MailPulse
GDPR and data processing
Who is responsible for what, which sub-processors are involved, and how to get a data processing agreement.
Which of us is responsible for what
For your own account details, we are the controller: we decide what is collected and why.
For the contacts you upload and the people you send to, you are the controller and we are your processor. You decide who is on your list, what you send them, and how long you keep them. We act on your instructions and nothing else.
That distinction decides who answers a request from one of your recipients. If somebody asks us to delete their data and they are your contact rather than your account holder, we will point them at you, because acting on it ourselves would mean changing your data without your instruction.
A data processing agreement
If you need a signed DPA, write to support@royalbengal.ai and we will provide one. It incorporates the standard contractual clauses for transfers outside the UK and the European Economic Area.
Sub-processors
These four, and we will give notice before adding another.
Amazon Web Services, in the us-east-1 region in the United States, which delivers the email and reports what happened to it.
Supabase, which hosts the database and handles authentication.
Railway, which runs the application.
Stripe, which processes payments. Stripe holds card details; we do not.
The rights of the people you email
Access, correction, deletion, and objection to processing. In practice, for a mailing list, most of these come down to unsubscribing and being deleted, and both are available from the dashboard immediately. Deleting a contact removes them from the audience and from every list; the delivery records for messages already sent to them remain, including the address those messages went to.
You can export a single contact's full record, including their delivery and engagement history, from the contact's own page. Deleting a contact removes that record, with the exception of the suppression entry for an address that hard bounced or complained, which is kept precisely so it is never emailed again.
Security
Every request to the database is checked against row-level security rules in the database itself, so one workspace cannot read another's data even if the application asks it to. API keys are stored as hashes and shown once, at creation. Traffic is encrypted in transit.
We will tell you without undue delay if we become aware of a breach affecting data we hold for you, and we will tell you what we know rather than waiting until we know everything.
Retention
Delivery records are kept for as long as the workspace exists and are deleted when it is closed, or when the individual campaign is deleted. Webhook delivery records are removed after three months and our internal audit records after one year. Contacts and campaigns stay until you delete them, and deleting a contact does not remove their address from the delivery records of messages already sent to them.
Written to describe what MailPulse actually does rather than to cover everything a lawyer would cover. If something here does not match what you see in the product, the product is the thing that is wrong and we want to hear about it: support@royalbengal.ai.
