Legal

Data Processing Agreement

This Data Processing Agreement summary describes MailForge as a software interface processing data on client instructions. The client determines the purposes, recipients, content, and lawful basis for email marketing activity and remains responsible for those decisions.

Data Processing Agreement

Processing Details

Subject Matter

MailForge processes workspace, sender, campaign, contact, automation, reporting, billing, security, and audit data to provide the email marketing service.

Processing Purpose

Processing is performed to authenticate users, operate workspaces, store and organize contacts, prepare sends, queue automations, report activity, and support customers.

Data Categories

Customer data may include business contact details, subscriber contact fields, suppression status, campaign content, sender metadata, SMTP secrets, usage logs, and engagement metrics.

Processing Duration

Processing continues while the customer uses the service and during any retention period needed for legal, security, backup, billing, or dispute purposes.

Data Processing Agreement

Roles and Instructions

Client as Controller

The client determines the subscriber data uploaded to MailForge, the campaign purpose, recipient audience, message content, retention period, and sending provider used.

MailForge as Interface or Processor

MailForge processes client data according to product configuration and client instructions. It does not independently select recipients or decide why marketing messages are sent.

Data Subject Requests

The client remains responsible for receiving and responding to data subject requests. MailForge may provide technical assistance where available, but does not replace the client’s legal role.

Return or Deletion

The client is responsible for requesting export, deletion, suppression, or retention actions in accordance with its own legal obligations and contracts.

Data Processing Agreement

Safeguards and Liability

Security Measures

Controls include role-based access, session protection, 2FA posture, CSRF protection, credential encryption, audit logs, and tenant-aware data access.

Client Safeguards

The client must configure access, protect credentials, limit user permissions, choose appropriate providers, and verify that connected services meet its compliance needs.

Subprocessors and Transfers

The client should review any infrastructure, database, email, payment, analytics, monitoring, and support providers used in production and decide whether transfer terms are required.

Liability Allocation

To the fullest extent permitted by applicable law, MailForge and Sahsee Technology LLP are not responsible for claims arising from the client’s data choices, campaign purpose, recipient selection, provider use, or failure to comply with data protection laws.

Next step

Plan your workspace with the right sending limits and controls.

Contact sales