m
    MailingPlatform
    PlatformDeliverabilityPricingSecurity & GDPR
    Sign inStart free →
    PlatformDeliverabilityPricingSecurity & GDPR
    Sign inStart free →
    Legal

    Privacy policy

    Version 2.0Updated July 25, 2026

    This privacy policy explains how MailingPlatform collects, uses and protects personal data when you visit mailingplatform.net, use the application at app.mailingplatform.net, or otherwise interact with us.

    1. Who we are

    The data controller for the processing described in this policy is:

    CMC
    Bredagervej 49
    2770 Kastrup
    Denmark
    VAT no. DK42289760

    Email: support@mailingplatform.net

    References to "MailingPlatform", "we", "us" and "our" mean CMC.

    2. Our two roles

    We process personal data in two distinct roles, and it matters for your rights which role applies:

    • As data controller for data about you: your account, billing, support conversations, and your use of our website and service.
    • As data processor for the subscriber data our customers upload and manage in the service (names, email addresses, engagement data and other fields). For this data, our customer is the data controller, and we process it only on the customer's instructions. If you are a subscriber on one of our customers' lists and want to exercise your rights, please contact the sender of the emails you received; we will assist them in responding.

    The rest of this policy primarily describes our processing as data controller.

    3. Information we collect

    Account information. Name, email address, company details and password (stored as a secure hash) when you create an account.

    Billing information. Your subscription plan, invoices and payment history. Card payments are processed by Stripe; we never receive or store your full card details.

    Usage and log data. Log entries about how the service is used, such as logins, campaigns sent, feature usage, IP addresses, browser type and timestamps. We use this to operate, secure and improve the service.

    Support data. The content of support tickets and related correspondence. Parts of our support are AI-assisted; support conversations may be processed by our AI systems to generate responses, and you can always request a human follow-up.

    Connected service credentials. If you connect third-party services (for example Amazon SES sending credentials or an e-commerce store), we store the required credentials encrypted and use them only to provide the integration.

    Website data. Cookies and similar technologies on our own websites, as described in our cookie policy.

    Emails we send to you. When we send you service or marketing emails, we record delivery and engagement events (such as opens and clicks) as described in section 6. You can opt out of our marketing emails at any time via the unsubscribe link.

    4. How we use your information

    • To provide, operate and maintain the service
    • To process payments and manage subscriptions
    • To provide customer support, including AI-assisted responses
    • To send service communications such as onboarding, security and billing notifications
    • To send marketing about the service, which you can opt out of at any time
    • To monitor, secure and improve the service, including abuse and anti-spam monitoring
    • To comply with legal obligations, such as bookkeeping and tax law

    5. Legal bases

    We rely on the following legal bases under the GDPR: performance of a contract (article 6(1)(b)) for providing the service and billing; our legitimate interests (article 6(1)(f)) in securing, improving and marketing the service; your consent (article 6(1)(a)) where required, for example for certain cookies; and compliance with legal obligations (article 6(1)(c)), for example retention of accounting records.

    6. Email and website tracking

    Emails sent through the platform can include a small tracking pixel to measure opens and rewritten links to measure clicks. Tracked links may contain an encrypted identifier that allows the sender to recognise the subscriber when they visit the sender's website. We filter automated bot and security-scanner activity from these statistics. Unsubscribe links always work regardless of tracking.

    Customers can also install our tracking script on their own websites to measure visits and e-commerce events for their own audience. For that data, the customer is the data controller.

    7. Service providers

    We use a small number of carefully selected service providers (sub-processors) to run the service:

    ProviderPurposeLocation
    StripePayment processingEU / United States
    Amazon Web Services (SES)Email delivery infrastructureEU / United States
    SupabaseDatabase and application hostingEU
    CloudflareContent delivery, DNS and securityEU / United States
    OpenAIAI-assisted support and featuresUnited States

    Where a provider processes personal data outside the EU/EEA, transfers are safeguarded by an adequacy decision (including the EU-U.S. Data Privacy Framework where applicable) or the European Commission's standard contractual clauses.

    8. Data retention

    DataRetention
    Account and customer dataFor as long as your account is active
    Deleted accountsDeleted from production systems upon account deletion; encrypted backups expire automatically on a rolling basis
    Invoices and accounting records5 years from the end of the financial year, as required by the Danish Bookkeeping Act
    Data export filesDeleted automatically 7 days after creation
    Support ticketsRetained while relevant to provide support and improve the service

    9. Security

    We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, encrypted storage of credentials, access controls, audit logging and separation between customer accounts. See our security policy for more detail. No system is completely secure; if we become aware of a personal data breach affecting you, we will notify you and the competent authority as required by law.

    10. Your rights

    Under the GDPR you have the right to:

    • Access the personal data we hold about you
    • Have inaccurate data rectified
    • Have your data erased ("right to be forgotten")
    • Restrict or object to our processing
    • Receive your data in a portable format
    • Withdraw consent at any time, where processing is based on consent

    To exercise your rights, contact us at support@mailingplatform.net. We respond within one month. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk.

    11. Children

    The service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18.

    12. Changes to this policy

    We may update this policy from time to time. If we make material changes, we will notify you by email or in-app notification before the changes take effect. The date of the latest version is always shown at the top of this page.

    13. Contact

    CMC
    Bredagervej 49
    2770 Kastrup
    Denmark
    VAT no. DK42289760

    Email: support@mailingplatform.net

    m
    MailingPlatform

    Email & automation for commerce, on infrastructure you don't have to think about.

    Product
    PlatformDeliverabilityPricingStart free
    Solutions
    Shopify storesWooCommerceNewsletters
    Compare
    Switch from KlaviyoSwitch from MailchimpSwitch from ActiveCampaignSwitch from OmnisendSwitch from BrevoSwitch from MailerLite
    Resources
    BlogHelp centerAPI docsDeliverability guideSupportSign in
    Company
    Security & GDPRPrivacy policyTerms of serviceData processing
    © 2026 MailingPlatform. Built and hosted in the EU.
    GDPR READYEU DATARFC 8058