Privacy at Maildroppa

GDPR support you can assess

Maildroppa supports permission-based email marketing with double-opt-in flows, documented consent, unsubscribe handling, bounce and complaint processing, exports and controlled integrations. Lawful contact acquisition, information to data subjects and your specific use of the data remain your responsibility.

No email-marketing platform can make every customer workflow “GDPR compliant” on its own. Maildroppa therefore does not issue a blanket compliance guarantee. Instead, it makes roles, data flows, contracts, subprocessors and security measures available for review.

Documentation available for your review

Roles without fine print

As controller, you decide why and how you use your subscribers’, prospects’ and customers’ data for email marketing. Maildroppa generally processes that data as your processor under documented instructions.

For its own purposes — including contract, billing, account security, abuse prevention and legal obligations — Maildroppa is itself a controller. These activities are described separately in the Privacy Notice rather than being hidden inside the processor role.

Location and service providers

Maildroppa is developed and operated in Germany. Core infrastructure and primary storage are located in Germany and the EU. Disclosed providers are used for delivery, authentication, protection, diagnostics and payment, which can create additional processing and access paths. The current subprocessor and transfer list is therefore more accurate than the abbreviated promise “Germany only”.

Product controls

Build and document permission

Signup Flows can connect a form, confirmation email and post-confirmation response. Maildroppa records the consent wording used and relevant timestamps. Whether consent is required and valid depends on your design, audience and applicable law.

Respect unsubscribes and delivery problems

Marketing emails contain an unsubscribe facility. Unsubscribes, complaints and hard bounces are taken into account for future delivery. A minimal suppression record may need to remain so that a deleted or re-imported address is not contacted accidentally.

Embed forms transparently

The Maildroppa form loader may transmit an identifier derived from screen, browser and operating-system characteristics for abuse checks and may store the last display time in local storage for popup forms. If you use the loader on your website, you must describe that data flow and device access in your own privacy notice and assess the required legal basis or consent.

Export and correct data

Customer export and editing features support contact-data management. A product export is not automatically a complete Article 15 GDPR response; associated metadata, recipients, purposes and exceptions may also need to be considered.

Protect access and transfer

Maildroppa uses authenticated accounts, role-restricted interfaces, encrypted transfer, tenant separation, domain and sender checks, safeguards against abusive requests, and type, size and access validation for supported uploads. The binding current description is in the technical and organisational measures.

Decisions you remain responsible for

  • the legal basis and permitted purpose for every contact;
  • transparent information and, where required, consent;
  • required fields, free-text fields, segments and retention periods;
  • permitted content, audiences and sending countries;
  • configuration of open/click measurement and embedded technology;
  • contracts and data flows for your own integrations;
  • assessment and response to data-subject requests.

Anti-spam protects privacy and infrastructure

Maildroppa prohibits purchased, rented, scraped or brokered lists and mass cold email. Higher-risk business models are excluded or reviewed before activation. This protects recipients, legitimate customers and shared sending reputation. Details are in the Anti-Spam and Acceptable Use Policy.

Frequently asked questions

Is Maildroppa GDPR compliant?

Maildroppa provides an Article 28 agreement, documented data flows and privacy controls and commits to the GDPR duties that apply to Maildroppa. Whether your particular use is lawful also depends on your purposes, legal bases, content and settings.

Is all data processed only in Germany?

No. Core infrastructure and primary storage are located in Germany or the EU. Disclosed providers support specific functions. Where a third-country connection exists, the transfer list describes the mechanism and supplementary assessment.

Does double opt-in replace a legal assessment?

No. Double opt-in is an important confirmation and evidence mechanism. It does not make an unclear or prohibited purpose lawful.

What happens after cancellation?

Access ends under the Terms. At the customer’s choice and under the DPA, operational customer data is returned or erased without undue delay. Legally required billing data, necessary suppression and security records, and access-restricted backups follow separate, purpose-limited rules.

How does Maildroppa report a personal-data breach?

As processor, Maildroppa informs the affected controller without undue delay, provides available information and assists with assessment. The controller’s potential 72-hour supervisory-authority deadline runs from the controller’s awareness; it should not wait for a final incident report.

Try Maildroppa for free
Review the privacy documentation

No credit card. No compliance autopilot. A transparent tool for permission-based email marketing.