Our GDPR commitments when we handle personal data on your behalf: what we process, how we secure it, who else touches it, and what happens at the end.
Effective 25 July 2026.
This addendum applies when CROapps Oy processes personal data on your behalf in providing MCPmailer, and forms part of the Terms of Service. Accepting those terms accepts this addendum; no signature is needed, though we will sign a copy on request.
You are the controller and we are the processor for the personal data in your workspace: the content of mail your agents send and receive, the addresses and names of the people they write to, your contacts, notes, and templates.
We are a controller in our own right for a narrow set of data: your account and billing records, security and abuse logs, and the technical logs the service generates. The Privacy Policy covers that data.
If a conflict arises between this addendum and the Terms of Service on the processing of personal data, this addendum wins.
You are responsible for having a lawful basis for the personal data you put into the service and for the mail your agents send, for giving the notices data subjects are entitled to, and for the accuracy of what you upload.
You must not instruct us to process personal data in a way that breaches data protection law, and you must not put special category data into the service without agreeing it with us first.
You give general authorisation for us to use sub-processors. The current list, with each one's role and location, is on the sub-processors page and forms part of this addendum.
Each sub-processor is bound by a written contract imposing data protection obligations no weaker than those in this addendum, and we remain fully liable to you for what they do.
We will announce a new or replacement sub-processor by email at least 30 days before it starts processing your data. If you object on reasonable data protection grounds within those 30 days, we will work with you to find a solution; if we cannot, you may terminate the affected part of the service and receive a refund of fees paid for the unused period.
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notice will describe what happened, the categories and approximate volume of data affected, the likely consequences, and the steps taken or proposed.
We will cooperate with you and take reasonable steps to contain and remediate the breach. Notifying supervisory authorities and data subjects is your decision as controller, and we will give you what you need to make it.
Personal data is processed in the United States and on a global edge network, as set out on the sub-processors page.
Where personal data leaves the EEA, the transfer relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), which are incorporated into this addendum by reference, with module two (controller to processor) applying between you and us and module three (processor to processor) applying between us and our sub-processors. The Terms of Service supply the details required by the clauses, and the security measures in section 6 are the technical and organisational measures required by annex II.
Where a provider is certified under the EU-US Data Privacy Framework, we rely on that certification in addition to the clauses.
You can export the whole workspace as JSON at any time from its settings page, and delete individual records yourself.
Deleting a workspace, or the whole account, from the settings page erases everything inside it at once, including the stored bytes of every message. If an account is simply abandoned instead, the data stays available for export for 30 days and is deleted within 90 days. Backups age out on their own cycle and are not restored to serve a deleted account.
We keep what the law requires us to keep, chiefly invoices for accounting purposes. We also keep affiliate commission records, with their link to your workspace removed, because a third party is owed that money whether or not you stay.
On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this addendum, and answer a reasonable security questionnaire.
Where documentation does not answer the question, we will allow an audit by you or an independent auditor bound by confidentiality, at your cost, on 30 days' notice, during business hours, and in a way that does not disrupt the service or expose other customers' data.
Liability under this addendum is subject to the limits in the Terms of Service, except where data protection law does not allow that.
This addendum lasts as long as we process personal data on your behalf, and the obligations that by their nature should survive termination do so.
Need a countersigned copy for your records: ask through the contact form.