Mailumi
Data Processing Agreement
Last updated
About this agreement
This Data Processing Agreement (“DPA”) is part of the Mailumi terms of service and applies automatically whenever Mailumi processes personal data for you. Accepting the terms when you create an account is enough; you do not need to sign anything. It sets out the processor terms required by Article 28 of the General Data Protection Regulation (GDPR).
Signed copy
If your records require a signed version, email privacy@mailumi.com with your company name, address and the email address of your Mailumi account. You receive a copy signed by Mailumi within one business day.
Parties and roles
You, the customer, are the controller of the personal data in the email you send and receive through Mailumi and in your contact lists. Scadex, trading as Mailumi, a sole proprietorship (eenmanszaak), Stalpaert van der Wielestraat 12, 5344 VR Oss, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 42065103, VAT number NL005468347B34 is your processor. For your own account and billing details, Mailumi is the controller, as described in the privacy notice.
Subject, duration and purpose
Mailumi processes personal data only to provide the service described in the terms: sending, receiving and storing email, tracking delivery, sending campaigns to your contact lists, delivering webhooks and answering support requests. Processing lasts for as long as you use Mailumi and ends when the data is deleted as described below.
Personal data and data subjects
- Data subjects: the recipients of the email you send, the senders of the email you receive, the contacts in your audiences and the people who use your workspace.
- Personal data: email addresses and names; the subject, content and attachments of email; delivery events such as delivered, bounced, opened and clicked, which can include an IP address and email client; unsubscribe status; and anything else you choose to put in an email or contact list.
- Mailumi is not designed for special categories of personal data. If you include them in email, you are responsible for having a legal basis to do so.
Your instructions
Mailumi processes personal data only on your documented instructions: the terms, this DPA and what you do in the dashboard and through the API, SMTP and webhooks. If the law requires us to process data in another way, we tell you first unless the law forbids that. If we believe an instruction breaks data protection law, we tell you.
Confidentiality and security
- Everyone at Mailumi who can access personal data is bound to confidentiality.
- Connections to the API, dashboard, SMTP server and webhooks are encrypted with TLS.
- Passwords are hashed with scrypt, API keys and session tokens are stored only as hashes, and webhook signing secrets are stored encrypted.
- The database and file storage are encrypted at rest and restricted to the European Union.
- Access to production systems is restricted to the people who run Mailumi.
- Email content and attachments are deleted automatically 30 days after an email is sent or received.
- Every part of the service is checked every 5 minutes; the results are public on the status page.
Sub-processors
- You authorise Mailumi to use these sub-processors for the data we process for you:
- Cloudflare, Inc.: hosting, the database and file storage, which are restricted to the European Union.
- Amazon Web Services EMEA SARL: sending and receiving email in the EU (Ireland) region.
- Fly.io, Inc.: the SMTP server in Amsterdam, which passes email sent over SMTP to Mailumi without storing it.
- We email you at least 30 days before we add or replace a sub-processor. You can object on reasonable data protection grounds, and if we cannot resolve your objection you can cancel before the change takes effect.
- Every sub-processor is bound by a written contract with data protection obligations that are at least as protective as this DPA, and Mailumi remains responsible for its sub-processors.
Transfers outside the EEA
Your email data is stored and processed in the European Union. If a sub-processor accesses it from outside the European Economic Area, for example for support or security, the transfer is protected by the European Commission’s Standard Contractual Clauses or an adequacy decision such as the EU-US Data Privacy Framework.
Helping you meet your obligations
- If someone asks us directly to exercise their rights over data you control, we forward the request to you without undue delay and help you answer it.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own reporting obligations.
- We give you the information about the service you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority.
Audits
We make available the information you need to verify that we meet this DPA and Article 28 GDPR, and we allow for and contribute to audits by you or an auditor you appoint who is bound to confidentiality. Ask through privacy@mailumi.com with reasonable notice.
Deletion at the end of the service
Email content and attachments are deleted 30 days after an email is sent or received. When you close your account, we delete the remaining personal data we process for you, unless the law requires us to keep it. Before you close your account, you can retrieve your data through the API.
Liability and order of precedence
The liability terms in the terms of service apply to this DPA. If this DPA and the terms of service conflict on the processing of personal data, this DPA applies.
Law and disputes
This DPA is governed by Dutch law. Disputes are handled by the District Court of Oost-Brabant (Rechtbank Oost-Brabant) in ’s-Hertogenbosch, the Netherlands.