Legal
Data Processing Agreement
Last updated: May 11, 2026
This DPA forms part of the agreement between you ("Controller") and mailzy.us ("Processor") and reflects our commitments under GDPR and similar regimes.
1. Subject matter
We process personal data on your behalf to provision and manage Google Workspace mailboxes and provide related support.
2. Categories of data
- Identification & contact data of you and your end-users.
- Domain provider and outreach tool credentials.
- Mailbox metadata.
- Support correspondence.
3. Sub-processors
We use a limited set of vetted sub-processors: Google LLC (Workspace provisioning), Stripe (payments), Lovable Cloud (hosting & database), and our transactional email provider. A current list is available on request.
4. Security
We apply industry-standard safeguards: TLS in transit, encryption at rest, RLS-isolated database access, AES-256-GCM envelope encryption for sensitive credentials, and audit logging of admin access.
5. Data subject rights
We assist you with access, rectification, deletion, and portability requests through dashboard tools and support requests.
6. International transfers
Where data is transferred outside the EEA, we rely on appropriate safeguards including SCCs.
7. Term
This DPA remains in effect for as long as we process your data. Upon termination, we delete or return data within 30 days unless retention is required by law.
Contact
DPA inquiries: support@mailzy.us