mailkube as processor under this Addendum, for the purposes of delivering the Customer’s messages and reporting to the Customer on them. The controller characterisation in the preceding paragraph attaches only to Mailkube’s own use of that data for the purposes stated there, and does not remove any data from the scope of Mailkube’s processor obligations.

Transfer safeguards for that data. Because Mail Tactic Corporation is established in a third country, the transfer of the data described in this Section to Mailkube is itself a restricted transfer. The safeguards in Section 8 therefore apply to it, through Module One of the EU SCCs as selected in Section 8.3, notwithstanding that the data is otherwise governed by the Privacy Policy or by the notice for email recipients. Exhibit A describes that data for the purposes of Annex I.B.

13. Precedence and Liability

The Terms govern the relationship between the parties generally. In the event of a conflict or inconsistency concerning the processing of personal data, the order of precedence is: first, the Standard Contractual Clauses to the extent they apply under Section 8; second, this Addendum; third, the Terms; and fourth, the Privacy Policy.

Each party’s liability under this Addendum is subject to the limitations and exclusions of liability set out in the Terms, except where Applicable Data Protection Law does not permit such limitation. Those limitations and exclusions limit Mailkube’s liability by their terms; they do not cap the Customer’s liability under the indemnity in Section 2.

14. Term, Survival, and Acceptance

This Addendum takes effect, in respect of each Organization, when the Terms are accepted for that Organization at its creation, and remains in effect until Mailkube ceases to process Customer Personal Data for that Organization, notwithstanding the expiry or termination of the Agreement. The obligations in this Addendum survive for as long as any Customer Personal Data is retained under Section 11.

This Addendum is binding on that acceptance and requires no separate signature.

Entry into the Standard Contractual Clauses. By that acceptance, the parties are deemed to have signed the Standard Contractual Clauses incorporated by Section 8, including their Annexes, with effect from the date of the acceptance recorded in the Organization’s account. No separate signature is required for them either. Section 8.10 applies where a Customer’s own law nevertheless requires the clauses to be executed as a separate instrument.

Change of Customer. Where the Customer in respect of an Organization changes under the substitution provision of Section 1 of the Terms, this Addendum and the Standard Contractual Clauses continue in force in respect of that Organization without re-issue or re-execution, with the substituted Customer as party and as data exporter, and the date of the original acceptance remains the date of execution.

15. Changes to this Addendum

Mailkube will notify the Customer’s organization owners and admins of any material change to this Addendum, by email, at least 14 days before the change takes effect. This overrides the general amendment mechanism in the Terms for this Addendum.

16. Language

The English version of this Addendum is the only contractual version and is authoritative. It is the version that is accepted, executed, and enforceable between the parties, including the Standard Contractual Clauses and their Annexes incorporated by Section 8. The French translation is provided for information and convenience only. It is not signed, is not accepted as such, and creates no independent obligation. In the event of any discrepancy between the two versions, the English version prevails.

17. Contact

For general questions, raise a ticket from the Help section of your mailkube dashboard. For questions about data protection or this Addendum, contact us at privacy@mailkube.com.

Exhibit A. Details of Processing

This Exhibit, together with Exhibit B, is the information required by Annex I of the EU SCCs.

Categories of data subjects. The Customer’s email recipients and contacts. Other individuals whose personal data the Customer includes in message content or template variables. The data of the Customer’s own account and team users is not processed under this Addendum as processor-scope data; it is addressed in Section 12.

Categories of personal data.

  • Recipient email addresses.
  • Envelope metadata (from, to, cc, bcc), including whether each recipient was addressed in the To, Cc, or Bcc field.
  • Message subject line (retained, subject to the rolling window in Section 11).
  • Template variables supplied by the Customer.
  • Message tags supplied by the Customer as name and value pairs.
  • Message identifiers and threading references (Message-ID, In-Reply-To).
  • Submission metadata recorded when a message is accepted: the originating IP address, the connecting client hostname, and the identifier of the SMTP or API credential used.
  • Authentication session records for SMTP connections, comprising the originating IP address, the credential identifier, and the sending domain.
  • Engagement events (open, click, bounce), recording that the event occurred, at a time, against a message, and the destination address of a tracked link when a click occurs, including any query string the Customer placed in that link.
  • Where, and only where, the Customer enables the corresponding per-domain setting, the recipient IP address and the country it resolves to, and the browser or mail client user-agent, recorded on each open and click event. Both settings are off by default and are enabled by the Customer in its dashboard. Recording this data may require the recipient’s consent depending on where the recipient is, and the Customer warrants under Section 2 that it holds any consent required.
  • Delivery diagnostics returned by the receiving mail server, which may repeat the recipient address.
  • Contact records (names, email addresses) and topic or segment subscriptions.
  • Bounce suppression entries.
  • Webhook delivery payloads, which repeat the event data above for each endpoint the Customer has configured.
  • Report exports generated at the Customer’s request, which contain the data described above in file form.
  • Message body and HTML content, including any personal data the Customer places in it (processed transiently for an immediate send; held until dispatch for a scheduled send, as described immediately below).

Message body and HTML content is processed transiently in the sending (MTA) spool pending delivery and is not retained after the message is sent. Where the Customer schedules a message for future transmission, its rendered body is instead held from the moment the message is submitted until it is transmitted, encrypted at rest as described in Exhibit C, for at most the maximum scheduling period the Service permits, which is currently 30 days. That body is deleted when the message is dispatched, cancelled, or fails.

Sensitive data. None. The Service is not intended for special categories of personal data within the meaning of Article 9 GDPR, or for personal data relating to criminal convictions and offences, and the Customer undertakes not to submit such data to it.

Nature and purpose of the processing. Transactional and marketing email delivery and related analytics, and service security, abuse prevention, and deliverability protection.

Frequency of the transfer. Continuous, for the term of the Agreement.

Duration. The term of the Agreement, plus the applicable retention windows in Section 11. The rolling retention windows in Section 11 apply during the term.

Retention. As described in Section 11.

Transfers to Sub-processors. Where personal data described above is transferred to a Sub-processor listed in Section 5, the subject matter and nature of that processing are the service each Sub-processor provides as described in that Section, and its duration is the term of Mailkube’s contract with that Sub-processor, which does not extend beyond the retention periods in Section 11.

Controller-scope data (Module One). Where Module One of the EU SCCs applies under Section 8.3, the transfer it covers is described as follows. The data subjects are the Customer’s authorized users and team users. The categories of personal data are account identity data (name, email address, and role within the organization), authentication and session records, billing and tax identity data (including business name, address, and VAT or tax identifier), and usage records of the Customer’s own use of the Service. No sensitive data is transferred. The frequency is continuous for the term of the Agreement. The nature and purpose are administering the customer relationship, billing, identity verification, security and abuse prevention, and meeting Mailkube’s own legal obligations. Retention is as described in the Privacy Policy, subject to the statutory exception in Section 11.

Module One also covers the abuse-prevention, security, and sending-reputation processing for which Mailkube is an independent controller under Sections 2 and 12. For that transfer, the data subjects are the Customer’s email recipients, and the senders and IP address holders whose connections to the Service are handled. The categories of personal data are delivery diagnostics, suppression entries, submission and authentication metadata, and the risk signals and ban records derived from them, in each case only to the extent used for those purposes. Engagement events are not among them, for the reason given in Section 12. No sensitive data is transferred. The frequency is continuous for the term of the Agreement. The nature and purpose are protecting the security, integrity, and sending reputation of the Service, including the abuse prevention and deliverability measures described in the Acceptable Use Policy. Retention is as described in Section 11 and in the notice for email recipients.

Exhibit B. Parties

This Exhibit, together with Exhibit A, is the information required by Annex I of the EU SCCs.

Data exporter. The Customer, whose name, address, and contact details are those given for its Organization in the Agreement and its account, or, where no business details have been submitted for the Organization, the individual owner of the Organization, acting in their own name, whose name and contact details are those given in the account. Its contact person for the purposes of Annex I.A is the person the Customer designates in its account for privacy and legal notices, or failing such designation, that Organization’s owner. Its activities relevant to the data transferred are the sending of transactional and marketing email through the Service and the management of its own audience and contact data. Its role is controller, or processor where the Customer is itself acting as a processor for its own customer, as described in Section 8.3.

Data importer. Mail Tactic Corporation, a Delaware C Corporation (file no. 10537478), registered office c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Contact point for data protection: privacy@mailkube.com. Its activities relevant to the data transferred are the operation of the Service described in Exhibit A. Its role is processor, and controller of the account, billing, and usage data described in Section 12.

Signature and date. The parties agree that acceptance of the Terms by the Customer constitutes execution of the Standard Contractual Clauses by both parties, on the date of that acceptance, as described in Section 14. That execution is of the English version of this Addendum, which is the only contractual version, as described in Section 16. Any signature block appearing on a copy of this Addendum that Mailkube deposits in the Organization’s legal-documents space, or that the Customer downloads, is included for reference purposes only: the operative execution and its date are the acceptance recorded in the Organization’s account, and the Customer block on a deposited copy may be countersigned but need not be.

Mail Tactic Corporation is incorporated in the United States (Delaware). Customer Personal Data is stored at rest in the European Union and operational access to it is performed from within the European Union, subject to the transfers described in Sections 8.1 and 8.2.

Exhibit C. Technical and Organizational Measures

Mailkube maintains the following measures. They are the current description referred to in Section 4 and may be updated provided the level of protection is not degraded. This Exhibit is the information required by Annex II of the EU SCCs.

Assistance with data subject rights. For the purposes of Clause 10(b) of the EU SCCs, the measures by which Mailkube assists the Customer in responding to requests from data subjects are those described in Section 6: self-service export of contacts, suppression entries, and per-recipient sending logs; deletion and rectification of contact and audience data through the contact management dashboard and API; the on-request export route described in Section 11 where the Customer can no longer generate an export within the Service; prompt notification and forwarding of any request Mailkube receives directly; and reasonable cooperation where the self-service tools do not provide what is requested. The scope and extent of that assistance are as stated in Section 6.

Access control and authentication. Identity and access management through a self-hosted identity provider, with support for time-based one-time-password two-factor authentication. Role-based permissions scoped to organization membership. Machine secrets are stored using peppered hashing.

Data access and integrity. Values originating from a request are never interpolated into a query string. Database access that carries request data is performed through a parameterized ORM or, where a datastore has no ORM layer, through server-side parameter binding. A small number of internal maintenance statements, such as cache-table cleanup, compose SQL from a driver-quoted table name and a server clock reading, neither of which originates from a request. Tracking tokens are signed with a secret-keyed hash and verified in constant time.

Transmission security. Personal data is encrypted in transit using TLS, subject to the qualification below for outbound delivery. The public edge terminates TLS and connects to the origin over an authenticated, encrypted origin connection, with no cleartext hop. Outbound delivery to a recipient’s mail server uses opportunistic TLS: the connection is encrypted where the receiving server supports it, and delivery proceeds unencrypted where it does not, because SMTP provides no way to require encryption of an arbitrary receiving server.

Erasure and retention enforcement. A daily automated job enforces the retention periods in Section 11 across a declarative registry of data surfaces. The erasure-archive period in that Section is enforced separately, by an expiration rule on the object store that holds the archives, so that it does not depend on a job running. On erasure, cache entries keyed on personal data are invalidated so that no stale, email-keyed result outlives the data.

Monitoring and logging hygiene. The outcome of each retention run is recorded so that personal data lingering past its window is visible to operators. A logging-hygiene gate and an error-monitoring scrubber keep personal data (including recipient addresses, subject lines, and template variables) out of logs and error reports. The scrubber applies to error reports raised in the dashboard as well as on the server, because dashboard reports are relayed through a proxy that applies the same redaction before they leave.

Abuse prevention. Rate limiting and automated evaluation of sending behaviour protect the Service and its recipients from abuse.

Encryption at rest. Erasure archives and offloaded scheduled-message bodies are encrypted at rest with an application-managed symmetric key and held in a segregated, non-public object-storage bucket. Database-level encryption at rest is not currently implemented; the compensating measures are those described in this Exhibit.

Availability and restoration. Personal data is backed up so that availability and access can be restored in a timely manner after a physical or technical incident. Backups are encrypted at rest and inherit the access controls described above.

Physical security. Physical and environmental security of the facilities in which personal data is stored is provided by the infrastructure Sub-processor named in Section 5, under the contractual obligations described in that Section. Mailkube operates no data centre of its own.

Testing and evaluation. Mailkube reviews the effectiveness of these measures on an ongoing basis, including automated checks in its build pipeline that enforce the logging-hygiene and cache-isolation rules described above, and revises them where a review identifies a deficiency.

Measures applying to Sub-processors. Each Sub-processor listed in Section 5 is bound by contract to technical and organisational measures affording a level of protection equivalent to those in this Exhibit, as described in that Section.