Last updated: 2 June 2026
A signed copy of this Data Processing Agreement is available on request.
This DPA forms part of the Agreement between the Client ("you", the Controller) and Remails B.V., trading as Email.eu, Boumaboulevard 406, 9723 ZT Groningen, The Netherlands, KVK 89044819 ("Email.eu", the Processor). It governs the processing of personal data within Customer Data and gives effect to Article 28 GDPR. Capitalised terms not defined here have the meaning given in the Terms. Where this DPA conflicts with the Terms on data protection, this DPA prevails.
"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data within Customer Data that we process on your behalf.
You are the Controller and Email.eu is the Processor of Customer Personal Data. Where you are yourself a processor for your own customers, you act as their processor and we act as sub-processor; in that case your instructions to us must be consistent with your own controller's instructions. We process Customer Personal Data only to provide the Service and as described in Annex I, for the duration of the Agreement.
We process Customer Personal Data only on your documented instructions, including the instructions set out in the Agreement and given through the configuration choices and features of the Service. We will not process Customer Personal Data for our own purposes. If we are required by EU or Member State law to process otherwise, we will inform you first unless that law prohibits it. If we believe an instruction infringes data protection law, we will tell you.
We ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are trained on their obligations. Access is limited to personnel who need it to provide or support the Service.
We implement and maintain the technical and organisational measures set out in Annex II, appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. We may update these measures provided the level of protection is not reduced.
You provide general written authorisation for us to engage sub-processors to process Customer Personal Data. Our current sub-processors are listed in Annex III and on our published, machine-readable sub-processor list. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.
We will give at least 30 days' advance notice of any intended addition or replacement of a sub-processor (via the published list and its change-notification feed). You may object on reasonable, data-protection-related grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the Service.
We process Customer Personal Data exclusively within the EU/EEA, in the hosting region(s) you select. We will not transfer Customer Personal Data outside the EU/EEA without your explicit, documented instruction and an appropriate Article 46 GDPR transfer mechanism (such as an adequacy decision or the European Commission's Standard Contractual Clauses with any necessary supplementary measures).
Taking into account the nature of the processing and the information available to us, we will assist you, by appropriate technical and organisational measures and so far as reasonably possible, to:
We may charge reasonable costs for assistance beyond what the Service provides through its standard features, on prior notice.
We will notify you without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, with the information then available (nature of the breach, likely consequences, and the measures taken or proposed). We will cooperate with you and take reasonable steps to mitigate. You are responsible for any notifications to Supervisory Authorities or Data Subjects, unless we agree otherwise.
We make available the information necessary to demonstrate compliance with Article 28 GDPR, including our certifications and third-party audit reports as they become available (see our trust center and the Email.eu compliance roadmap). On reasonable prior notice of at least four weeks, and no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), you may audit our compliance, by yourself or an independent auditor bound by confidentiality. Audits must respect the security and confidentiality of other tenants. You bear the costs of audits you initiate; we bear the costs of remedying any non-compliance found.
On termination of the Agreement, at your choice, we will return Customer Personal Data to you or securely delete it, and delete existing copies, within the post-termination retrieval and deletion windows set out in the Terms — a 30-day retrieval window followed by secure deletion within a further 90 days — unless EU or Member State law requires retention. Operational backups containing Customer Personal Data are deleted on their normal 30-day rotation cycle (see Annex II).
Each party's liability under this DPA is subject to the limitations of liability in the Terms, to the extent permitted by the GDPR.
This DPA takes effect when the Agreement does and remains in force for as long as we process Customer Personal Data on your behalf.
Technical
Organisational
| Sub-processor | Role | Location |
|---|---|---|
| OVHcloud (OVH SAS) | Infrastructure hosting (compute, storage, network) | EU/EEA (France) |
| Mollie B.V. | Payment processing | EU/EEA (Netherlands) |
| Moneybird B.V. | Invoicing & accounting (billing contact and invoice data) | EU/EEA (Netherlands) |
The Email.eu mail, file, and identity software (Stalwart, La Suite Drive, Authentik) is self-hosted by Email.eu on the above infrastructure and is not a separate sub-processor. Outbound transactional email is handled within the Remails B.V. group. Self-hosted billing (Lago) runs on the OVHcloud infrastructure above and is not a separate sub-processor.
© 2026 Remails B.V. All rights reserved.