Data Processing Agreement
Last updated: August 2026
1. Scope and Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between Mailverick ("Processor") and the customer ("Controller") for the use of the Mailverick email delivery platform. This DPA governs the processing of personal data by the Processor on behalf of the Controller in accordance with Article 28 of the GDPR.
2. Definitions
"Personal Data", "Processing", "Data Subject", "Controller", and "Processor" have the meanings given in the GDPR (Regulation (EU) 2016/679).
3. Subject Matter and Duration
The Processor processes personal data on behalf of the Controller for the purpose of delivering transactional emails. Processing begins when the Controller starts using the Service and continues for the duration of the service agreement.
4. Types of Personal Data
The following categories of personal data are processed:
- Email addresses (sender and recipient).
- Names (when included in email headers).
- Email metadata (subject lines, timestamps, delivery status, IP addresses).
- Email message content, processed for delivery and, where applicable, retained for a limited period for security and abuse prevention.
- Custom identifiers provided by the Controller (custom_id fields).
5. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller.
- Ensure that persons authorized to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures.
- Not engage sub-processors without prior written authorization from the Controller.
- Assist the Controller in responding to data subject requests.
- Delete or return all personal data upon termination of the service, at the Controller's choice.
- Make available all information necessary to demonstrate compliance with GDPR obligations.
6. Email Open Tracking and Recipient Consent
Open tracking is carried out only on the Controller's documented instructions. It relies on a small, invisible image (a "tracking pixel") embedded in each email. Under the EU ePrivacy Directive, reading information from a recipient's device through such a pixel requires a lawful basis, and obtaining any consent required from recipients is the responsibility of the Controller.
To enable the Controller to meet that responsibility, the Processor makes open tracking configurable on every send. A default applies at the account level, and each email may override it with one of three modes:
- None: no tracking pixel is inserted and no open is recorded.
- Last open only: only the most recent open is retained; earlier opens are discarded, minimizing the data processed per recipient.
- Full: every open is recorded with its timestamp and technical metadata.
Tracking can also be disabled entirely for a given email, which turns off both open and click tracking. By default the most restricted mode ("last open only") applies, and the Controller remains free to raise, lower, or fully disable it on a per-recipient basis according to the consent it has collected.
7. Data Location
All personal data is stored and processed by the Processor exclusively within the European Economic Area (EEA). The Processor's infrastructure is hosted on European-owned data centers with no exposure to the US Cloud Act, and the Processor initiates no transfer of personal data to third countries.
Event subscribers deliver event data, including recipient email addresses, to a destination the Controller configures and controls. Where that destination lies outside the EEA, the transfer is made solely on the Controller's documented instruction, and the Controller is solely responsible for its lawfulness under Chapter V of the GDPR, including any transfer mechanism or impact assessment required.
8. Security Measures
The Processor implements the following security measures:
- Encryption of data in transit (TLS) and at rest.
- Access controls with role-based permissions.
- Regular security assessments and updates.
- Automated data retention and purging policies.
- Incident detection and response procedures.
9. Data Breach Notification
The Processor shall notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach, providing sufficient information for the Controller to meet its obligations under the GDPR.
10. Sub-Processors
The Processor shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object. The sub-processors engaged as at the date of this DPA are listed below. This list is kept current on this page and also remains available upon request.
- OVHcloud (OVH SAS, 2 rue Kellermann, 59100 Roubaix, France): hosting of servers, databases, and backups, DNS record management, and IP address routing. Processing location: France. This is the only sub-processor with access to the personal data processed under this DPA.
Paddle (Paddle.com Market Ltd, United Kingdom) is not a sub-processor under this DPA. It processes the Controller's own billing data as our payment provider and merchant of record, and has no access to the personal data processed under this DPA; that processing is carried out by Mailverick as controller and is described in our Privacy Policy.
11. Audits
The Processor shall allow and contribute to audits and inspections by the Controller or an authorized auditor, subject to reasonable notice and confidentiality obligations.
12. Termination
Upon termination of the service agreement, the Processor shall delete all personal data within 30 days, unless EU law requires further storage. The Controller may request a copy of the data before deletion.
13. Contact
For DPA-related inquiries, contact us at privacy@mailverick.com.