Technical and organisational measures
Maildroppa maintains the following measures for Customer Personal Data. Implementation may evolve with the state of the art without materially reducing overall protection.
1. Organisation and governance
- documented privacy, security and incident responsibilities;
- confidentiality obligations for authorised personnel;
- role- and task-appropriate privacy and security instructions;
- controlled granting, change and revocation of internal access;
- documented provider review and required data-processing contracts;
- procedures for data-subject requests, instructions, erasure and authority demands.
2. Authentication and access control
- authenticated accounts through Auth0/Okta and role-restricted product and administration interfaces;
- individual internal access based on need and least privilege;
- protection of privileged access and technical secrets; no storage of passwords in plaintext by Maildroppa;
- logging of security-relevant account and administrative events;
- event- and risk-based review and prompt revocation of access no longer required.
3. Transmission and communication security
- encrypted transmission using current HTTPS/TLS connections;
- protected APIs and webhooks using authentication or signature/secret methods where provided;
- domain and sender checks and support for common email-authentication methods;
- protection against abusive requests through proxy, network, rate-limit and security controls.
4. Tenant and purpose separation
- logical allocation of data and access to Customer accounts;
- server-side authorisation for account resources;
- separated roles and purposes for operations, support, billing and Customer processing;
- no use of Customer Personal Data for third-party advertising or list trading.
5. Availability, resilience and recovery
- core application operation on controlled infrastructure in Germany and primary object-data storage in the EU;
- safeguards against network attacks and abusive load;
- service monitoring, error capture and controlled escalation;
- access-restricted backups on a documented schedule;
- controlled recovery procedures;
- reapplication of outstanding erasure and restriction records after restoration.
6. Integrity and secure processing
- technical type, size and access validation for supported uploads;
- controlled software deployment and dependency/vulnerability handling;
- error and security logging with data minimisation;
- safeguards against unauthorised alteration through access control;
- accountable bounce, complaint, unsubscribe and suppression processing.
7. Data protection by design
- required fields and processing limited to purpose; additional Customer fields are configurable;
- export, rectification, erasure and suppression functions support data-subject processes;
- consent and signup flows can record text, source and relevant timestamps;
- open and click measurement is presented as a transparent configuration where the function applies;
- diagnostic and analytics data is pseudonymised or minimised where possible.
8. Erasure and retention
- operational erasure flows for contacts, campaigns, automations, forms, files and related Customer data;
- separation of statutory billing records from operational Customer data;
- limited suppression and security information used only for its protective purpose;
- operational erasure without undue delay after service end and completion of any agreed return; backup expiry under the documented backup cycle;
- return or erasure documented on request.
9. Incident management and review
- documented detection, classification, containment, investigation, remediation and review process;
- notice to Customer without undue delay after awareness of a breach affecting Customer Personal Data;
- recording of timeline, affected systems and data, measures and available impact;
- evidence preservation under access restrictions;
- periodic effectiveness review and risk-based adjustment of measures.