Legal & trust

GDPR Compliance

MailerZ’s GDPR program is designed around lawful processing, transparency, data minimization, security, individual rights, processor accountability, and controlled international transfers.

Effective and last updated: September 5, 2026

This page describes our compliance framework; it is not a certification. Applicability and customer obligations depend on the parties, data, users, purposes, and jurisdictions involved.

Our roles

MailerZ is generally a controller for account, billing, website, support, and service-security data. When a customer uses MailerZ to process message content, recipient data, routing data, or sending activity on its instructions, MailerZ generally acts as processor and the customer acts as controller. The Data Processing Addendum applies to that processing.

Data protection principles

  • Lawfulness, fairness, and transparency.
  • Purpose limitation and data minimization.
  • Accuracy and appropriate correction.
  • Retention limited to operational, contractual, security, and legal needs.
  • Integrity, confidentiality, and risk-based security.
  • Accountability through contracts, records, controls, and review.

Lawful bases

For controller activities, MailerZ may rely on contract, legitimate interests, consent, and legal obligation. Customers must identify and document the lawful basis for data they route or send through MailerZ, provide required notices, and honor objections or withdrawal of consent where applicable.

Individual rights

  • Access personal data and information about its processing.
  • Correct inaccurate or incomplete data.
  • Request deletion where no exception requires continued processing.
  • Restrict or object to qualifying processing.
  • Receive portable data where the legal conditions apply.
  • Withdraw consent without affecting earlier lawful processing.
  • Complain to a competent supervisory authority.

How to submit a request

Send requests to support@mailerz.net and identify the account, domain, and right being exercised. We may verify identity and authority before disclosing or changing data. When MailerZ acts as processor, we may direct the requester to the customer-controller and assist that customer as required by the DPA.

Processors and transfers

MailerZ uses service providers under confidentiality, security, and data-processing obligations appropriate to their role. Where personal data is transferred internationally and the GDPR requires a transfer mechanism, we use recognized safeguards such as adequacy decisions or approved contractual clauses as applicable.

Security and breach assistance

We maintain technical and organizational measures appropriate to the risk of the service. When acting as processor, we notify the customer of a confirmed personal-data breach without undue delay as required by contract and law, and provide information reasonably available to support the customer’s assessment and notifications.

Retention and deletion

Customer content follows the plan’s storage window and customer instructions, subject to backup cycles, security evidence, disputes, and legal preservation. On termination, eligible customer data is deleted or returned according to the Terms and DPA unless law requires retention.

Authoritative references

These official sources help explain the regulatory standards reflected in this policy.

Questions about this policy?

Email support@mailerz.net and include the policy name in your subject line.