Data Processing Addendum

Our GDPR commitments when we handle personal data on your behalf: what we process, how we secure it, who else touches it, and what happens at the end.

Effective 25 July 2026.

1. Scope and roles

This addendum applies when CROapps Oy processes personal data on your behalf in providing MCPmailer, and forms part of the Terms of Service. Accepting those terms accepts this addendum; no signature is needed, though we will sign a copy on request.

You are the controller and we are the processor for the personal data in your workspace: the content of mail your agents send and receive, the addresses and names of the people they write to, your contacts, notes, and templates.

We are a controller in our own right for a narrow set of data: your account and billing records, security and abuse logs, and the technical logs the service generates. The Privacy Policy covers that data.

If a conflict arises between this addendum and the Terms of Service on the processing of personal data, this addendum wins.

2. Details of processing

  • – Subject matter: providing email identities and messaging for software agents.
  • – Duration: for as long as your account is open, plus the retention periods in section 9.
  • – Nature and purpose: transmitting, receiving, storing, indexing, and displaying messages and related workspace records so the service works.
  • – Types of personal data: names, email addresses, phone numbers, message content and attachments, contact records and notes, and any other personal data you choose to put into the service.
  • – Categories of data subjects: your staff and agents, your customers, and anyone your agents correspond with.
  • – Special category data: not expected. The service is not designed for it, and you should not put it in without telling us first.

3. Our obligations

  • – We process personal data only on your documented instructions. Your use of the service, and this addendum, are those instructions. If we believe an instruction breaks EU or member-state data protection law, we will tell you.
  • – We do not read message content, and we never use your data to train models or for our own purposes.
  • – Everyone with access is bound by confidentiality obligations, and access is limited to those who need it to run the service.
  • – We implement the technical and organisational measures in section 6, taking account of the state of the art and the risk to data subjects.
  • – We assist you, as far as we reasonably can, with data subject requests, data protection impact assessments, and consultations with supervisory authorities.

4. Your obligations

You are responsible for having a lawful basis for the personal data you put into the service and for the mail your agents send, for giving the notices data subjects are entitled to, and for the accuracy of what you upload.

You must not instruct us to process personal data in a way that breaches data protection law, and you must not put special category data into the service without agreeing it with us first.

5. Sub-processors

You give general authorisation for us to use sub-processors. The current list, with each one's role and location, is on the sub-processors page and forms part of this addendum.

Each sub-processor is bound by a written contract imposing data protection obligations no weaker than those in this addendum, and we remain fully liable to you for what they do.

We will announce a new or replacement sub-processor by email at least 30 days before it starts processing your data. If you object on reasonable data protection grounds within those 30 days, we will work with you to find a solution; if we cannot, you may terminate the affected part of the service and receive a refund of fees paid for the unused period.

6. Security measures

  • – Encryption of personal data in transit (TLS) and at rest.
  • – End-to-end encryption of the vault, so vault secrets are unreadable to us and to anyone who obtained the database.
  • – Credentials stored only as hashes: API keys and passwords are never held in a recoverable form.
  • – Access control on production data, limited to personnel who need it, with administrative actions logged.
  • – Tenant isolation: every query is scoped to a workspace, and cross-workspace access is prevented at the data layer, not just in the interface.
  • – Rate limiting and abuse tripwires that act on behaviour rather than on message content.
  • – Point-in-time backups of the database, held by our database provider, with documented restoration steps.
  • – Regular review of these measures as the service changes.

7. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notice will describe what happened, the categories and approximate volume of data affected, the likely consequences, and the steps taken or proposed.

We will cooperate with you and take reasonable steps to contain and remediate the breach. Notifying supervisory authorities and data subjects is your decision as controller, and we will give you what you need to make it.

8. International transfers

Personal data is processed in the United States and on a global edge network, as set out on the sub-processors page.

Where personal data leaves the EEA, the transfer relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), which are incorporated into this addendum by reference, with module two (controller to processor) applying between you and us and module three (processor to processor) applying between us and our sub-processors. The Terms of Service supply the details required by the clauses, and the security measures in section 6 are the technical and organisational measures required by annex II.

Where a provider is certified under the EU-US Data Privacy Framework, we rely on that certification in addition to the clauses.

9. Return and deletion

You can export the whole workspace as JSON at any time from its settings page, and delete individual records yourself.

Deleting a workspace, or the whole account, from the settings page erases everything inside it at once, including the stored bytes of every message. If an account is simply abandoned instead, the data stays available for export for 30 days and is deleted within 90 days. Backups age out on their own cycle and are not restored to serve a deleted account.

We keep what the law requires us to keep, chiefly invoices for accounting purposes. We also keep affiliate commission records, with their link to your workspace removed, because a third party is owed that money whether or not you stay.

10. Audits

On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this addendum, and answer a reasonable security questionnaire.

Where documentation does not answer the question, we will allow an audit by you or an independent auditor bound by confidentiality, at your cost, on 30 days' notice, during business hours, and in a way that does not disrupt the service or expose other customers' data.

11. Liability and term

Liability under this addendum is subject to the limits in the Terms of Service, except where data protection law does not allow that.

This addendum lasts as long as we process personal data on your behalf, and the obligations that by their nature should survive termination do so.

Need a countersigned copy for your records: ask through the contact form.