Skip to main content
MailChannels processes email on behalf of customers worldwide, including customers who send messages to or on behalf of individuals in the European Union. This page summarizes how MailChannels approaches GDPR and how to obtain the documents you need to satisfy your own compliance obligations.

Is MailChannels GDPR compliant?

MailChannels complies with the GDPR requirements that apply to its processing activities. MailChannels also complies with applicable Canadian privacy laws, including the British Columbia Personal Information Protection Act (PIPA) and the Personal Information Protection and Electronic Documents Act (PIPEDA). MailChannels acts as both a data controller (for account, billing, and support data it collects directly) and a data processor (for personal data contained in messages that customers submit for delivery). The obligations that apply to a given piece of data depend on which role MailChannels is performing at the time.

Data handling

  • MailChannels does not store copies of delivered email messages. Messages are queued briefly during delivery (seconds to at most a few hours) and are not retained after delivery completes.
  • Email delivery logs are retained for 35 days. Older delivery records are not available.
  • Personal data collected to operate customer accounts is handled as described in the Privacy Policy.
  • MailChannels transfers data internationally between its data centers and cloud regions. For personal data covered by the DPA, it describes safeguards for these transfers, including the European Commission’s 2021 Standard Contractual Clauses (SCCs) when an adequacy decision does not apply.
For details on message metadata that is available for investigating a specific delivery, see Law enforcement requests.

Contractual commitments

MailChannels’ contractual commitments related to GDPR are in the following documents:

Strengthen your GDPR compliance with a DPA

Signing the MailChannels DPA can strengthen your GDPR compliance program when MailChannels processes personal data on your behalf. The DPA documents:
  • The controller and processor relationship between you and MailChannels
  • The nature, purpose, and duration of processing
  • Technical and organizational security measures
  • Security incident notification and assistance with data subject requests
  • Requirements for subprocessors and advance notice of changes
  • Deletion or return of personal data
  • Safeguards for international transfers, including SCCs for EEA and Swiss transfers when required
Signing the DPA does not make your organization GDPR compliant on its own. You remain responsible for your obligations as a controller or processor, including establishing a lawful basis for processing and providing documented instructions to MailChannels.

Request a signed DPA

If your use of MailChannels involves processing personal data subject to GDPR, email privacy@mailchannels.com to request a DPA for e-signature.
A DPA can only be executed on top of an existing agreement with MailChannels, such as acceptance of the Terms of Service. Allow up to two business days for the privacy team to respond.

GDPR contact

For any other GDPR or privacy question, including questions about international data transfers, subprocessors, or MailChannels’ role as controller or processor, email privacy@mailchannels.com.