• Resolved lovinglyhappy

    (@luckilyhappy)


    Hi,

    I am currently looking at whether MailPoet might be an option for me.

    Here, I have read about your servers. In order to really be GDPR compliant, it is of the utmost importance that no subscriber (personal) data shall be sent through, to or stored on any server outside of the EU or countries where it is applied as such.

    Therefore I would like to ask:

    – Where are the SMTP-servers located? And will you ever consider moving tham out of the EU, even in case they are in the EU?

    – You say you are storing logs of e-mails sent. Will they contain e-mail, IP and / or other subscriber data? And where are those logs stored?

    – Support enquiries by e-mail are stored. Does this refer only to your customer’s enquiries, or will you store your customers’ subscribers’ enquiries by e-mail, too (i.e. my concern is there might be in the newsletter or on the sign up, unsubscribe or management page accessible to the subscriber a support link leading to your support which might mnake me co-responsible for where you store those enquiries).`

    My apologies for molesting you with these detailed questions, but I think the answers are important, and I think it would be helpful if you could include these matters in your FAQ.

    • This topic was modified 2 years, 1 month ago by lovinglyhappy.
    • This topic was modified 2 years, 1 month ago by lovinglyhappy. Reason: spelling
    • This topic was modified 2 years, 1 month ago by lovinglyhappy. Reason: grammar
Viewing 8 replies - 1 through 8 (of 8 total)
  • Thread Starter lovinglyhappy

    (@luckilyhappy)

    P. S.: As I cannot edit my question any longer and only thought of this addition now, one further question: Are the SMTP-servers your own or are you using the services of a company that is ultimately located (or owned by a company located) outside of the EU?

    Plugin Support Dani F. a11n

    (@danielinhou)

    Hi there @luckilyhappy 👋🏽!

    Thank you for reaching out to MailPoet Support!

    My apologies for molesting you with these detailed questions, but I think the answers are important, and I think it would be helpful if you could include these matters in your FAQ.

    Hey, I’ll share these questions with the deliverability team and will get back to you here as soon as I hear from them. I’ll be happy to help from their reply too so no need to apologize at all.

    Thanks for your patience.

    Plugin Support Dani F. a11n

    (@danielinhou)

    Hi again,

    I can reply this one:

    Support enquiries by e-mail are stored. Does this refer only to your customer’s enquiries, or will you store your customers’ subscribers’ enquiries by e-mail, too (i.e. my concern is there might be in the newsletter or on the sign up, unsubscribe or management page accessible to the subscriber a support link leading to your support which might mnake me co-responsible for where you store those enquiries).

    This refers to our customer’s inquiries. Your subscribers won’t have a way to contact us.

    Thread Starter lovinglyhappy

    (@luckilyhappy)

    Hi Dani,

    Thank you for your answering that part of my question. I look forward to receiving the other answers from your deliverability team.

    Plugin Support Dani F. a11n

    (@danielinhou)

    Hi there @luckilyhappy 👋🏽

    Our team reached back to us. This issue is a bit outside of my understanding but this is what we got from them:

    Our services are GDPR compliant, and we offer a data processing agreement to formalize those obligations. Detailed information can be found at our privacy policy.

    I hope this helps.

    Cheers

    Thread Starter lovinglyhappy

    (@luckilyhappy)

    Hi Dani,

    Thank you for your reply. But my questions are, in most parts, not answered with it, as a brief look into your privacy policy does not reveal so much about where your servers are actually located (unless I have overlooked it), even less perhaps than the link I gave above.

    Your privacy policy only addresses a very small part of what I have asked, so I would like to point to my questions above once more. And the processing agreement, which I have read, does not answer these questions either.

    Actually, I even have to ask one more question: Would the SMTP-servers, or other servers in contact with my subscribers’ data, be, even if in Europe, owned by a company outside of the EU?

    I have seen more than once that companies explain to be GDPR-compliant and then, by my own judgement (not as an expert on IT law, but, still…), were either not or perhaps they were for themselves (if so…), but their setup did not allow their users to be compliant. I am not saying that this would be the case with you, but I prefer to look into matters myself. In the end, it is your customers who are responsible on their own, so it is only prudent to check for oneself. Again, I appreciate your efforts to give details, but why not give those I have asked, too, on your website (please forward this to the person in charge?

    Also, things are in flux and especially after the recent ruling against the use of Google Analytics I prefer not to have any servers owned by US companies in play at all in touch with the data of subscribers to my newsletters.

    I fully understand that it may not be your area of expertise, but these are legitimate questions actually every customer should, in my eyes, ask when dealing with services involving servers.

    I therefore suggest to forward my request to those who know about it. I an not too sure it would be the deliverability team anyway, by the way. This would be a question to those of your staff who are involved in actually dealing with the servers or those responsible for your privacy declaration.

    Without knowing about location and ownership of the servers my subscribers would come into contact with, an assessment of my own of whether my setup with you would be compliant for sure would be impossible.

    You seem to offer a good service; it would be great if you could allow potential customers to also assess the legal side for themselves by providing really all the relevant data.

    • This reply was modified 2 years, 1 month ago by lovinglyhappy. Reason: clarified
    • This reply was modified 2 years, 1 month ago by lovinglyhappy. Reason: spelling
    totheo

    (@totheo)

    Thank you very much for asking These important questions @luckilyhappy.

    These concerns are fully justified: At present, there are not even any drafts of the wording for a successor agreement to Privacy Shield, which the European Court of Justice declared invalid in a landmark ruling in 2020. So it could be years before the U.S. and Europe reach an agreement on this – if ever. In the meantime, it is unfortunatly a legal risk for European companies to transfer personal data to servers in the U.S. This is true even if a data processing agreement is concluded (and even with standard contractual clauses and if all technical organizational measures are specified).

    Therefore, I do not understand why Mailpoet quite obviously still does not operate servers in Europe. Please check the possibility to do so, dear Mailpoet team. Because as long as you don’t provide a solution for this, we can’t really use your great service and have to switch to other providers. That is a pity because Mailpoet really is awesome.

    I am sorry to be so direct, but this is the recommendation I have received from various IT lawyers by now.

    Plugin Support Dani F. a11n

    (@danielinhou)

    Hi again,

    While I am not an expert at all in this subject I think that many of your questions are answered in the DPA agreement that we offer to our customers. https://kb.mailpoet.com/article/303-is-mailpoet-gdpr-compliant

    Please follow the steps listed in that tutorial to get a signed copy of our DPA and then reach back to us if you still have further questions.

    Cheers

Viewing 8 replies - 1 through 8 (of 8 total)
  • The topic ‘Server Locations in Contact with Subscribers’ Data’ is closed to new replies.