Third Party Index

Snapshot 62432

Document
Trust center
URL
https://maileroo.com/trust-center
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
158407 bytes
SHA-256 (raw)
b5b6be42bb298ad467881bdf39ef9f827a9efb9feadc6ffcd81e4c0a308f9974
SHA-256 (normalized text)
d5da6ce6969438203dbc747e9e71c6391915aa1e10d3f6ee1a763588d1f8ddaa

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Compliance
SOC 2 Type IIIn Progress
GDPRCompliant
Certified Senders AllianceCertified
ISO 27001Coming Soon
Resources
Request access
Third-Party Management Policy
Request access
Information Security Policy
Request access
Information Security Roles and Responsibilities
Request access
Secure Development Policy
Request access
Business Continuity and Disaster Recovery Plan
Request access
Controls
Infrastructure Security
Network segmentation implemented
Production multi-availability zones established
Production data segmented
Organizational Security
Production inventory maintained
Employee background checks performed
Asset disposal procedures utilized
Internal Security Procedures
Support system available
Service description communicated
Third-party agreements established
Product Security
Data encryption utilized
Vulnerability and system monitoring procedures established
Data transmission encrypted
Data and Privacy
Data retention procedures established
Data classification policy established
Subprocessors
View in DPA
Stripe, Inc.
Subscription billing, payment processing, tax compliance, and customer invoicing
United States
Paddle.com Market Limited
Subscription billing, payment processing, tax compliance, and customer invoicing
United Kingdom
Crisp IM SAS
Customer support chat and messaging platform
France
Zendesk, Inc.
Customer support ticketing system and helpdesk software
United States
StatCounter
Analytics and reporting services
Ireland
FAQ
Maileroo is certified by the Certified Senders Alliance and complies with the EU GDPR, and we have appointed an EU representative under Article 27. Our SOC 2 Type II audit is in progress and ISO 27001 certification is coming soon. The Compliance tab shows the current status of each framework.
We process customer data only to provide the service and on your documented instructions, as set out in our Data Processing Addendum. Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, and backups are encrypted.
Email processing runs on EU infrastructure across Germany, the Netherlands, France, and Finland. Supporting services such as billing and support tools are provided by the subprocessors listed on this page.
Email content, attachments, metadata, and delivery logs are kept for up to 14 days from transmission. Encrypted backups are kept for up to 30 days and then deleted using secure deletion methods.
Yes. We work with 25 vetted subprocessors for hosting, payments, support, and fraud prevention. The Subprocessors tab lists each one with its location and purpose, and the same list appears in Annex 3 of our Data Processing Addendum.
Yes. We email customers at least 30 days before adding or replacing a subprocessor. You can object on reasonable data protection grounds within 15 days of that notice.
No. Our Data Processing Addendum forms part of our Terms and applies automatically to every customer, including Standard Contractual Clauses for international transfers. If your legal team needs a countersigned copy, contact us.
We notify affected customers without undue delay, and in any event within 72 hours of becoming aware of a personal data breach. Each incident is logged, investigated, and resolved under our incident response plan.
Every plan includes two-factor authentication and passkeys. SAML single sign-on is available on Pro plans and above, so your team can sign in through your identity provider.
Select Request access next to any locked document and you will be taken to our contact page. Tell us which documents you need and our team will review the request and share them with you directly.
Use our contact page or email [email protected] for security questions and vulnerability reports. For privacy, GDPR, or Data Processing Addendum questions, email [email protected].
We update this Trust Center whenever our compliance status, controls, or subprocessors change. Material changes to the subprocessor list are also emailed to customers in advance.