Switch in a weekend

Request a free migration

Tell us where you’re coming from and we’ll do the rest, free. A migration specialist in Groningen moves your mail, calendars, contacts and files, and schedules cutover around your team.

We only use these details to plan your migration. See our privacy terms.

Your migration request is in.

A migration specialist in Groningen will email you within one business day to scope the move and map out a cutover that fits your team.

Product
The suite
Every app. One workspace.
See full product
Email
Priority inbox, instant search, open standards.
Calendar
Scheduling that respects timezones and focus.
Drive
Files with keys your team controls.
Docs
Real-time writing, comments, version history.
Sheets
Spreadsheets with formulas and real-time collab.
Slides
Designed decks, slide libraries, brand kits.
Wiki
Team knowledge base, structured, searchable.
Meet
HD video hosted in the EU by default.
Chat
Channels, DMs, and threads, searchable.
Platform
Security & TrustPricingCompare alternativesAbout
Get started

Hand-onboarded by our team in Groningen. Migration tooling included, cancel anytime.

Sign up
Pricing
Company
About Email.eu
An independent European company.
The company
About usMission, team & ownershipSecurity & TrustArchitecture, audits & disclosuresPartner programResell, refer & earn marginBlogNews, updates & deep dives
Contact
EnglishENNederlandsNLDeutschDEFrançaisFR
Sign inSign up
Product
OverviewSecurity & Trust
Company
AboutPricingPartner programBlog
Contact
Language
EnglishENNederlandsNLDeutschDEFrançaisFR
Sign upSign in

Email.eu — Data Processing Agreement

Last updated: 2 June 2026

A signed copy of this Data Processing Agreement is available on request.

This DPA forms part of the Agreement between the Client ("you", the Controller) and Remails B.V., trading as Email.eu, Boumaboulevard 406, 9723 ZT Groningen, The Netherlands, KVK 89044819 ("Email.eu", the Processor). It governs the processing of personal data within Customer Data and gives effect to Article 28 GDPR. Capitalised terms not defined here have the meaning given in the Terms. Where this DPA conflicts with the Terms on data protection, this DPA prevails.


1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data within Customer Data that we process on your behalf.

2. Roles & scope

You are the Controller and Email.eu is the Processor of Customer Personal Data. Where you are yourself a processor for your own customers, you act as their processor and we act as sub-processor; in that case your instructions to us must be consistent with your own controller's instructions. We process Customer Personal Data only to provide the Service and as described in Annex I, for the duration of the Agreement.

3. Processing instructions

We process Customer Personal Data only on your documented instructions, including the instructions set out in the Agreement and given through the configuration choices and features of the Service. We will not process Customer Personal Data for our own purposes. If we are required by EU or Member State law to process otherwise, we will inform you first unless that law prohibits it. If we believe an instruction infringes data protection law, we will tell you.

4. Confidentiality

We ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are trained on their obligations. Access is limited to personnel who need it to provide or support the Service.

5. Security

We implement and maintain the technical and organisational measures set out in Annex II, appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. We may update these measures provided the level of protection is not reduced.

6. Sub-processors

You provide general written authorisation for us to engage sub-processors to process Customer Personal Data. Our current sub-processors are listed in Annex III and on our published, machine-readable sub-processor list. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.

We will give at least 30 days' advance notice of any intended addition or replacement of a sub-processor (via the published list and its change-notification feed). You may object on reasonable, data-protection-related grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the Service.

7. International transfers

We process Customer Personal Data exclusively within the EU/EEA, in the hosting region(s) you select. We will not transfer Customer Personal Data outside the EU/EEA without your explicit, documented instruction and an appropriate Article 46 GDPR transfer mechanism (such as an adequacy decision or the European Commission's Standard Contractual Clauses with any necessary supplementary measures).

8. Assisting you

Taking into account the nature of the processing and the information available to us, we will assist you, by appropriate technical and organisational measures and so far as reasonably possible, to:

  • 8.1 Data Subject requests. Respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, objection). Where a Data Subject contacts us directly about Customer Personal Data, we will forward the request to you and not respond ourselves except on your instruction.
  • 8.2 Security, breach notification, DPIAs, and prior consultation. Comply with your obligations under Articles 32–36 GDPR.

We may charge reasonable costs for assistance beyond what the Service provides through its standard features, on prior notice.

9. Personal Data Breach

We will notify you without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, with the information then available (nature of the breach, likely consequences, and the measures taken or proposed). We will cooperate with you and take reasonable steps to mitigate. You are responsible for any notifications to Supervisory Authorities or Data Subjects, unless we agree otherwise.

10. Audits & inspections

We make available the information necessary to demonstrate compliance with Article 28 GDPR, including our certifications and third-party audit reports as they become available (see our trust center and the Email.eu compliance roadmap). On reasonable prior notice of at least four weeks, and no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), you may audit our compliance, by yourself or an independent auditor bound by confidentiality. Audits must respect the security and confidentiality of other tenants. You bear the costs of audits you initiate; we bear the costs of remedying any non-compliance found.

11. Return & deletion

On termination of the Agreement, at your choice, we will return Customer Personal Data to you or securely delete it, and delete existing copies, within the post-termination retrieval and deletion windows set out in the Terms — a 30-day retrieval window followed by secure deletion within a further 90 days — unless EU or Member State law requires retention. Operational backups containing Customer Personal Data are deleted on their normal 30-day rotation cycle (see Annex II).

12. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms, to the extent permitted by the GDPR.

13. Duration

This DPA takes effect when the Agreement does and remains in force for as long as we process Customer Personal Data on your behalf.


Annex I — Details of the processing

  • Subject matter & duration: Provision of the Email.eu workspace for the duration of the Agreement plus any retrieval/deletion window.
  • Nature & purpose: Hosting, transmission, storage, indexing, backup, and security of mailboxes, email, files, contacts, calendars, and identity data, and providing related support — solely to deliver the Service.
  • Categories of Data Subjects: The Client's Users (employees, contractors); the Client's own contacts and customers whose data appears in Customer Data; any other individuals whose personal data the Client chooses to store in the Workspace.
  • Categories of Personal Data: Identification and contact data (names, email addresses, usernames); authentication data; content of emails, files, calendars, and contacts submitted by the Client and its Users; technical and usage metadata necessary to operate and secure the Service.
  • Special categories: Not requested or required by the Service. The Client may choose to store such data within Customer Data and is responsible for ensuring a lawful basis; we apply the measures in Annex II to all Customer Personal Data.

Annex II — Technical & organisational measures

Technical

  • Encryption in transit (TLS 1.3, HSTS) and at rest (AES-256)
  • Optional end-to-end encryption per tenant (PGP / S/MIME)
  • Per-tenant isolation: dedicated encryption keys held in a hardware security module, dedicated storage paths, and per-tenant quota enforcement; optional bring-your-own-key for eligible plans
  • Hosting exclusively in EU/EEA regions you select, with 3× redundancy
  • Encrypted operational backups with a retention of 30 days
  • Infrastructure as code, monitoring, and logging
  • Access controls and least-privilege administrative access

Organisational

  • Security-trained staff bound by confidentiality undertakings
  • Strong authentication (multi-factor for administrative access; strong password policy)
  • Full-disk encryption on workstations; restrictions on removable media
  • Documented incident-response process; post-incident write-ups within 7 days, where appropriate
  • Vendor/sub-processor due diligence and data protection terms

Annex III — Approved sub-processors

Sub-processorRoleLocation
OVHcloud (OVH SAS)Infrastructure hosting (compute, storage, network)EU/EEA (France)
Mollie B.V.Payment processingEU/EEA (Netherlands)
Moneybird B.V.Invoicing & accounting (billing contact and invoice data)EU/EEA (Netherlands)

The Email.eu mail, file, and identity software (Stalwart, La Suite Drive, Authentik) is self-hosted by Email.eu on the above infrastructure and is not a separate sub-processor. Outbound transactional email is handled within the Remails B.V. group. Self-hosted billing (Lago) runs on the OVHcloud infrastructure above and is not a separate sub-processor.


© 2026 Remails B.V. All rights reserved.

The sovereign business workspace. Built in Europe, for Europe, by an independent European company.

Service status

Product

  • Overview
  • Pricing
  • Security & Trust
  • Compare alternatives
  • Alternatives guide

Company

  • About
  • Blog
  • Partner program
  • Contact

Newsletter

Building a sovereign workspace, a monthly letter on what shipped and what's next. No tracking, unsubscribe anytime.

© 2026 Remails B.V. · KVK 89044819 · Groningen, NL
PrivacyTermsDPACookies
Ask us anything

Questions about Email.eu?

Sovereignty, migration, pricing, whatever’s on your mind. A real person in Groningen replies by email, usually the same day.

We only use your email to reply. See our privacy terms.

Got it. Thanks for asking.

Your question landed with our team in Groningen. We’ll reply to your email, usually within one business day.

Live walkthrough

Book a demo of Email.eu

30 minutes, screen-shared with a solutions engineer in Groningen. We tailor it to your stack, bring the migration questions.

We’ll send a calendar invite from our Groningen team, never outside the EU. See our privacy terms.

Thanks, we’ll be in touch.

A solutions engineer in Groningen will email you within one business day with a couple of slots that fit your timezone.

  1. Confirm a slot. Pick the time that works, calendar invite lands in your inbox.
  2. The walkthrough. 30 minutes, screen-shared, tailored to your stack and migration path.
  3. Next steps. Trial workspace provisioned the same week if you want to go deeper.