Legal · Last updated August 2026
GDPR
MailerSpark is committed to helping our customers comply with the EU General Data Protection Regulation (GDPR). This page summarizes how we handle personal data, what controls we provide, and how to request a Data Processing Agreement (DPA).
Roles
You (the MailerSpark customer) are the data controller for the personal data of your contacts. MailerSpark is the data processor — we process data on your behalf, following your instructions, and never use it for our own purposes.
Lawful basis
We process personal data on the lawful basis of performing a contract (your subscription) and our legitimate interest in operating a secure, reliable service.
Controls we provide
- Double opt-in for contact groups
- Suppression list (auto-managed from bounces, complaints, unsubscribes)
- CAN-SPAM-compliant unsubscribe links in every email
- Data export (Settings → Account → Export)
- Account deletion with 30-day data purge
- Audit log on Business and above
- SSRF + IDOR protection, encryption at rest, signed webhooks
Data Processing Agreement
Email legal@mailerspark.app to request our DPA. We'll send a signed copy within 5 business days.
Subprocessors
See the Privacy Policy for the current subprocessor list. We notify customers at least 30 days before adding a new subprocessor.