Subject Matter
MailForge processes workspace, sender, campaign, contact, automation, reporting, billing, security, and audit data to provide the email marketing service.
Legal
This Data Processing Agreement summary describes MailForge as a software interface processing data on client instructions. The client determines the purposes, recipients, content, and lawful basis for email marketing activity and remains responsible for those decisions.
Data Processing Agreement
MailForge processes workspace, sender, campaign, contact, automation, reporting, billing, security, and audit data to provide the email marketing service.
Processing is performed to authenticate users, operate workspaces, store and organize contacts, prepare sends, queue automations, report activity, and support customers.
Customer data may include business contact details, subscriber contact fields, suppression status, campaign content, sender metadata, SMTP secrets, usage logs, and engagement metrics.
Processing continues while the customer uses the service and during any retention period needed for legal, security, backup, billing, or dispute purposes.
Data Processing Agreement
The client determines the subscriber data uploaded to MailForge, the campaign purpose, recipient audience, message content, retention period, and sending provider used.
MailForge processes client data according to product configuration and client instructions. It does not independently select recipients or decide why marketing messages are sent.
The client remains responsible for receiving and responding to data subject requests. MailForge may provide technical assistance where available, but does not replace the client’s legal role.
The client is responsible for requesting export, deletion, suppression, or retention actions in accordance with its own legal obligations and contracts.
Data Processing Agreement
Controls include role-based access, session protection, 2FA posture, CSRF protection, credential encryption, audit logs, and tenant-aware data access.
The client must configure access, protect credentials, limit user permissions, choose appropriate providers, and verify that connected services meet its compliance needs.
The client should review any infrastructure, database, email, payment, analytics, monitoring, and support providers used in production and decide whether transfer terms are required.
To the fullest extent permitted by applicable law, MailForge and Sahsee Technology LLP are not responsible for claims arising from the client’s data choices, campaign purpose, recipient selection, provider use, or failure to comply with data protection laws.
Next step