Back to Home

Data Processing Agreement (DPA)

Last updated: 9/26/2026

1. Definitions and Roles

This Data Processing Agreement ("DPA") governs the processing of personal data by MailVoy ("Data Processor") on behalf of our customers ("Data Controller"). By using MailVoy's services, you agree to these terms, which act as a supplement to our Terms of Service to ensure strict compliance with the General Data Protection Regulation (GDPR) and other applicable privacy frameworks.

2. Categories of Data Processed

In the course of providing our email orchestration services, MailVoy may process the following types of personal data on behalf of the Data Controller:

3. Authorized Sub-processors

MailVoy engages the following enterprise-grade sub-processors to securely manage and orchestrate data. All sub-processors are bound by strict confidentiality and data protection obligations:

4. Technical and Organizational Measures (TOMs)

MailVoy implements rigorous security measures to protect Controller data:

5. Data Retention and Deletion

MailVoy strictly adheres to the Controller's right to erasure. When a contact initiates an unsubscribe action, or when the Controller terminates their MailVoy account, MailVoy executes a complete destruction cascade. Data is permanently wiped from the MongoDB cluster and flushed from Redis queues within 30 days.

6. Incident Management and Breach Notification

In the event of a verified security breach impacting the Data Controller's personal data, MailVoy commits to notifying the primary administrative contact within 72 hours of incident confirmation, accompanied by a full remediation plan based on Axiom infrastructure telemetry.