Skip to content
Bring your own SMTP or SES — pay AWS rates, not SaaS rates

Legal · Last updated August 2026

GDPR

MailerSpark is committed to helping our customers comply with the EU General Data Protection Regulation (GDPR). This page summarizes how we handle personal data, what controls we provide, and how to request a Data Processing Agreement (DPA).

Roles

You (the MailerSpark customer) are the data controller for the personal data of your contacts. MailerSpark is the data processor — we process data on your behalf, following your instructions, and never use it for our own purposes.

Lawful basis

We process personal data on the lawful basis of performing a contract (your subscription) and our legitimate interest in operating a secure, reliable service.

Controls we provide

  • Double opt-in for contact groups
  • Suppression list (auto-managed from bounces, complaints, unsubscribes)
  • CAN-SPAM-compliant unsubscribe links in every email
  • Data export (Settings → Account → Export)
  • Account deletion with 30-day data purge
  • Audit log on Business and above
  • SSRF + IDOR protection, encryption at rest, signed webhooks

Data Processing Agreement

Email legal@mailerspark.app to request our DPA. We'll send a signed copy within 5 business days.

Subprocessors

See the Privacy Policy for the current subprocessor list. We notify customers at least 30 days before adding a new subprocessor.