Subscription billing, payment processing, tax compliance, and customer invoicing
Subscription billing, payment processing, tax compliance, and customer invoicing
Customer support chat and messaging platform
Customer support ticketing system and helpdesk software
Analytics and reporting services
Maileroo is certified by the Certified Senders Alliance and complies with the EU GDPR, and we have appointed an EU representative under Article 27. Our SOC 2 Type II audit is in progress and ISO 27001 certification is coming soon. The Compliance tab shows the current status of each framework.
We process customer data only to provide the service and on your documented instructions, as set out in our Data Processing Addendum. Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, and backups are encrypted.
Email processing runs on EU infrastructure across Germany, the Netherlands, France, and Finland. Supporting services such as billing and support tools are provided by the subprocessors listed on this page.
Email content, attachments, metadata, and delivery logs are kept for up to 14 days from transmission. Encrypted backups are kept for up to 30 days and then deleted using secure deletion methods.
Yes. We work with 25 vetted subprocessors for hosting, payments, support, and fraud prevention. The Subprocessors tab lists each one with its location and purpose, and the same list appears in Annex 3 of our Data Processing Addendum.
Yes. We email customers at least 30 days before adding or replacing a subprocessor. You can object on reasonable data protection grounds within 15 days of that notice.
No. Our Data Processing Addendum forms part of our Terms and applies automatically to every customer, including Standard Contractual Clauses for international transfers. If your legal team needs a countersigned copy, contact us.
We notify affected customers without undue delay, and in any event within 72 hours of becoming aware of a personal data breach. Each incident is logged, investigated, and resolved under our incident response plan.
Every plan includes two-factor authentication and passkeys. SAML single sign-on is available on Pro plans and above, so your team can sign in through your identity provider.
Select Request access next to any locked document and you will be taken to our contact page. Tell us which documents you need and our team will review the request and share them with you directly.
Use our contact page or email [email protected] for security questions and vulnerability reports. For privacy, GDPR, or Data Processing Addendum questions, email [email protected].
We update this Trust Center whenever our compliance status, controls, or subprocessors change. Material changes to the subprocessor list are also emailed to customers in advance.