Last updated: 4 September 2026 · Version 1.0
This Privacy Notice explains how Maildroppa processes personal data when you visit our website, create or manage a Maildroppa account, communicate with us or use another service for which Maildroppa determines the purposes. Data that business customers place in Maildroppa for their own recipients is addressed separately under
1. Controller and contact details
The controller under the General Data Protection Regulation (GDPR) is:
Marcus Biel, trading as “Maildroppa”
Dr.-Peter-Hecker-Str. 4b
82031 Grünwald
Germany
Telephone: +49 171 1151013
General and privacy enquiries: contact form
Illegal content, spam or other abuse can also be reported through Report illegal content and abuse.
Privacy requests reach Maildroppa through the privacy contact above. Where a data protection officer is designated or a statutory designation duty arises, that officer’s direct contact details will be published here.
2. Who this Notice covers
This Notice covers, in particular:
- visitors to our website and publicly hosted Maildroppa pages;
- prospects, trial users, customers and their authorised account users;
- people who send support, privacy or abuse requests;
- recipients of Maildroppa’s own sales and product communications;
- people whose data we process for our own contract, security, billing or abuse-prevention purposes.
Maildroppa is offered only to businesses and not to consumers or children. Account users must be at least 18 years old.
3. Our roles
Maildroppa as controller
Maildroppa is the controller where we determine the purposes and essential means of processing. This includes operating the website, prospect communications, contract and account administration, authentication, billing, our own product communications, security, fraud and abuse prevention, and legal obligations.
Maildroppa as processor
Where a customer processes recipient lists, campaigns, form submissions, automations or similar customer data in Maildroppa, the customer generally determines the purposes and essential means. Maildroppa processes that data as processor under the customer’s documented instructions. Our Data Processing Agreement under Article 28 GDPR applies.
Data subjects should generally address a request concerning such customer data to the relevant sender or Maildroppa customer. Where we can securely identify that customer, we forward the request and assist under the DPA. We do not independently decide the lawfulness of a customer campaign or exceptions to data-subject rights.
For narrowly limited purposes — in particular provider-level complaint and abuse signals, platform and network security, protection of sending infrastructure, prevention of unlawful use and our own legal obligations — Maildroppa may be controller for particular metadata. Those purposes are not combined with advertising for Maildroppa. Clause 4.12 provides details.
4. Data, purposes, legal bases and retention
4.1 Website delivery and technical security
When our website or a public page is requested, we process information such as IP address, date and time, requested URL, referrer, browser and device details, HTTP status, transferred volume and security or error indicators.
We use the data to deliver the page, maintain stability, investigate errors, protect against attacks and abuse, and evidence security-relevant events. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are a secure, available and accountable service. Storage of or access to device information that is strictly necessary for a service expressly requested by the user is governed by section 25(2) TDDDG. We use non-essential device access only on the basis of valid consent under section 25(1) TDDDG.
Routine web and security logs are erased under the documented operational cycle when no longer needed for delivery, diagnostics and protection. Security-relevant extracts may be retained until an incident is resolved and for the applicable period for legal claims.
4.2 Technically necessary settings
Where necessary for a session, language, security, login or another function you expressly request, we store or read the required information in the browser. These operations serve only the requested function and are governed by section 25(2) TDDDG. Session information ends with the session; other necessary settings remain only as long as required for the relevant function or security purpose.
4.3 Audience and product analytics
We use Plausible Analytics to obtain aggregate information about page views, sources, browser, operating system, device class, approximate location, outbound links and selected events such as a click to registration. In our integration, Plausible uses no cookies, local storage or persistent identifier across devices or users. IP address and User-Agent are used to process a request but are not stored in raw form; a daily rotating identifier cannot be linked across days or websites.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is privacy-conscious aggregate measurement and improvement of the website and product. The provider is Plausible Insights OÜ, Estonia; according to the provider, visitor data is processed in the EU. Google Ads and Google Tag Manager are not currently used on the website.
4.4 Embedded videos and external content
Individual pages may embed YouTube or Spotlightr videos and other external media. The external player itself is loaded only when you deliberately activate playback. A preview image may be retrieved locally or from the relevant provider beforehand. For an external request, the provider technically receives information including IP address, browser and device details, the requested page and time. After player activation, further usage and, if you are signed in with the provider, account information may be processed.
Retrieving a preview image is based on Article 6(1)(f) GDPR; our legitimate interest is an informative, data-minimising video preview. Deliberately activating the external player is a request for that content; necessary device access is governed by section 25(2) TDDDG. The provider’s own privacy notice applies to its subsequent processing.
4.5 Contact, support, privacy and abuse reports
When you contact us, we process contact details, company and account context, the message and attachments, technical metadata, our response and case notes. An abuse report may also include the reported URL, sender, headers, campaign identifier, reasons, evidence and good-faith statement.
Purposes are responding to the request, entering into or performing a contract, complying with legal duties, defending claims and protecting recipients and the platform. Depending on the request, the legal basis is Article 6(1)(b), (c) or (f) GDPR. Our legitimate interests are accountable case handling, abuse prevention and legal defence.
General cases are normally retained for three years from the end of the calendar year in which they close. A case may remain longer where required by law, an investigation, an authority request or a legal claim. Attachments and identity evidence that are clearly no longer needed are erased earlier.
4.6 Registration, account, authentication and contract
At registration and during use, we process name, business contact details, company, address, country, language, login and authentication identifiers, roles, account settings, contract and plan details, acceptance versions, usage and security events, and necessary communications.
Purposes are entering into and performing the contract, providing and administering the service, authenticating authorised users, recording contractual declarations and providing support. The legal basis is Article 6(1)(b) GDPR, supplemented by Article 6(1)(f) GDPR for security and evidence.
Operational account data is erased under the documented termination and erasure process when no longer needed for return, winding down or a lawful restriction period. Contract and evidence data may remain until applicable limitation periods expire.
4.7 Billing and payment
For quotations, orders, payments, credits and invoices, we process name, company, address, VAT ID, plan, amount, currency, payment status, transaction identifiers and correspondence. Full card or bank details are generally processed by Stripe and only the status and billing information needed by Maildroppa are returned to us.
The legal bases are Article 6(1)(b) GDPR for contract and payment and Article 6(1)(c) GDPR for commercial and tax duties. Accounting vouchers are generally retained for eight years and commercial books and records subject to longer statutory retention for ten years, in each case from the end of the relevant calendar year. Where Stripe uses data for its own regulatory purposes, it acts under its own data-protection responsibility for those purposes.
4.8 Account security, fraud and abuse prevention
To protect the service, sending reputation and other users, we process account, domain, sender, payment, network, usage, delivery, bounce, complaint and risk signals. These may include IP address and country, email and domain characteristics, unusual login or sending patterns, evidence of list origin, complaint rates and account-review results.
The legal basis is Article 6(1)(f) GDPR and, for a legal reporting or cooperation obligation, Article 6(1)(c) GDPR. Our legitimate interests are preventing spam, fraud, phishing, malware, unauthorised access and reputational harm. Automated signals may trigger a review, evidence request or immediately necessary temporary protective measure. Where a decision produces legal or similarly significant effects concerning a natural person, the statutory requirements for automated decisions apply; that person may request human review and present their position.
Unconfirmed routine risk signals are erased when no longer needed to assess and protect the service. Confirmed violations, restriction and complaint evidence may remain for necessary protection and limitation periods. A minimal, access-restricted suppression record may remain where necessary to prevent renewed unwanted communication or evasion.
4.9 Error diagnostics and operational monitoring
When an error occurs, we may process error time, affected function, pseudonymous account or user identifier, device, browser, operating system, release, stack and request metadata. Content and direct identifiers are minimised or removed before transfer where possible.
Purposes are troubleshooting, security and availability, based on Article 6(1)(f) GDPR. Diagnostic data is erased under the configured provider and operational cycle when no longer needed for troubleshooting, security or a particular support case.
4.10 Our service and marketing communication
We send contractual and security messages where necessary to perform the contract under Article 6(1)(b) GDPR. Newsletters and other advertising rely on consent under Article 6(1)(a) GDPR and section 7 UWG or, within the narrow statutory existing-customer exception for our similar services, Article 6(1)(f) GDPR together with section 7(3) UWG.
You can opt out of marketing at any time free of charge. After withdrawal or objection, we retain a minimal suppression and evidence record where needed to honour the choice and demonstrate prior lawfulness. Consent records are normally retained until three years after the end of the calendar year in which consent was last used or withdrawn.
4.11 Customer content and recipient data
Customers may process contact details, custom fields, tags, segments, consent and source evidence, form submissions, campaign and automation content, delivery, open, click, bounce, complaint and unsubscribe data, files and integration data in Maildroppa. The customer determines the specific scope.
Where a customer embeds the Maildroppa form loader on its website, the loader may derive a technical identifier from screen dimensions, browser and operating-system details and transmit it with the form request to Maildroppa for form-abuse checks. To control repeated display of a popup form, the loader may also store the last display time in browser local storage. The customer decides on embedding and configuration, must describe these device operations in its own privacy notice and assess their lawfulness under applicable law.
Maildroppa generally processes this data only to provide, secure and support the service under documented customer instructions. For Maildroppa, the contractual basis is Article 6(1)(b) GDPR in relation to the customer together with Article 28 GDPR; the customer determines the legal basis in relation to each data subject. Processing details, categories, erasure and subprocessors are in the DPA.
Special categories of personal data under Article 9 GDPR and criminal-conviction data under Article 10 GDPR are not intended for the service and must not be uploaded or processed.
4.12 Provider-level complaint, delivery and abuse signals
Maildroppa generally processes delivery events, bounces, complaints, unsubscribes and suppressions on behalf of the relevant customer. Where Maildroppa separately needs particular metadata to protect the platform, sending infrastructure or other recipients, Maildroppa determines that narrowly limited purpose itself. Sources include customer configurations, delivery-provider feedback, recipient actions and abuse reports. Data may include a recipient address or derived suppression identifier, sender and domain, message or campaign identifier, event type, time, reason, and handling or review status.
The legal basis is Article 6(1)(f) GDPR. Legitimate interests are observing complaints and objections, preventing repeated unwanted communication, preventing abuse and protecting shared sending reputation. Information is limited to the necessary protection and evidence scope and erased or anonymised when that purpose and necessary limitation or restriction periods end. The relevant customer provides the primary information about its communication; this Notice supplies the additional information about Maildroppa’s separate purposes.
5. Recipients and service providers
Personal data is disclosed only to recipients that need it for the purposes above. These may include:
- Marcus Biel and, where engaged, expressly authorised persons and professional advisers bound to confidentiality;
- the technical provider used for the published support mailbox and its incoming and outgoing communication;
- Hetzner Online GmbH for core hosting and infrastructure in Germany;
- Cloudflare, Inc. for DNS, content delivery, proxy and security functions;
- Amazon Web Services EMEA SARL and relevant AWS entities for object storage and technical cloud services, primarily in Frankfurt;
- SparkPost/Bird for transactional and customer email delivery;
- Okta/Auth0 for authentication and account access;
- Bugsnag/SmartBear for error diagnostics;
- Plausible Insights OÜ for privacy-conscious website and product analytics;
- Stripe Payments Europe, Limited and relevant Stripe entities for payments;
- YouTube/Google and Spotlightr for external preview images where used and, after deliberate activation, for the relevant player;
- legal, tax and security advisers, authorities and courts where necessary or legally required.
For data processed by Maildroppa as processor, the current subprocessor list applies. Services such as Zapier, Make or other integrations connected by the customer receive data under the customer’s instruction and responsibility; the customer must assess those recipients, contracts and transfers.
We do not sell personal data or disclose it for another party’s direct advertising.
6. International transfers
Some providers or support entities are outside the European Economic Area. Where personal data is transferred to or accessed from a third country, we use an appropriate mechanism under Chapter V GDPR, particularly an adequacy decision, including valid participation in the EU-US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses.
Where Standard Contractual Clauses are used, we assess relevant laws and practices and any supplementary technical, contractual and organisational safeguards. Recipients, regions and transfer mechanisms used for customer data are in the subprocessor and transfer list. A copy of relevant safeguards may be requested through our contact form; trade secrets and security details may be redacted.
7. Retention, erasure and backups
Specific periods appear above. Where no fixed period is stated, we erase or anonymise data when its purpose ends and no legal duty, restriction need, continuing investigation or legal defence requires it. We consider purpose, sensitivity, volume, risk and statutory limitation periods.
Operational customer data is returned or erased without undue delay under the DPA after the service and any agreed return are complete. Data in access-restricted backups is not used for new production purposes and is overwritten under the documented backup cycle. If a backup must be restored, due erasure, objection and restriction records are reapplied.
Legally retained billing and contract records, minimal suppression information and security or abuse evidence are separated and purpose-limited. They are not used for new marketing campaigns.
8. Required information
Website visitors generally need not provide additional contractual information. Data marked as required for registration, authentication, contract, payment and security review is necessary; without it we may be unable to provide an account or particular function. Optional information is identified or clear from context.
9. Your rights
Where the legal requirements are met, you have rights to:
- access under Article 15 GDPR;
- rectification under Article 16 GDPR;
- erasure under Article 17 GDPR;
- restriction under Article 18 GDPR;
- data portability under Article 20 GDPR;
- objection under Article 21 GDPR;
- withdraw consent with future effect;
- complain to a data-protection authority.
Objection: Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons; the data will then no longer be processed for that purpose.
Use our contact form. We may request information needed to confirm identity and safely locate data. We generally respond within one month; where legally permitted, complex or numerous requests may take up to two additional months.
If the request concerns customer data for which a Maildroppa customer is controller, please contact that customer. We will assist it with the response.
10. Right to complain
You may complain to a data-protection authority. Maildroppa’s competent local authority is generally:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de
You may also contact the authority for your habitual residence, workplace or the place of an alleged infringement.
11. Security
We use technical and organisational measures intended to provide a level of security appropriate to the risk, taking into account the state of the art, implementation costs, nature, scope, context and purposes. These include encrypted transfer, authenticated and role-restricted access, tenant separation, security logging, infrastructure protection and procedures for incidents, backups, recovery and erasure.
The binding measures for processing on behalf of customers are in the technical and organisational measures. No internet-based service can guarantee absolute security.
12. Changes to this Notice
We update this Notice where processing, providers or the legal position changes materially. The current version and date are available on this page. We also provide appropriate additional notice of material changes affecting an account or an existing choice.