Legal

Data Processing Agreement

Last updated: May 11, 2026

This DPA forms part of the agreement between you ("Controller") and mailzy.us ("Processor") and reflects our commitments under GDPR and similar regimes.

1. Subject matter

We process personal data on your behalf to provision and manage Google Workspace mailboxes and provide related support.

2. Categories of data

  • Identification & contact data of you and your end-users.
  • Domain provider and outreach tool credentials.
  • Mailbox metadata.
  • Support correspondence.

3. Sub-processors

We use a limited set of vetted sub-processors: Google LLC (Workspace provisioning), Stripe (payments), Lovable Cloud (hosting & database), and our transactional email provider. A current list is available on request.

4. Security

We apply industry-standard safeguards: TLS in transit, encryption at rest, RLS-isolated database access, AES-256-GCM envelope encryption for sensitive credentials, and audit logging of admin access.

5. Data subject rights

We assist you with access, rectification, deletion, and portability requests through dashboard tools and support requests.

6. International transfers

Where data is transferred outside the EEA, we rely on appropriate safeguards including SCCs.

7. Term

This DPA remains in effect for as long as we process your data. Upon termination, we delete or return data within 30 days unless retention is required by law.

Contact

DPA inquiries: support@mailzy.us