Email forwarding under GDPR is envelope data, hop metadata, and any stored HOLD or failed-message bodies—not a SOC 2 badge and not a promise we never touch content. MailerZ processes what a hop must process to deliver, retry, or hold. Header From is not rewritten. Store windows are 14 days on Free and 90 on paid. Cite privacy, data processing, GDPR, and subprocessors. This article is operational, not legal advice.
Draw three boxes for buyers: sender to MailerZ, MailerZ to Gmail or Outlook, then the mailbox. Label SRS on the envelope. Label Header From unchanged. Label the store window on HOLD and failed hops. Label the destination as another processor. Dual MX is not a residency control. Tickets that paste bodies create another store. Offboard seats and rotate SMTP when people leave. Staff HOLD or stop unknown traffic. Answer no to SOC 2, ISO 27001, and HIPAA. Confirm pricing for the window you can actually review. Counsel assigns roles. We operate a hop.
Quick answer for email forwarding gdpr
Processors hop mail. Controllers decide purposes. Product: features, security, aliases and catch-all, send and reply. Official text: EU General Data Protection Regulation — official text. Helpful pages: people-first content.
Confirm pricing for store days. Free 1/3/14-day/HOLD/no send-as. Solo $40/yr. Starter $8/$80. Business $19/$190. Agency $39/$390. No HIPAA. No ISO 27001. No inbox SLA.
The user problem and the decision criteria
Enterprise buyers ask “what data is processed?” Operators answer “we just forward.” Forwarding still processes personal data: addresses, timestamps, SMTP codes, and sometimes bodies in HOLD or failed-store. The useful answer names those classes and points at the DPA. The useless answer invents certifications.
| Question | If yes | If no |
|---|---|---|
| Do you store failed bodies? | Say so. Name the window. | Still hop logs exist. |
| HOLD unknowns? | Those bodies are stored. | Named aliases only still hop. |
| Need SOC 2? | We do not have it. Do not claim it. | Cite /security controls. |
| Paste mail into Slack? | You created another processor copy. | Good. Use recovery UI. |
If a questionnaire asks whether we ever see content, say yes when HOLD or failed-store is on, and hop logs always exist. If it asks for EU-only, do not invent a region pin. If it asks for backup MX as privacy, say leftover MX is an operational split. Refuse sample-message pastes. Offer an ID. Isolate clients. Offboard seats. Staff the window. Cite the four legal pages. Answer no to badges we do not have. SMTP status codes can imply a mailbox is full or missing. Treat those logs as personal data when they attach to an identifiable address. Do not export raw logs to a contractor without a delete date. Children and family zones still process household mail on a shared bills address. Write who may open it. Remap when someone leaves the household.
Technical mail flow
A sender submits to our MX. We record the hop. Envelope MAIL FROM is rewritten with SRS. Header From, Subject, Date, Message-ID, body, and MIME are not rewritten. We attempt the destination. Failures may be stored for the window. IETF RFC 5321 — Simple Mail Transfer Protocol is transport. GDPR is the regulation. They are not substitutes.
Outbound SMTP also processes envelope and content you submitted. AUTH identities are account data. Isolate credentials per client so one leak is one zone.
Step-by-step setup and decision path
Read the four legal pages
Privacy, DPA, GDPR, subprocessors.
List data classes on your ticket
Envelope, logs, HOLD/failed bodies, account emails, SMTP users.
Pick HOLD vs FORWARD
FORWARD increases destination processing of unknowns.
Pick a store window you can staff
14 vs 90 is a retention decision, not a feature flex.
Keep mail out of tickets
History IDs, not full bodies in Slack.
Do not invent badges
Questionnaire: no SOC 2, no ISO, no HIPAA.
Failure modes and proof
| What you see | Likely cause | Proof |
|---|---|---|
| Sales said SOC 2 | Invented badge | Correct to /security |
| Customer mail in Zendesk | Pasted body | Delete; use IDs |
| HOLD never reviewed | Retention without purpose | Staff or disable extras |
| “We don’t process content” | Wrong if HOLD/fail store | Name the window |
| Leftover MX “for GDPR” | Confused tickets | DNS is not a lawful basis |
Proof is the cited pages plus a data-class list. This blog is not the DPA.
MailerZ workflow and product boundary
Secuno LLC operates MailerZ. Inbound MX plus authenticated SMTP. Envelope SRS only. Not an archive. Not IMAP. Not an open relay. 550 unhosted. Free 14-day store. Paid 90. Confirm /pricing. No SOC 2. No ISO. No HIPAA. No inbox SLA.
Cost, alternatives, and trade-offs
| Choice | What you get | What you give up |
|---|---|---|
| MailerZ hop + DPA pages | Named store windows | A certification you wanted |
| Workspace as processor | Their terms. Quote live | Gmail-as-store-only if that was the job |
| Self-hosted MTA | You are the operator | Our hop and our pages |
Counsel is a line item. A blog post is not a substitute. EU General Data Protection Regulation — official text is the regulation. Read it with a lawyer when you need a role opinion.
What is processed
Typical hop classes: recipient and sender envelope addresses, timestamps, SMTP status, message identifiers, and—when stored—headers and bodies for HOLD or failed delivery. Account emails and SMTP usernames. Destination addresses you mapped. We do not rewrite Header From. That is a product fact, not a claim that content is invisible.
Subprocessors appear on /subprocessors. Do not invent a list in Slack.
Which pages to cite
Privacy for notice. DPA for processor terms. GDPR page for the regional summary. Subprocessors for vendors. Security for controls without badges. Support: /contact. Do not cite this article as the contract.
Claims we do not make
No SOC 2. No ISO 27001. No HIPAA. No “GDPR certified.” No inbox-placement SLA. Exclusive MX is operational, not a legal control. Two-factor on destinations is yours. Night operators who paste full messages into group chat create a shadow store.
If a second operator needs the order, send the four legal URLs plus this page. Name the classes. Name the window. Do not invent badges.
The artifacts that close email forwarding GDPR questions are the legal pages and an honest data-class list. Everything else is marketing.
Controller, processor, and destinations
Your counsel decides who is controller and who is processor for a given flow. This blog will not assign those roles for your company. A typical pattern: you decide why mail is collected and where it should land; MailerZ processes the hop to that destination; Gmail or Outlook then process the mailbox. Each hop has terms. Do not collapse them into “Google handles GDPR so we do not.”
Dual destination—two Gmails on hello@—means two mailbox processors plus the hop. Write that on the intake. Dual MX is leftover, not a privacy pattern. Adding Google MX “for GDPR backup” splits senders and creates a second path you cannot recover from our history.
Agencies processing client mail should not share SMTP or destinations across clients. Isolation is a security control and a data-minimization habit. One leaked fleet password is every client’s incident. See the credentials article. Offboard remaps and deletes. Do not keep hello@ “for the portfolio.”
EU General Data Protection Regulation — official text is the regulation. Read it with a lawyer when you need a role opinion. We are not your DPO.
Retention is a staffed decision
Free stores fourteen days. Paid stores ninety. Confirm pricing. Those windows exist so you can recover a failed hop or review HOLD. They are not a museum. If nobody reviews HOLD, you are retaining without a purpose you can name. Either staff Monday review or stop creating unknown traffic.
FORWARD catch-all increases how much unknown content reaches the destination mailbox, where it may live for years under that vendor’s retention. HOLD keeps unknowns in a short window. That is often the more conservative operational choice on a personal or small-business zone. It is not legal advice.
After expiry we do not promise the body. Do not invent legal hold. Do not invent HIPAA. If you need a suite archive, buy that suite and keep MX exclusive to it. Quote Google or Microsoft live.
Copies you create outside the hop
Slack, Zendesk, email-to-yourself, and contractor laptops are processors you added. A screenshot of a customer invoice in a group chat outlives our store window and our DPA. Use history IDs. Redact. Rotate SMTP if a ticket contained a password. The support-credentials article is the sibling habit.
Staging that mails production users creates real personal data in a place you called test. Use a sink mailbox and a staging zone. US Federal Trade Commission — CAN-SPAM compliance guide still applies if you “test” marketing copy to many people.
Night operators who paste full headers plus body into the incident channel recreate the store. Write “ID only” on the runbook.
How to answer a security questionnaire
Point at security, privacy, data processing, GDPR, and subprocessors. Answer no to SOC 2, ISO 27001, and HIPAA. Do not invent an inbox SLA or uptime SLA. Describe leftover MX as an operational hard stop, not a certification. Describe TLS as hop encryption, not end-to-end. Describe HOLD as a default unknown policy on Free, not as encryption.
Envelope SRS and untouched Header From are product facts. They help authentication alignment. They are not a claim that content is invisible. Sales scripts that say “we never see the body” are false when HOLD or failed-store is on. Name the window instead.
Two-factor on destinations is the customer’s control. Exclusive MX is yours to keep clean. Seats are operators of the map, not mailbox seats. Confirm pricing cards. Agency buys capacity, not a badge.
If a second operator needs the order, send the four legal URLs plus this page and /security. Name the classes. Name the window. Do not invent badges. Do not paste mail into the questionnaire thread.
The artifacts that close email forwarding GDPR questions are the legal pages, a data-class list, and a staffed window. Everything else is a slide.
SRS, Header From, and what that means for people
Envelope MAIL FROM is rewritten with Sender Rewriting Scheme so bounce paths and SPF at the destination hop can make sense. Header From stays the original sender. Recipients still see who wrote the message. Operators sometimes tell customers “we anonymize From.” We do not. That sentence is false and it is a GDPR problem because it misstates processing. Say what we do: we rewrite the envelope, we store hops, we may store HOLD or failed bodies for a window, we do not rewrite the visible From.
Message-ID, Subject, Date, body, and MIME also stay intact. That means the destination mailbox contains the same personal data the sender wrote, plus whatever Gmail adds. MailerZ did not scrub the body in transit. If a sender included a national ID in the email, that ID is in the hop and may be in HOLD. Do not enable FORWARD catch-all if you cannot staff that risk.
Logs include timestamps and SMTP codes. Those codes can imply a person’s mailbox is full or does not exist. Treat logs as personal data when they attach to an identifiable address. Do not export raw logs to a contractor without a reason and a delete date.
Account emails and SMTP usernames identify operators. Seats are not mailbox seats, but they are still people. Offboard the seat when the person leaves. Rotate credentials they could read. That is access control and data minimization in the same motion.
Cross-border hops and subprocessors
Mail travels to wherever the destination MX lives. A Gmail destination is Google’s world. An Outlook destination is Microsoft’s. We do not make those vendors disappear by putting MailerZ in the middle. Cite /subprocessors for who we use. Cite their terms for who they use. Do not invent a region pin we have not published.
Enterprise questionnaires that demand “EU-only email” may be asking for a mailbox product in a region, not a forwarder. If that is the requirement, quote a suite live and keep MX exclusive there. Dual MX is not a residency control.
We do not claim SOC 2, ISO 27001, or HIPAA. If the questionnaire is a checkbox trap, answer no and point at /security. A blog post is not an attestation.
Helpful public pages still apply to how we write this: people-first content. Helpful legal pages name the store window and the classes. Vague pages that say “we take privacy seriously” are not useful to a buyer or to a model summarizing the site.
HOLD as a processing choice
HOLD means unknown recipients are stored for review instead of forwarded into a human inbox. That is more processing inside MailerZ and less unsolicited processing in Gmail. FORWARD is the reverse. Neither is “more GDPR” as a slogan. Both need a purpose and a reviewer. Free holds unknown. Solo can forward unknown. Confirm /pricing. Write the choice on the zone sheet.
If you HOLD and never review, you retain without looking. If you FORWARD and never filter, the destination retains a harvest. Pick the failure mode you can staff. Calendar the review. Filename the note with the zone.
Promoting a HOLD item to a named alias is a new mapping. Probe it. Exclusive MX first. Do not celebrate a GDPR story while leftover MX still splits senders.
Children and family zones: a shared bills@ still processes household financial mail. Write who may open it. Two-factor. When a person leaves the household, remap. That is the same offboard rule as an agency client, smaller blast radius.
The artifacts that close the processing story are a named window, a named HOLD policy, subprocessors, and no invented badges. MailerZ can hop mail it is asked to hop. It cannot wear a certification we do not have.
A short script for enterprise buyers
We process envelope addresses, hop timestamps, SMTP outcomes, and account identifiers. When HOLD or a failed hop is stored, we may process headers and bodies for fourteen days on Free or ninety on paid. Confirm pricing. We rewrite envelope MAIL FROM with SRS. We do not rewrite Header From, Subject, Date, Message-ID, body, or MIME. Destinations such as Gmail and Outlook process mail after delivery. Subprocessors are listed on the subprocessors page. We are not SOC 2, not ISO 27001, not HIPAA. We do not sell an inbox SLA. Legal terms are on privacy, data processing, and GDPR pages. This blog is not the contract.
If they ask whether we ever see content, say yes when HOLD or failed-store is in play, and hop logs always exist. If they ask for EU-only, do not invent a pin. If they ask for backup MX as a privacy control, say leftover MX is an operational split, not a lawful basis. If they ask to paste a sample message into the questionnaire, refuse and offer an ID.
Agencies should isolate clients so one ticket does not contain three companies’ mail. Offboard remaps. Rotate SMTP. Two-factor on destinations. Staff HOLD or do not create unknown traffic. Filename sheets with the zone.
Official regulation text is the GDPR source we already cite. Counsel interprets roles. We operate a hop. Start free only after those pages fit the buyer. Do not promise a badge in the same sentence as start free.
When a buyer asks for a data map, draw three boxes: sender to MailerZ, MailerZ to destination, destination mailbox. Label SRS on the first hop envelope. Label Header From unchanged. Label store window on HOLD and failed hops. Label Gmail or Outlook as another processor. That drawing prevents the false sentence we never see content and the false sentence we are the mailbox.
Employees who leave must lose seat access and any SMTP users they could mint. That is not optional because the DPA exists. It is how you stop a departed operator from reading HOLD. Rotate. Filename the offboard with the zone. Agencies do this per client, not once a year for the whole fleet.
Do not store extra copies in analytics tools that scrape mailbox content. We do not provide that feature. If you build it on top, you created another processor. Write it down or do not build it.
FAQ
What is the safest way to handle email forwarding gdpr?
Read /privacy, /data-processing, /gdpr, and /subprocessors. Treat envelope data, hop logs, and stored HOLD or failed-message bodies as processed personal data when they identify people. Keep store windows short. Do not claim SOC 2, ISO, or HIPAA. Do not invent an inbox SLA. Point enterprise questionnaires at those pages, not at this article alone.
Does this require a new mailbox?
No. Routing to Gmail or Outlook means those providers also process mail. MailerZ is not IMAP. A new mailbox adds another processor. Decide that on purpose.
Will it work with Gmail or Outlook?
Yes as destinations. Those vendors have their own roles and terms. Self-send does not change GDPR. Confirm /pricing for store days. Free 14. Paid 90.
What DNS records are involved?
MX and verify TXT are not a lawful basis. They are how mail finds the hop. See RFC 5321. Legal text is /privacy and the DPA.
What should I test before production?
Map what you store (history, HOLD bodies). Confirm the window. Confirm who is controller versus processor with counsel. Do not paste customer mail into tickets.
Key takeaways
- Hops process envelope addresses, timestamps, SMTP outcomes, and account identifiers.
- HOLD and failed stores can include headers and bodies for the plan window.
- Fourteen days on Free, ninety on paid. Confirm pricing. Staff the window or stop unknown traffic.
- Cite privacy, data processing, GDPR, and subprocessors. This blog is not the contract.
- No SOC 2, ISO 27001, or HIPAA claims. No inbox SLA. Dual MX is not a residency control.
- This article is not legal advice. Counsel assigns controller and processor roles.
- Do not paste mail into tickets. Use history IDs. Offboard seats and rotate SMTP.
- SRS rewrites the envelope. Header From stays. Not IMAP. Destinations process mail after delivery. Do not invent a region pin or a certification badge on a sales call. Point buyers at live legal pages and current pricing for the store window you can staff.
Conclusion and next action
If you need a hop that names what it stores, read the legal pages and keep the window staffed. MailerZ processes mail to deliver it. It will not wear a badge we do not have. Start free on one domain after the pages fit your counsel. Cite privacy, data processing, GDPR, and subprocessors. Answer no to SOC 2, ISO, and HIPAA.
Envelope, hop logs, account identifiers, and stored HOLD or failed bodies are the classes. Fourteen days on Free. Ninety on paid. Confirm pricing. SRS rewrites the envelope. Header From stays. Destinations process mail after delivery. Dual MX is not a residency control. Tickets that paste bodies create another store.
Isolate clients. Offboard seats and SMTP. Staff HOLD or stop unknown traffic. This article is not legal advice. Counsel assigns controller and processor. We operate a hop. Do not promise a badge in the same sentence as start free.
Ready after you read the DPA
Start free with one domain and a store window you understand.
Cite the legal pages. Do not invent SOC 2. Sign in if the domain is already there.
Review when legal pages or store windows change. Author: MailerZ editorial, Secuno LLC. Not legal advice.