MailMama policies

Terms governing MailMama's processing of personal data on behalf of customers.

Data Processing Addendum

Effective Date: September 5, 2026

Company: MailMama Software LLC

Company Address: 75 E 3rd St, Sheridan, WY 82801, United States

Website: https://mailmama.net/

Email: info@mailmama.net

This Data Processing Addendum governs the processing of personal data by MailMama Software LLC on behalf of its customers in connection with the MailMama services. It forms part of the Terms of Service and applies where data protection law requires a written processing agreement.

1. Parties and Incorporation

This Data Processing Addendum (the “DPA”) is entered into between MailMama Software LLC, a limited liability company organized under the laws of the State of Wyoming, United States (“MailMama”, “Processor”, “we”, or “us”), and the customer identified in the applicable order or account record (“Customer”, “Controller”, or “you”).

This DPA supplements and forms part of the Terms of Service between the parties (the “Agreement”). It takes effect on the date the Agreement takes effect, or on the date this DPA is executed by both parties, whichever is later, and applies for as long as MailMama processes Customer Personal Data.

Where the Customer is an entity subject to the General Data Protection Regulation, the UK General Data Protection Regulation, the Swiss Federal Act on Data Protection, or a United States state privacy law that requires a written processing agreement, this DPA applies automatically. A countersigned copy may be requested at info@mailmama.net with the subject line “DPA Request”.

2. Definitions

  • “Data Protection Law” means all laws relating to the protection of personal data applicable to the processing under this DPA, including the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK General Data Protection Regulation and the Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), other United States state privacy laws, and the Personal Information Protection and Electronic Documents Act of Canada.

  • “Customer Personal Data” means personal data contained in Customer Content or otherwise processed by MailMama on behalf of the Customer in the course of providing the Services.

  • “Services” means the hosted business email and email productivity services provided by MailMama under the Agreement.

  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.

  • “UK Addendum” means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018.

  • “Subprocessor” means any third party engaged by MailMama to process Customer Personal Data in connection with the Services.

The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach”, and “supervisory authority” have the meanings given in the GDPR. The terms “business”, “service provider”, “sell”, “share”, and “personal information” have the meanings given in the CCPA.

3. Roles of the Parties

In relation to Customer Personal Data, the Customer is the controller and MailMama is the processor. Where the Customer is itself acting as a processor on behalf of a third-party controller, the Customer warrants that it has the authority of that controller to appoint MailMama as a subprocessor and to give the instructions set out in this DPA, and MailMama acts as subprocessor.

Under the CCPA and comparable United States state laws, the Customer is the business and MailMama is the service provider or processor.

MailMama acts as an independent controller in relation to personal data that it determines the purposes and means for itself, including account registration and administration data, billing and transaction data, support correspondence, security and abuse records, and website visitor data. That processing is governed by the MailMama Privacy Policy and not by this DPA.

4. Subject Matter, Duration, Nature, and Purpose

The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I. The processing continues for the term of the Agreement and for the limited period thereafter described in Section 12.

5. Customer Obligations

The Customer warrants and undertakes that:

  • it has a valid legal basis for the collection and processing of Customer Personal Data and for its transmission to and processing by MailMama;

  • it has provided all notices and obtained all consents required under Data Protection Law in relation to data subjects, including authorized users, correspondents, and message recipients;

  • its instructions to MailMama comply with Data Protection Law and do not cause MailMama to breach it;

  • it is responsible for the accuracy, quality, and legality of Customer Personal Data and for the means by which it was acquired;

  • it will not transmit to the Services categories of data that the Agreement excludes, including protected health information, cardholder data, and classified or export-controlled information, unless a separate written agreement expressly permits it;

  • where it enables email tracking or AI-assisted features, it has determined that doing so is lawful in its circumstances and has met any resulting transparency, legal-basis, or consent requirements in relation to its recipients and authorized users;

  • it will configure and use the Services, and the security features available within them, in a manner appropriate to the sensitivity of the data it processes.

6. Processing on Documented Instructions

MailMama will process Customer Personal Data only on the documented instructions of the Customer, including with regard to international transfers, unless required to do otherwise by law applicable to MailMama. Where such a legal requirement applies, MailMama will inform the Customer before processing, unless the law prohibits that notice on important grounds of public interest.

The Agreement, this DPA, the configuration choices the Customer makes within the Services, and the instructions the Customer gives through the ordinary use of the Services constitute the Customer’s complete and final documented instructions. Additional or different instructions require written agreement and may be subject to additional charges where they require material effort or change to the Services.

MailMama will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. MailMama may suspend the execution of an instruction that it reasonably believes to be unlawful until the instruction is confirmed, amended, or withdrawn.

MailMama will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than the specific purpose of performing the Services or as otherwise permitted by Data Protection Law, will not use it outside the direct business relationship between the parties, and will not combine it with personal information received from other sources except as permitted by law. MailMama does not use Customer Personal Data for advertising, and does not use it to train generative artificial intelligence models of its own.

7. Confidentiality

MailMama ensures that persons authorized to process Customer Personal Data are subject to an appropriate duty of confidentiality, whether by contract or by statutory obligation, that survives the end of their engagement. Access to Customer Personal Data is limited to personnel who require it to perform their role, is granted on a least-privilege basis, and is logged.

8. Security Measures

Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to data subjects, MailMama implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The measures in effect are described in Annex II.

MailMama may update the measures from time to time provided that the level of protection is not materially reduced. MailMama regularly tests and evaluates the effectiveness of the measures.

The Customer is responsible for the security measures within its own control, including credential management, access control within its account, device and network security, and the use of security features made available in the Services.

9. Subprocessors

The Customer gives MailMama general written authorization to engage Subprocessors for the purpose of providing the Services. The categories of Subprocessor currently engaged are listed in Annex III, and the current list of named Subprocessors, including their roles and processing locations, is maintained by MailMama and provided to the Customer on request at info@mailmama.net.

MailMama imposes on each Subprocessor, by written contract, data protection obligations that are no less protective than those in this DPA, including obligations of confidentiality, security, and assistance, and including the terms required by Article 28(3) of the GDPR. MailMama remains fully liable to the Customer for the performance of each Subprocessor’s obligations.

MailMama will notify the Customer of the intended addition or replacement of a Subprocessor at least thirty (30) days before that Subprocessor begins processing Customer Personal Data, by email to the address associated with the account or by a notification mechanism made available in the Services. Where a change must be made more urgently for security, legal, or continuity reasons, MailMama will give notice as soon as reasonably practicable.

The Customer may object to the addition or replacement of a Subprocessor on reasonable data protection grounds by notifying MailMama in writing within fifteen (15) days of the notice. The parties will discuss the objection in good faith, and MailMama will use reasonable efforts to make an alternative arrangement available. Where no reasonable alternative can be made available, the Customer may terminate the affected Services on written notice and will receive a pro-rata refund of prepaid fees for the unused remainder of the subscription term. Termination on this basis is the Customer’s sole remedy for an objection under this Section.

10. Assistance with Data Subject Rights

MailMama provides the Customer with the functionality within the Services necessary for the Customer to access, correct, export, restrict, and delete Customer Personal Data, so that the Customer can respond to data subject requests itself.

Where MailMama receives a request from a data subject relating to Customer Personal Data, MailMama will not respond to it directly except to confirm that the request should be directed to the Customer, and will promptly forward the request to the Customer. Taking into account the nature of the processing, MailMama will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond, and may charge a reasonable fee where the assistance required is substantial and falls outside the functionality of the Services.

11. Assistance with Compliance Obligations

Taking into account the nature of the processing and the information available to it, MailMama will provide reasonable assistance to the Customer in relation to the Customer’s obligations under Articles 32 to 36 of the GDPR and equivalent provisions of other Data Protection Law, including security of processing, personal data breach notification, data protection impact assessments, and prior consultation with a supervisory authority. MailMama may charge a reasonable fee for assistance that requires substantial effort.

12. Personal Data Breach

MailMama will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known at the time and supplemented as further information becomes available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and to mitigate its effects, and a contact point for further information.

MailMama will take reasonable steps to contain and remediate the breach and will provide the Customer with the information reasonably necessary for the Customer to meet its own notification obligations to supervisory authorities and data subjects. Notification of a breach is not an acknowledgment of fault or liability.

The Customer is responsible for determining whether the breach requires notification to a supervisory authority or to data subjects and for making that notification.

13. Deletion and Return of Customer Personal Data

During the term of the Agreement, the Customer may access, export, and delete Customer Personal Data using the functionality of the Services.

On termination or expiry of the Agreement, MailMama will make Customer Personal Data available for export for a period of thirty (30) days, after which it will delete Customer Personal Data from active systems. Data deleted from active systems is removed from routine backups within ninety (90) days in the ordinary course of backup rotation. Where termination results from abuse, unlawful use, or fraud, the export period may be shortened or withheld as provided in the Agreement.

MailMama may retain Customer Personal Data to the extent required by law applicable to it, or where retention is necessary to establish, exercise, or defend legal claims or to comply with legal process, in which case MailMama will continue to protect it in accordance with this DPA and will process it only for the purpose of that retention.

On written request made within the thirty-day export period, MailMama will certify in writing that deletion has been carried out in accordance with this Section.

14. Audits and Information

MailMama will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR, including this DPA, Annex II, the current Subprocessor list, and any audit reports, certifications, or security documentation that MailMama holds.

Where the information made available is not sufficient for the Customer to demonstrate compliance, the Customer may request an audit no more than once in any twelve-month period, on at least thirty (30) days’ written notice, during normal business hours, subject to reasonable confidentiality obligations, and in a manner that does not disrupt the Services or compromise the security or confidentiality of other customers’ data. An additional audit may be carried out where required by a supervisory authority or following a confirmed personal data breach affecting the Customer.

The Customer bears its own costs and MailMama’s reasonable costs of an on-site audit. Audits by a third-party auditor are subject to that auditor not being a competitor of MailMama and to the auditor entering into a confidentiality undertaking.

15. International Transfers

MailMama is established in the United States. Customer Personal Data will be processed in the United States and may be processed in other countries where MailMama or its Subprocessors operate.

15.1 European Economic Area

Where the transfer of Customer Personal Data from the European Economic Area to MailMama is subject to Chapter V of the GDPR, the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows. Module Two applies where the Customer is a controller and MailMama is a processor. Module Three applies where the Customer is a processor and MailMama is a subprocessor. In Clause 7, the docking clause applies. In Clause 9, Option 2, general written authorization, applies, with the notice period stated in Section 9 of this DPA. In Clause 11, the optional independent dispute resolution provision does not apply. In Clause 17, the Clauses are governed by the law of Ireland. In Clause 18(b), disputes are to be resolved before the courts of Ireland. Annex I, Annex II, and Annex III of this DPA populate the corresponding annexes of the Standard Contractual Clauses.

15.2 United Kingdom

Where the transfer is subject to the UK GDPR, the Standard Contractual Clauses apply as amended by the UK Addendum, which is incorporated by reference. In Table 1 of the UK Addendum, the parties and their details are as set out in Annex I. In Table 2, the version of the Approved EU SCCs to which the Addendum is appended is the version described in Section 15.1. In Table 3, the appendix information is as set out in Annexes I to III. In Table 4, neither party may end the Addendum as set out in Section 19 of the Addendum.

15.3 Switzerland

Where the transfer is subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the following modifications: references to the GDPR are to be understood as references to the Swiss Act; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term “member state” is not to be interpreted so as to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence.

15.4 Transfer Risk and Government Access

MailMama has assessed the laws and practices of the countries in which it processes Customer Personal Data and has no reason to believe that they prevent it from fulfilling its obligations under the Standard Contractual Clauses. MailMama will notify the Customer if it becomes unable to comply with those obligations. MailMama will review the legality of any request for disclosure from a public authority, will challenge requests that it considers unlawful or excessive, will disclose only the minimum amount of data required, and will notify the Customer of the request where legally permitted to do so.

15.5 Alternative Mechanisms

If a finding of adequacy, a certification mechanism, or another transfer mechanism recognized under Data Protection Law becomes available and applicable to the transfer, MailMama may rely on it instead of or in addition to the Standard Contractual Clauses, on notice to the Customer.

16. United States State Privacy Law Terms

Where the CCPA or a comparable United States state privacy law applies, MailMama acts as a service provider or processor and, in that capacity: processes personal information only for the specific business purposes set out in the Agreement and this DPA; does not sell or share personal information; does not retain, use, or disclose personal information for any purpose other than performing the Services, or as otherwise permitted by law; does not use personal information outside the direct business relationship between the parties; does not combine personal information with information received from other sources except as permitted; and will notify the Customer if it determines that it can no longer meet these obligations.

The Customer may take reasonable and appropriate steps to ensure that MailMama uses personal information in a manner consistent with these obligations and to stop and remediate any unauthorized use. MailMama will comply with applicable obligations under the CCPA and will provide the Customer with the assistance necessary to enable the Customer to respond to consumer requests.

17. Liability

Each party’s liability arising out of or in connection with this DPA, including the Standard Contractual Clauses, is subject to the exclusions and limitations of liability set out in the Agreement, except that nothing in this DPA or the Agreement limits or excludes liability that cannot lawfully be limited or excluded, including the rights of data subjects under the Standard Contractual Clauses and the liability of the parties to data subjects and supervisory authorities under Data Protection Law.

18. Term, Conflict, and General

This DPA takes effect as described in Section 1 and continues until MailMama ceases to process Customer Personal Data. Sections relating to confidentiality, deletion, international transfers, liability, and any provision that by its nature should survive, survive termination.

In the event of a conflict, the order of precedence is: the Standard Contractual Clauses, then this DPA, then the Agreement, then any other document, in each case only in relation to the processing of Customer Personal Data. In all other respects the Agreement continues in full force.

If any provision of this DPA is held invalid or unenforceable, the remaining provisions continue in effect. This DPA is governed by the law stated in the Agreement, except where Section 15 or mandatory Data Protection Law requires otherwise.

19. Execution

Where a signed copy is required, the Customer may complete the details below and return the document to info@mailmama.net. MailMama will countersign and return an executed copy. Electronic signature is accepted.

MailMama Software LLC

Name: ______________________________

Title: ______________________________

Signature: __________________________

Date: ______________________________

Customer

Legal entity name: ___________________

Registered address: __________________

Contact email for data protection notices: ___________________

Name: ______________________________

Title: ______________________________

Signature: __________________________

Date: ______________________________

Annex I — Description of the Processing

A. List of Parties

Data exporter: the Customer identified in the applicable order or account record. Role: controller, or processor where the Customer processes on behalf of a third-party controller. Activities relevant to the transfer: use of hosted business email and email productivity services. Contact details and signature: as recorded in the Customer’s account and in Section 19.

Data importer: MailMama Software LLC, 75 E 3rd St, Sheridan, WY 82801, United States, info@mailmama.net. Role: processor, or subprocessor where the Customer is a processor. Activities relevant to the transfer: provision of hosted business email and email productivity services as described in the Agreement.

B. Description of the Processing

Categories of data subjects: the Customer’s authorized users and mailbox users; the Customer’s employees, contractors, and personnel; the Customer’s clients, suppliers, and business contacts; senders of messages to the Customer’s mailboxes; recipients of messages sent by the Customer; and any other individual whose personal data appears in Customer Content.

Categories of personal data: names; email addresses; telephone numbers and postal addresses where included; job titles and organizational information; the content of email messages and attachments; contacts and address book entries; calendar entries where applicable; message metadata including sender and recipient addresses, timestamps, message identifiers, routing and delivery records, and authentication results; mailbox and alias names; folder structures and filter rules; authentication credentials in hashed form and access tokens for connected accounts; IP addresses, device and browser information, and connection logs; and, where the Customer enables the relevant features, email tracking event data and data submitted to AI-assisted features.

Special categories of personal data: MailMama does not request and does not intentionally collect special category data. Customer Content may contain special category data placed there by the Customer or by a correspondent. Where present, it is protected by the measures described in Annex II, including access restriction, logging, and encryption in transit.

Frequency of the transfer: continuous, for the duration of the Agreement.

Nature of the processing: collection, receipt, transmission, routing, filtering, storage, organization, retrieval, indexing, backup, restoration, display, synchronization, automated abuse and malware scanning, and, where enabled by the Customer, tracking-event recording and AI-assisted summarization and drafting, followed by erasure.

Purpose of the processing: to provide, operate, secure, maintain, and support the hosted business email and email productivity services ordered by the Customer.

Duration of the processing: the term of the Agreement, plus the export and deletion periods described in Section 13.

Processing by Subprocessors: the subject matter, nature, and duration of processing by each Subprocessor are limited to the function that Subprocessor performs, as described in Annex III, and continue for as long as that Subprocessor is engaged.

C. Competent Supervisory Authority

Where the Standard Contractual Clauses apply, the competent supervisory authority is determined in accordance with Clause 13, being the supervisory authority of the member state in which the Customer is established, or in which its Article 27 representative is established, or in which the data subjects whose personal data is transferred are located, as applicable. For transfers subject to the UK GDPR, the competent authority is the Information Commissioner’s Office. For transfers subject to Swiss law, the competent authority is the Federal Data Protection and Information Commissioner.

Annex II — Technical and Organizational Measures

MailMama implements and maintains the following measures. The measures are reviewed periodically and may be updated provided the level of protection is not materially reduced.

Access control and authentication

  • Role-based access control with least-privilege assignment for administrative and support access.

  • Individual named accounts for personnel, with no shared administrative credentials.

  • Multi-factor authentication required for administrative access to production systems.

  • Storage of account credentials using accepted one-way hashing methods with salting.

  • Secure handling and storage of access tokens for connected third-party accounts.

  • Prompt revocation of access on change of role or termination of engagement.

Encryption

  • Encryption of data in transit over public networks using industry-standard transport protocols, including opportunistic transport encryption for mail exchange where the receiving network supports it.

  • Encryption of data at rest in the production environment and in backups, using industry-standard algorithms and managed key material.

System security and integrity

  • Segregation of production, staging, and development environments.

  • Logical separation of customer data within multi-tenant systems.

  • Network controls restricting access to production systems to authorized sources.

  • Timely application of security patches to infrastructure and application components.

  • Automated anti-malware and anti-phishing scanning of message traffic.

  • Rate limiting, connection throttling, and abuse detection controls on mail and API interfaces.

Logging and monitoring

  • Logging of administrative access, authentication events, configuration changes, and security-relevant events.

  • Monitoring and alerting for anomalous access, abnormal traffic, and abuse indicators.

  • Retention of security logs for the periods described in the Privacy Policy.

Availability and resilience

  • Regular backups of production data with documented restoration procedures.

  • Periodic testing of restoration from backup.

  • Capacity monitoring and redundancy appropriate to the Services.

Organizational measures

  • Confidentiality obligations binding on all personnel and contractors with access to Customer Personal Data.

  • Security and data protection awareness requirements for personnel with such access.

  • Documented incident response and breach notification procedures.

  • Written data protection terms with all Subprocessors, including the terms required by Article 28(3) of the GDPR.

  • Assessment of Subprocessors before engagement and periodic review thereafter.

  • Data minimization and retention schedules as described in the Privacy Policy.

  • Secure disposal of media and deletion of data at the end of the retention period.

Measures for transfers to Subprocessors

  • Subprocessors are engaged only under written contracts imposing equivalent obligations.

  • Transfers to Subprocessors located outside the European Economic Area or the United Kingdom are covered by an appropriate transfer mechanism.

  • Subprocessor access is limited to the data necessary for the function performed.

MailMama does not claim any security certification, audit attestation, or compliance accreditation in this Annex. Where MailMama obtains a certification or third-party audit report, it will be made available to Customers under Section 14.

Annex III — Subprocessors

MailMama engages Subprocessors in the following categories. The current list of named Subprocessors, including the identity of each Subprocessor, the function it performs, and the country in which it processes Customer Personal Data, is maintained by MailMama and provided to the Customer on request at info@mailmama.net. Changes are notified in accordance with Section 9.

  • Cloud infrastructure, compute, storage, and content delivery providers.

  • Email infrastructure, routing, filtering, anti-spam, and anti-malware providers.

  • Domain name system and network service providers.

  • Backup and disaster recovery providers.

  • Artificial intelligence providers supporting optional AI-assisted features.

  • Customer support, ticketing, and communication providers.

  • Monitoring, logging, error reporting, and security providers.

  • Payment processing and billing providers, to the extent they process personal data on MailMama’s behalf.

  • Identity, business, and sanctions verification providers.

Named Subprocessor list: available to customers on request at info@mailmama.net.

Scroll to Top