Skip to content
MailHaap
[01]Last updated 21 August 2026

Data processing agreement

The processor terms, the sub-processors, and the transfer mechanism.

Roles and scope

You are the controller of the personal data in your contacts, your recipients and your message content. MailHaap is the processor. We process that data only on your documented instructions, which are: to deliver the messages you send, to record the events those messages generate, and to operate the suppression and consent records that keep both of us compliant.

Sub-processors

Sub-processors and what each one touches
Sub-processorPurposeLocation
Amazon Web ServicesOutbound delivery and key managementeu-central-1 (Germany)
CloudflareEdge, CDN, object storage, tracking workerEU jurisdiction
HetznerCompute and databasesGermany and Finland
StripeBilling and payment processingEU / US, SCCs in place
MaxMindGeolocation database licenceNo data transferred — the database is a local file

The geolocation note matters

MaxMind appears on this list as a licensor, not as a recipient of data. Geolocation runs against a local database file, so no recipient IP address is ever sent to them. A per-request lookup API would have made every recipient IP a transfer to a third party — which is one of the reasons we rejected that approach.

Transfers

Production data stays in the EU by default. Where a sub-processor's group includes entities outside the EEA, transfers are covered by Standard Contractual Clauses with the supplementary measures the platform already implements: encryption at rest with keys held separately from the storage provider, no standing human access, and full audit logging of every decryption.

Security measures

  • Envelope encryption with a per-workspace key, bound to the workspace by additional authenticated data — a ciphertext moved between workspaces fails to decrypt.
  • Row-level security enforced in the database, so even a query missing its tenant clause returns nothing.
  • No standing production access. Access is time-boxed, request-based, approved by a second person, and session-recorded.
  • Mandatory two-factor authentication for any account that can send or manage domains.
  • Continuous backups to a different provider than production storage, with monthly timed restore drills.

Breach notification

Detection, containment, assessment within 24 hours, and notification to affected controllers within 48 hours — giving you a full day inside your own 72-hour obligation. The contact tree and the notification templates are written in advance, because writing them during an incident is how deadlines get missed.