Privacy Notice
This notice explains how devsub GmbH handles personal data on the Mailactor website, in access enquiries, and when operating the invite-only Mailactor email API.
1. Controller
devsub GmbH, c/o Quartier22, Bautzner Str. 22, 01099 Dresden, Germany, represented by Maurice Ihl, is the controller for the website and for the business, security, and compliance processing described below. Email us at hello@mailactor.com. Further provider information is available in the Imprint.
2. Website access
When this website is requested, the web server processes technical connection data needed to deliver and protect it. This can include IP address, date and time, requested URL, referrer if supplied by the browser, user agent, and response status. We process this data to provide the website, prevent misuse, diagnose faults, and maintain security on the basis of our legitimate interests under Article 6(1)(f) GDPR.
Access logs are kept only for the time reasonably needed for security and troubleshooting, then erased or anonymised unless a specific incident or legal obligation requires longer retention. The current website code does not include marketing analytics, advertising trackers, account forms, or non-essential browser storage. If that changes, this notice and any consent mechanism will be updated before the new processing is enabled.
3. Enquiries and onboarding
If a person contacts us, we process their contact details, the content of the enquiry, and related correspondence to respond, assess the proposed use case, and arrange access. The legal basis is Article 6(1)(b) GDPR where processing is needed for pre-contractual steps with the person, and otherwise our legitimate interest in business communication under Article 6(1)(f) GDPR.
For private-beta onboarding, we may also record the organisation, responsible contact, intended sending domain, expected volume, and use case so we can assess safety, deliverability, and eligibility. Business correspondence is erased when no longer needed for those purposes, subject to statutory record-keeping duties and the need to establish, exercise, or defend legal claims.
4. Mailactor service data
Depending on how a customer uses Mailactor, the service processes organisation and contact details; domains and DNS records; inbox and thread metadata; sender and recipient addresses; subject lines; message bodies, raw email, and attachments; delivery events, replies, complaints, and suppression records; webhook destinations and delivery attempts; and limited API, network, audit, and security data.
This data comes from customers and their users, correspondents, public DNS, email and network providers, and the operation of the service. It is used to create and manage inboxes, send and receive email, maintain threads, deliver webhooks, enforce sending controls, prevent abuse, investigate security issues, and keep the service reliable.
5. Roles and legal bases
For message content and other personal data processed on a customer's instructions, the customer is normally the controller and devsub GmbH acts as processor under Article 28 GDPR. The customer determines the applicable legal basis, provides required notices to data subjects, and must enter into an appropriate data-processing agreement with us before production use involving personal data.
We act as an independent controller where we process business contact data to manage the customer relationship, security and audit data to protect the platform, and limited delivery, complaint, and suppression evidence to prevent abuse and protect email deliverability. Depending on the activity, this processing is necessary for a contract or pre-contractual steps under Article 6(1)(b) GDPR, compliance with a legal obligation under Article 6(1)(c), or our legitimate interests in operating a secure and trustworthy service under Article 6(1)(f).
6. Recipients and international delivery
We use Hetzner infrastructure and object storage in Europe for the core service. Within their duties, authorised operators and advisers may receive limited data. Email is sent to recipient mail providers, and events may be sent to webhook destinations selected by the customer. We may also disclose data where required by law or necessary to protect legal rights.
Email delivery is global by nature. A recipient's mail provider or a customer-selected webhook may be outside the European Economic Area. The customer is responsible for the destinations it selects and the lawfulness of its instructions. Where we transfer controller data to a recipient outside the EEA, we use an applicable adequacy decision or appropriate safeguards where required by Chapter V GDPR.
7. Retention and deletion
We keep account, domain, and inbox metadata while it is needed to provide and administer the customer's access. Message bodies, raw email, and attachments are removed when the customer's configured retention period expires or the relevant inbox, message, or organisation is deleted. Deletion is applied to active object storage before linked metadata and then propagates through encrypted backup rotation.
Delivery and webhook records, redacted operational logs, and security evidence are retained only for the period needed to operate and secure the service, investigate incidents, and establish or defend legal claims. Complaint and suppression records may be kept longer where needed to prevent repeated unwanted email. A longer period applies only where required by law, a legal hold, or an agreed customer configuration.
8. Security
Mailactor uses tenant-scoped credentials and access controls, encrypted transport, service-managed encryption for stored mailbox content and attachments, signed webhooks, and logging designed to exclude message bodies. Access is limited to what is needed to operate and protect the service.
Mailactor is not end-to-end encrypted. The service must process email content to send, receive, parse, store, and deliver it as instructed. Customers should not submit data that is unnecessary for their use case and should secure their own credentials and webhook endpoints.
9. Your rights
Subject to the statutory conditions, a data subject may request access, correction, deletion, restriction, or portability of their personal data. They may object to processing based on Article 6(1)(f) GDPR. Where consent is the legal basis, it may be withdrawn at any time without affecting earlier lawful processing. We may need to verify the requester's identity before acting on a request.
Where devsub GmbH is a processor, the customer controls the response and requests should normally be directed to that customer. We assist customers with verified requests as required by the applicable data-processing agreement.
A data subject also has the right to lodge a complaint with a data protection supervisory authority. The authority responsible for companies established in Saxony is the Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden, Germany.
10. Changes to this notice
We may update this notice when the service, vendors, or legal requirements change. The current version will be published on this page with its revision date.
Last updated 7 September 2026.