Legal

Data Processing Addendum

Last updated: July 12, 2026

Template notice. This document is a plain-language starting point and is not legal advice. Have a lawyer review before you rely on it in production.

This addendum sits under the Terms of Service and applies when mailzy.us processes personal data on your behalf (customer data, mailbox metadata, lead-list rows).

Roles

You are the data controller. mailzy.us is the data processor for the data you upload, generate, or ask us to extract.

Purpose of processing

Provisioning mailboxes, delivering scraped lead lists, sending transactional email tied to your orders, and providing support.

Subprocessors

  • Google LLC — Workspace mailbox provisioning.
  • Supabase, Inc. — database, auth, storage.
  • Stripe, Inc. — global card payments.
  • bKash Ltd. — payments in Bangladesh.
  • Brevo (Sendinblue) — transactional email delivery.
  • Cloudflare, Inc. — edge network and DNS.

We'll notify customers by email before adding or replacing a subprocessor that handles personal data.

Security measures

  • TLS for data in transit.
  • AES-256 encryption at rest for admin credentials and lead-list files.
  • Row-level security in the primary database.
  • Audited access to production data.

Data subject requests

Forward any access, deletion, or correction requests to hello@mailzy.us. We respond within 30 days.

International transfers

Data may be processed in the US, EU, and South Asia. For EU personal data we rely on Standard Contractual Clauses with subprocessors that need them.

Termination

On account deletion, personal data is purged within 30 days, except where law requires retention.