Data Processing Agreement
Last updated: 4 September 2026 · Version 1.0
This Data Processing Agreement (“DPA”) forms part of the Agreement for Maildroppa. It applies whenever Maildroppa processes personal data on behalf of a Customer.
Parties
Controller (“Customer”): the natural or legal person identified as Customer in the Order or Maildroppa account, including an effectively included Customer Affiliate where that Affiliate is controller of Customer Personal Data.
Processor (“Maildroppa”):
Marcus Biel, trading as “Maildroppa”
Dr.-Peter-Hecker-Str. 4b
82031 Grünwald
Germany
Email: support@maildroppa.com
Customer and Maildroppa are together the “Parties”.
1. Scope, term and priority
1.1 This DPA governs Maildroppa’s processing of personal data on behalf of Customer in connection with the service (“Customer Personal Data”). The subject matter, nature, purpose, data-subject categories and data types are described in Schedule 1.
1.2 The DPA takes effect when Customer accepts the Terms, an Order incorporating it or a separate electronic confirmation. It remains in effect for the Agreement term and for as long as Maildroppa processes Customer Personal Data.
1.3 This DPA prevails over the main Agreement for processing on behalf of Customer. Mandatory data-protection law prevails in every case.
1.4 For its own purposes — including contract and billing, Maildroppa’s own account security, protection of the platform and sending infrastructure, abuse prevention and legal duties — Maildroppa may be a separate controller. Such processing is governed by the Privacy Notice, not this DPA. Maildroppa will not use the processor role to use Customer Personal Data for Maildroppa advertising.
2. Definitions and applicable law
2.1 “Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR.
2.2 “Data Protection Law” means the GDPR, the German Federal Data Protection Act and other data-protection law applicable to the particular processing.
2.3 If Customer is itself a processor for another controller, Maildroppa acts as a further processor. Customer warrants that it is authorised to instruct and engage Maildroppa and will make the controller’s information and rights available to Maildroppa to the extent needed to perform this DPA.
3. Customer responsibility and instructions
3.1 Customer is responsible for the lawfulness of processing, data-subject rights, data accuracy and necessity, and its instructions. Customer ensures, in particular, the legal basis, notices, consent where required, retention and erasure decisions, and lawful recipients.
3.2 Documented instructions consist of the main Agreement, this DPA, Customer’s configuration and use of the service, and supplementary instructions in text form. An instruction must not fundamentally change the nature, purpose or scope of the agreed service. Additional instructions may require a separate agreement and reasonable charge.
3.3 Customer must not process special categories under Article 9 GDPR, criminal-conviction and offence data under Article 10 GDPR, complete payment-instrument data, official secrets or other specially protected information in Maildroppa unless Maildroppa expressly approves the specific purpose and safeguards in advance in text form.
3.4 Customer configures available role, export, erasure, consent, tracking and integration functions appropriately for risk and protects accounts, domains, API keys and credentials.
4. Processing only on documented instructions
4.1 Maildroppa processes Customer Personal Data only on Customer’s documented instructions, including for a transfer to a third country, unless Union or Member State law requires processing. In that case Maildroppa informs Customer of the legal requirement before processing unless the law prohibits such information on important grounds of public interest.
4.2 Maildroppa uses Customer Personal Data only to provide, secure, support and end the agreed service and to carry out lawful instructions. Sale, third-party advertising and creation of another party’s recipient list are prohibited.
4.3 If Maildroppa considers an instruction to infringe Data Protection Law, it informs Customer without undue delay and may suspend the affected instruction until it is confirmed, changed or clarified by the competent body. The Parties cooperate in good faith on a lawful alternative.
4.4 Only personnel who need access for their duties may access Customer Personal Data. Before access, those people are bound by confidentiality or an appropriate statutory duty and receive privacy and security instructions.
5. Technical and organisational measures
5.1 Maildroppa implements the measures in Schedule 2 under Articles 28(3)(c) and 32 GDPR. The measures take into account the state of the art, implementation costs, nature, scope, context and purposes, and the likelihood and severity of risk.
5.2 Maildroppa may develop or replace individual measures with equivalent or more effective controls. The overall agreed level of protection must not be materially reduced. Material adverse changes are notified in advance unless immediate action is necessary to address an acute risk.
5.3 Security is a shared responsibility. Maildroppa is not responsible for risks caused solely by unlawful Customer Content, insecure Customer devices, shared credentials, misconfigured Customer integrations or Customer instructions. Maildroppa’s own statutory and contractual duties remain unaffected.
6. Assistance with data-subject rights
6.1 Taking account of the nature of processing, Maildroppa assists Customer by appropriate technical and organisational measures with requests under Chapter III GDPR, including access, rectification, erasure, restriction, portability, objection and information concerning automated decisions.
6.2 Where requested data is available through product functionality, Customer handles the request itself. For additional proportionate support, Maildroppa provides available information or rectifies, exports, restricts or erases data under documented instruction.
6.3 If Maildroppa receives a data-subject request recognisably concerning Customer Personal Data, it informs Customer without undue delay and does not substantively respond unless instructed by Customer or required by law. Maildroppa may tell the data subject that the request has been forwarded to the controller.
6.4 Customer sends only information needed to locate and fulfil the request securely. Maildroppa may charge reasonable, pre-notified costs for manifestly excessive, repeated or non-standard assistance to the extent Article 28 GDPR permits.
7. Compliance, impact assessments and authorities
7.1 Taking account of the nature of processing and information available, Maildroppa assists Customer with Articles 32 to 36 GDPR, including security, breach notification and communication, data-protection impact assessments and prior consultation.
7.2 On reasonable request, Maildroppa supplies information about the service, data flows, measures, subprocessors and known risks needed for Customer’s impact assessment where not already available in the documentation or account.
7.3 If Maildroppa receives a binding authority or court request for Customer Personal Data, it informs Customer before disclosure where legally permitted. Maildroppa assesses authority and scope, discloses only what is legally required and records the matter.
8. Personal data breaches
8.1 Maildroppa notifies Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Initial information may be supplied in phases and will not be delayed until an investigation is final.
8.2 To the extent available, notice includes:
- the nature of the breach, including categories and approximate numbers of affected people and records;
- likely consequences;
- measures taken or proposed to contain and remedy it;
- timing or period and current investigation status;
- a contact point for questions.
8.3 Maildroppa promptly takes reasonable containment, evidence-preservation, root-cause and remediation steps, documents the breach and provides information available for Customer’s Articles 33 and 34 GDPR duties.
8.4 Customer remains responsible for assessment and any supervisory-authority notification within 72 hours of its own awareness and for any communication to data subjects. A Maildroppa notice is not an admission of breach of duty or liability.
8.5 Customer promptly informs Maildroppa of security incidents in Customer’s environment that may affect Customer Personal Data or the service and cooperates with mitigation.
9. Subprocessors
9.1 Customer gives general written authorisation for the subprocessors in Schedule 3. Maildroppa remains responsible to Customer for a subprocessor’s performance of its Article 28(4) GDPR obligations.
9.2 Maildroppa contractually binds every subprocessor to substantially the same level of data protection for the relevant service, including instructions, confidentiality, security, assistance, erasure and audit rights.
9.3 Maildroppa generally gives at least 30 days’ notice before adding or replacing a subprocessor to the business email address stored in the account and publishes the dated change in the subprocessor list. A shorter period may apply for urgent security or availability needs; Maildroppa explains the reason and gives notice as early as possible.
9.4 Customer may object within the notice period on specific, substantiated data-protection grounds. The Parties seek a reasonable solution, such as a configuration change. If none is possible and the objection is justified, Customer may terminate the main Agreement for cause without an additional charge before the new subprocessor is used. Purely commercial or competitive objections are insufficient.
9.5 Services that do not process Customer Personal Data, and recipients or integrations connected by Customer under its instruction, are not Maildroppa subprocessors. This includes a service for which Customer connects and contracts through its own third-party account.
10. International transfers
10.1 Maildroppa transfers Customer Personal Data outside the European Economic Area only on documented instructions and in compliance with Chapter V GDPR.
10.2 Where there is no applicable adequacy decision, Maildroppa enters into the then-current European Commission Standard Contractual Clauses with the importer. Module 2 generally applies where Customer is controller and Module 3 where Customer is processor. This DPA and its Schedules complete the corresponding SCC Annexes.
10.3 Where a provider is validly certified under the EU-US Data Privacy Framework for the relevant data, the adequacy decision may be used. Maildroppa monitors relevant certification at reasonable intervals and maintains an alternative mechanism where needed to continue the transfer.
10.4 Maildroppa documents a transfer impact assessment where required and uses supplementary technical, contractual or organisational measures appropriate to the relevant law, access possibility and data risk. Customer supplies information needed to assess its own instructions.
11. Return and erasure
11.1 During the Agreement, Customer may use available export and erasure functions. Before contract end, Customer may request return of operational Customer Personal Data in an available, commonly used machine-readable format.
11.2 After services end, Maildroppa erases all Customer Personal Data and copies without undue delay unless Customer previously requests return or Union or Member State law requires retention. Erasure begins once any agreed return is complete. On request, Maildroppa confirms erasure in text form.
11.3 Data remaining in access-restricted backups is not used for new production purposes and is overwritten under the documented regular backup cycle. Until then, it remains blocked from regular access. If a backup is used for recovery, Maildroppa promptly reapplies outstanding erasure, objection and restriction records.
11.4 Legally retained data and minimal information strictly needed for security, abuse prevention or permanent observance of unsubscribes is isolated, access-restricted and used only for that purpose, then erased when no longer needed. Maildroppa identifies the category and legal basis to Customer where not already documented.
12. Information and audits
12.1 Maildroppa provides information necessary to demonstrate compliance with Article 28 GDPR and this DPA. This may include current TOMs, subprocessor and transfer information, appropriate certifications, audit reports, questionnaires and erasure confirmations.
12.2 If those materials do not resolve a substantiated risk, Customer or an independent competent auditor bound to confidentiality may conduct an audit. Audits normally occur no more than once in twelve months, with at least 30 days’ notice, during ordinary business hours and without avoidable disruption to other customers or security.
12.3 An additional or shorter-notice audit is allowed where justified by a Personal Data Breach, specific material concern or supervisory-authority direction. Maildroppa may make highly sensitive security material available through a suitable third-party report and limit access to other customers’ data, source code, vulnerabilities or trade secrets where the audit purpose can still be achieved.
12.4 Each Party bears its own costs. Where an audit creates substantial work beyond statutory duties or finds no material Maildroppa non-compliance, Maildroppa may charge reasonable costs agreed in advance. If it identifies material Maildroppa non-compliance, Maildroppa bears reasonable audit costs and remedies the matter without undue delay.
12.5 Maildroppa maintains records of categories of processing under Article 30(2) GDPR and cooperates with the competent supervisory authority on request.
13. Liability
13.1 Liability between the Parties is governed by Article 82 GDPR, other mandatory Data Protection Law and the effective liability provisions of the main Agreement. Nothing in this DPA limits data-subject rights or supervisory-authority powers.
13.2 As between the Parties, each is responsible for loss and cost to the extent caused by its culpable breach of this DPA, statutory duty or lawful responsibility. Statutory rights of recourse remain unaffected.
14. Termination for data-protection breach
14.1 If Maildroppa materially breaches this DPA, Customer may suspend the affected processing until it is remedied. If Maildroppa does not remedy a material breach within a reasonable period, or remedy is impossible, Customer may terminate the affected service for cause.
14.2 Maildroppa may suspend an unlawful instruction under clause 4.3. If no lawful alternative can be found and continuation would infringe Data Protection Law, Maildroppa may terminate the affected processing. Return, erasure and evidence duties remain.
15. Final provisions
15.1 Amendments are agreed in text form or incorporated through a demonstrable electronic process. Schedules may be updated to reflect actual processing where the overall protection is not materially reduced and DPA notice and objection rights are observed.
15.2 If a provision is invalid, the remaining provisions remain effective and statutory rules replace it.
15.3 German law and the venue provision of the main Agreement apply to the extent mandatory Data Protection Law does not require otherwise.
15.4 This English version is provided for convenience. If it conflicts with the German version, the German version prevails unless mandatory law requires otherwise.
Schedule 1 – Description of processing
1. Subject matter and purpose
Provision of the cloud-based Maildroppa service for permission-based email marketing, including contact and list management, forms and Signup Flows, campaigns, templates, automations, sending, delivery and interaction reports, files, integrations, exports, support, security, backup and contractual erasure.
2. Duration
The main Agreement term plus the return, erasure and backup-expiry period in clause 11.
3. Nature of processing
Collection through Customer forms, recording, organisation, structuring, storage, adaptation, segmentation, matching, retrieval, display, import, export, transmission, sending, logging, analysis, restriction, backup and erasure under Customer instruction.
4. Categories of data subjects
- Customer subscribers, prospects, leads, customers and other business contacts;
- visitors and submitters to Customer forms and landing pages;
- recipients of Customer campaigns, automations and transactional messages;
- other individuals whose data Customer lawfully submits to the service.
5. Categories of personal data
- identity and contact data: name, email address and business contact information entered by Customer;
- Customer-defined profile fields, tags, segments, lists and audience assignments;
- consent, source and evidence data: signup source, form, consent wording, timestamps, confirmation and unsubscribe status, and IP/browser metadata where enabled and lawful;
- technical form and abuse data: screen dimensions, browser and operating-system version, a derived device identifier, IP/request data and a last popup-display time stored in the browser where Customer embeds the form loader accordingly;
- campaign, form, automation, template and message content;
- delivery and interaction data: delivery status, open and click events where enabled and lawful, bounces, complaints, unsubscribes and suppressions;
- technical data: IP address, device, browser, request, security, log and error information;
- files, attachments and content uploaded by Customer;
- integration, import, export and support information, including third-party identifiers submitted by Customer.
6. Special data
Processing of Article 9 special categories and Article 10 criminal-conviction data is not part of the service and is prohibited unless expressly agreed in advance in text form for a specific purpose with additional safeguards.
7. Frequency and volume
Continuous, at the volume determined by Customer’s use, configuration, recipients, plan and instructions.
8. Customer rights and duties
Customer’s rights and duties arise from this DPA, the main Agreement and Data Protection Law. Customer decides in particular the purposes, legal bases, data categories, recipients, configuration, retention and response to data-subject rights.
Schedule 2 – Technical and organisational measures
Maildroppa maintains the following measures for Customer Personal Data. Implementation may evolve with the state of the art without materially reducing overall protection.
1. Organisation and governance
- documented privacy, security and incident responsibilities;
- confidentiality obligations for authorised personnel;
- role- and task-appropriate privacy and security instructions;
- controlled granting, change and revocation of internal access;
- documented provider review and required data-processing contracts;
- procedures for data-subject requests, instructions, erasure and authority demands.
2. Authentication and access control
- authenticated accounts through Auth0/Okta and role-restricted product and administration interfaces;
- individual internal access based on need and least privilege;
- protection of privileged access and technical secrets; no storage of passwords in plaintext by Maildroppa;
- logging of security-relevant account and administrative events;
- event- and risk-based review and prompt revocation of access no longer required.
3. Transmission and communication security
- encrypted transmission using current HTTPS/TLS connections;
- protected APIs and webhooks using authentication or signature/secret methods where provided;
- domain and sender checks and support for common email-authentication methods;
- protection against abusive requests through proxy, network, rate-limit and security controls.
4. Tenant and purpose separation
- logical allocation of data and access to Customer accounts;
- server-side authorisation for account resources;
- separated roles and purposes for operations, support, billing and Customer processing;
- no use of Customer Personal Data for third-party advertising or list trading.
5. Availability, resilience and recovery
- core application operation on controlled infrastructure in Germany and primary object-data storage in the EU;
- safeguards against network attacks and abusive load;
- service monitoring, error capture and controlled escalation;
- access-restricted backups on a documented schedule;
- controlled recovery procedures;
- reapplication of outstanding erasure and restriction records after restoration.
6. Integrity and secure processing
- technical type, size and access validation for supported uploads;
- controlled software deployment and dependency/vulnerability handling;
- error and security logging with data minimisation;
- safeguards against unauthorised alteration through access control;
- accountable bounce, complaint, unsubscribe and suppression processing.
7. Data protection by design
- required fields and processing limited to purpose; additional Customer fields are configurable;
- export, rectification, erasure and suppression functions support data-subject processes;
- consent and signup flows can record text, source and relevant timestamps;
- open and click measurement is presented as a transparent configuration where the function applies;
- diagnostic and analytics data is pseudonymised or minimised where possible.
8. Erasure and retention
- operational erasure flows for contacts, campaigns, automations, forms, files and related Customer data;
- separation of statutory billing records from operational Customer data;
- limited suppression and security information used only for its protective purpose;
- operational erasure without undue delay after service end and completion of any agreed return; backup expiry under the documented backup cycle;
- return or erasure documented on request.
9. Incident management and review
- documented detection, classification, containment, investigation, remediation and review process;
- notice to Customer without undue delay after awareness of a breach affecting Customer Personal Data;
- recording of timeline, affected systems and data, measures and available impact;
- evidence preservation under access restrictions;
- periodic effectiveness review and risk-based adjustment of measures.
Schedule 3 – Authorised subprocessors and transfers
The following list applies to the relevant functions; not every provider processes the same data for every Customer. Maildroppa verifies the legal entity, region and transfer mechanism against the actual contract before first use and after a material change.
| Subprocessor | Service and possible data | Primary location | Third-country mechanism where required |
|---|---|---|---|
| Hetzner Online GmbH, Germany | Core hosting, compute, database and network; Customer Personal Data needed for the service | Germany | no third-country transfer for regular EEA operations |
| Cloudflare, Inc., United States, and contracted entities | DNS, proxy, CDN, WAF, DDoS and security; IP, request, domain, traffic and, for proxied processing, transmitted content data | EU and global edge locations; possible US access | EU-US Data Privacy Framework for certified US recipients and/or SCCs with supplementary safeguards |
| Amazon Web Services EMEA SARL, Luxembourg, and contracted AWS entities | Object storage and technical cloud services; files, templates and related metadata | primarily Frankfurt, Germany (eu-central-1); possible global support access | adequacy decision where applicable, otherwise SCCs with supplementary safeguards |
| Bird B.V., Netherlands, including the SparkPost email platform and service affiliates | Email transmission, delivery events, bounces and complaints; recipient address, sender, message body and sending metadata | SparkPost EU endpoint configured technically; possible support or group access outside the EEA | for third-country access, EU-US Data Privacy Framework where applicable and/or SCCs with supplementary safeguards |
| Okta, Inc., United States, and contracted Auth0/Okta entities | Authentication and account access; account user, login identifier, email, security and session metadata | EU region where enabled; possible US access | EU-US Data Privacy Framework for certified recipients and/or SCCs with supplementary safeguards |
| SmartBear Software, Inc., United States, and affiliates (Bugsnag) | Error diagnostics and operational monitoring; pseudonymous account/user identifier, error, device, request and release metadata | selected Bugsnag region; possible US access | EU-US Data Privacy Framework for certified recipients and/or SCCs with supplementary safeguards |
Auth0/Okta is included in this Schedule only to the extent that it processes Customer Personal Data as a subprocessor in a particular data flow. Maildroppa’s controller processing of account-user data for its own contract, account and authentication purposes is governed by the Privacy Notice and is outside this DPA.
Change notices
Maildroppa informs Customers at the business email address stored in the account and publishes a dated version of this list. The notice identifies the provider, purpose, location, mechanism and intended start date. The objection process is governed by clause 9.
Customer-directed integrations
Zapier, Make and other services connected by Customer are not automatically Maildroppa subprocessors. Where Maildroppa transmits data to such an integration under Customer instruction, Customer is responsible for recipient selection, authority, privacy notices, contracts and international-transfer mechanisms.