Annex 1: Data Processing Agreement

Version 1.5 /June 2026

When you use MailBlue’s services, you process Personal Data relating to you and your contacts. Personal Data means data providing information about a natural person by which you can directly or indirectly establish that person’s identity. This means that the information is either directly about someone or can be traced back to that person. Examples of Personal Data include names, email addresses, telephone numbers and address details.

If you engage another organisation to process Personal Data on your behalf, the General Data Protection Regulation (GDPR) requires you to conclude a Data Processing Agreement with that organisation. Because you use MailBlue’s services, MailBlue is the Processor and you are designated as the Controller. In this Data Processing Agreement, we set out our arrangements concerning the processing of the Personal Data.

To make this Data Processing Agreement easier to read, we would first like to properly explain the most important terms to you:

Processor:
The person or organisation that processes Personal Data on behalf of the Controller, for example via a web application. In this Data Processing Agreement, MailBlue B.V., with its registered office at Akkerstraat 227, 4811 JL Breda, the Netherlands, and registered in the Commercial Register of the Dutch Chamber of Commerce under number 68740077, is the Processor.

Controller:
The (legal) person or organisation that determines whether Personal Data may be processed and, if so, which Personal Data, for what purpose that Personal Data may be processed, what that processing entails precisely, and which means may be used in doing so. In this Data Processing Agreement, you are the Controller.

Data Subject:
The person to whom the Personal Data relates. For example, your customer or supplier.

 

Processing of Personal Data:
Anything that can be done with Personal Data, such as:

  • collecting, recording and organising data;
  • retrieving, amending and consulting data;
  • disclosing data to others;
  • restricting access to or destroying data.

Data Breach:
A security incident in which Personal Data is accidentally or unlawfully destroyed, lost, altered, disclosed without authorisation or accessed without authorisation, and where it can reasonably be assumed that this leads to a risk to the rights and freedoms of the persons concerned.

Article 1 – General description

The subject matter of the processing:
The provision of services by MailBlue.


Duration of the processing:
The processing shall commence on the commencement date of the Agreement and shall end upon the expiry or termination of the Agreement.


Nature and purpose of the processing:
MailBlue offers software and services in the field of email marketing, marketing automation, CRM and (digital) communication channels, and supports the Client in deploying them. When you use our services, Personal Data of your customers or contacts is processed by us for marketing purposes or management purposes related to the customer relationship. MailBlue stores and processes part of the Personal Data on its own systems. The Personal Data processed in the context of the email marketing account is stored and processed via ActiveCampaign. In both cases, the processing shall take place exclusively in accordance with your instructions and not for our own purposes.


Categories of Personal Data processed:
Given the nature of MailBlue’s services, the categories of Personal Data processed may differ per Controller. Each Controller has the ability to choose which Personal Data the Processor will process. In any event, the following data is processed on behalf of each Controller:

  • email address;
  • name;
  • if email open tracking is enabled: IP address and click behaviour;
  • if the Controller uses email link tracking: IP address and click behaviour;
  • depending on the use of the software: other data, depending on the Controller.



Categories of data subjects:

Customers, prospective customers, business contacts and other contact persons of the Controller.

Article 2 – Responsibilities of the Processor

  1. MailBlue shall process Personal Data only on the instructions of the Controller and shall follow the Controller’s instructions in doing so. The Personal Data shall not be processed for MailBlue’s own purposes and shall remain the property of the Controller.
  2. MailBlue shall comply with the law and shall process the data in a proper, careful and transparent manner.
  3. The Controller hereby grants MailBlue general authorisation to engage Sub-processors. MailBlue shall maintain at mailblue.io/legal/subprocessors/ a current, publicly accessible list of all Sub-processors engaged, stating their name, place of establishment and the nature of the processing.
  4. MailBlue shall publish any changes to the list of Sub-processors at mailblue.io/legal/subprocessors/ at least 14 days before a new or changed Sub-processor is put into use. This publication constitutes the formal notification to the Controller. The Controller is itself responsible for keeping track of changes on this page. As an additional service, MailBlue offers the option of receiving email notifications of changes via an opt-in form on the aforementioned page; this service is voluntary and does not affect the validity of notification by publication.
  5. The Controller has the right to object in writing to the deployment of a new or changed Sub-processor within 10 business days of the date of publication at mailblue.io/legal/subprocessors/,  stating its reasons, via info@mailblue.nl. In that event, MailBlue and the Controller shall consult with a view to finding an appropriate solution. If the parties fail to reach agreement, the Controller has the right to terminate the Agreement in writing subject to a notice period of 30 days, without the Controller being entitled to any compensation. If the Controller does not object within the aforementioned period, the Sub-processor shall be deemed to have been approved.
  6. MailBlue shall impose on each Sub-processor at least the same data protection obligations as those imposed on MailBlue in this Data Processing Agreement, in particular the obligations concerning security, confidentiality and the transfer of personal data. MailBlue shall remain fully responsible to the Controller for the performance of these obligations by the Sub-processor.
  7. MailBlue shall provide the Controller with the information necessary to support it in the context of Articles 32 to 36 of the GDPR.
  8. In support of a DPIA, MailBlue shall make relevant information available via mailblue.io/legal/dpia-information/.
  9. iMailBlue shall ensure that its staff and any auxiliary persons engaged observe confidentiality.
  10. MailBlue shall inform the Controller if it suspects that the Controller’s instructions are contrary to the GDPR.
  11. MailBlue shall maintain a record of the processing activities it carries out as Processor, in accordance with Article 30(2) of the GDPR. A public list of the Sub-processors engaged and the nature of the processing can be consulted at mailblue.io/legal/subprocessors/. On request, MailBlue shall give the Controller access to the part of the processing record relevant to it.
  12. For questions about the processing of Personal Data and the performance of this Data Processing Agreement, the Controller may contact MailBlue’s Privacy Officer at avg@mailblue.nl.

Article 3 – Warranty by the Controller

The Controller warrants that the processing of the Data Subjects’ Personal Data is not unlawful and that this processing does not infringe the rights of others. The Controller indemnifies MailBlue against all claims relating thereto.

Article 4 – Security breach (Data Breach)

In the event that MailBlue discovers a Data Breach, reasonably suspects one, or receives notice from a third party that a breach has occurred which, in its judgement, poses a real risk to the rights and freedoms of data subjects, MailBlue shall notify the Controller thereof without undue delay, so that the Controller can assess in good time whether notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is necessary. MailBlue aims in any event to inform the Controller within 72 hours of discovery, so that the Controller can comply with its own notification deadline.

The notification shall include, to the extent known at that time, at least: a description of the nature of the breach, the categories and (estimated) numbers of data subjects and personal data records concerned, the name and contact details of the contact person at MailBlue, the likely consequences of the breach, and the measures MailBlue has taken or proposes to take. If not all information is immediately available, the notification may be provided in phases.

MailBlue shall keep the Controller informed of new developments concerning the Data Breach and shall submit to the Controller the measures taken to limit and end the Data Breach and to prevent a similar incident in the future.

Notification of the Data Breach to the Dutch Data Protection Authority is the responsibility of the Controller.

Article 5 – Term and termination

This Data Processing Agreement enters into force at the moment the Controller accepts MailBlue’s General Terms and Conditions, in accordance with Article 1 of those General Terms and Conditions. Separate signature of this Data Processing Agreement is not required.

This Data Processing Agreement is entered into for the duration of the Agreement between the Parties and, where signed, in any event for the duration of the working relationship.

After termination of this Data Processing Agreement, the obligations relating to confidentiality, liability and indemnification shall continue to apply.

MailBlue offers the Controller the opportunity to export the Personal Data processed in the context of the services at any time during the contract period. Exports are possible until the expiry date of the subscription. The Controller is itself responsible for exporting the required Personal Data in good time before the end of the contract period.

After termination of the services, MailBlue shall enable the Controller to export Personal Data for a period of 6 months after the expiry date of the subscription, by means of reactivating the subscription for a minimum period of 1 month. After this period, MailBlue shall archive the account and all Personal Data and existing copies shall be permanently deleted no later than 12 months after the expiry date, unless storage of that Personal Data is required pursuant to a statutory retention obligation. In that case, MailBlue shall retain the relevant Personal Data solely for the duration of that statutory obligation, after which it shall still be deleted.

At the Controller’s request, MailBlue shall provide written confirmation of the deletion of the Personal Data.

Article 6 – Confidentiality and secrecy

MailBlue shall treat as confidential all Personal Data and other data it receives from the Controller. MailBlue shall restrict access to this data to only those staff who need access for the proper performance of MailBlue’s services.

MailBlue shall keep the Personal Data provided confidential and shall also impose a duty of confidentiality on its staff.

Article 7 – Rights of data subjects

MailBlue shall provide its cooperation so that the Controller can respond to requests from data subjects under the GDPR (including requests for access, rectification, erasure, restriction of processing and data portability). MailBlue shall provide the Controller with the information required for this purpose within 5 business days of receipt of the request.

If MailBlue receives requests from third parties or government authorities to provide access to the Personal Data pursuant to a statutory obligation, MailBlue shall inform the Controller thereof without delay and in writing, unless a statutory prohibition prevents this. The Controller shall then assess whether the request is well-founded.

Article 8 – Transfer of Personal Data

MailBlue acts as a partner of ActiveCampaign and works with ActiveCampaign in providing its services. ActiveCampaign is established in the United States. Depending on the data centre location, Personal Data is stored in the United States or within the European Union. For accounts where data is stored in European data centres, information about the location of the storage of Personal Data is available in the MailBlue Hub. For the purposes of ongoing platform support, authorised ActiveCampaign staff may access your email marketing account and the servers on which it is hosted from various countries. To the extent that such access takes place from countries outside the EEA that do not benefit from an adequacy decision of the European Commission, appropriate safeguards have been put in place in the form of Standard Contractual Clauses (SCCs) as adopted by the European Commission and, to the extent the receiving party is qualified for it, the EU-US Data Privacy Framework (DPF). A current list of the Sub-processors engaged by MailBlue, including the location of data storage and the transfer mechanisms used, can be consulted at mailblue.io/legal/subprocessors/.

In all transfers, MailBlue shall comply with the rules of the GDPR (Chapter V) and the arrangements in this Data Processing Agreement.

Article 9 – Security of Personal Data

MailBlue shall ensure that the Personal Data is adequately secured. To prevent loss and unlawful processing, MailBlue shall take appropriate technical and organisational security measures. The measures taken include, among others:

  1. pseudonymisation and encryption of Personal Data;
  2. ensuring the ongoing availability and resilience of the processing systems;
  3. restoring the availability of the Personal Data in a timely manner in the event of an incident;
  4. establishing a procedure for assessing, testing and evaluating security measures.

MailBlue acts in accordance with the framework of the ISO 27001 standard. The current certificate is, where applicable, available at mailblue.io/legal/.

Article 10 – Audits

The Controller may have an audit carried out by a third party in order to determine whether the processing of the Personal Data complies with the law and the arrangements in this Data Processing Agreement. MailBlue shall cooperate with this, including by granting access to buildings and databases and making relevant information available. The following arrangements apply to the conduct of an audit:
  1. the audit shall be carried out after prior written notice to MailBlue. This notice shall be provided by the Controller in the form of an audit plan describing the scope, duration and start date of the audit;
  2. the audit plan shall be submitted to MailBlue at least 30 (thirty) days before the proposed audit date;
  3. an audit shall be carried out no more than once per year;
  4. the audit shall be carried out during MailBlue’s normal business hours;
  5. the audit shall be carried out in a manner that disrupts MailBlue’s operations as little as possible;
  6. all information provided by MailBlue during the audit shall be treated as confidential, and the parties shall sign a non-disclosure agreement prior to the audit;
  7. the costs of the audit, including the costs of the auditor and a reasonable fee for the time of MailBlue staff, shall be borne by the Controller.

Article 11 – Liability

  1. MailBlue’s liability as Processor towards the Controller for loss arising from an attributable failure in the performance of this Data Processing Agreement is limited to compensation of direct loss up to a maximum of the amount paid by the Controller to MailBlue in the subscription period immediately preceding the event giving rise to the loss. A series of related events shall be regarded as a single event.
  2. Liability for indirect loss, consequential loss, loss of profit, lost savings or loss due to business interruption is excluded in all cases.
  3. For loss resulting from intent or gross negligence on MailBlue’s part, the limitation in paragraph (a) applies in full, on the understanding that MailBlue shall in that case make a claim under its insurance. Where applicable, the Controller may claim the amount paid out by MailBlue’s insurance, to the extent that this exceeds the amount referred to in paragraph (a).
  4. MailBlue’s liability towards data subjects under Article 82 of the GDPR is not limited or excluded by this article to the extent that this is not permitted under mandatory law. If MailBlue is held liable by a data subject for loss for which the Controller is responsible, the Controller shall indemnify MailBlue for the share attributable to the Controller.

Article 12 – Final provisions

In the event that any provision of this Data Processing Agreement is null and void or voidable, this shall not affect the validity of the remainder of this Data Processing Agreement. In that case, the void provision shall be replaced by a provision that reflects the content of the void provision as closely as possible.

Deviations from and additions to this Data Processing Agreement shall apply only if agreed by both parties in writing.

This Data Processing Agreement and its performance are governed by Dutch law. Any disputes arising between the parties shall be submitted to the District Court of Zeeland-West-Brabant.

DISCLAIMER

MailBlue makes no undertaking or warranty whatsoever that this Data Processing Agreement provides a legally sufficient basis for compliance with the Controller’s obligations under the applicable legislation. MailBlue expressly disclaims all representations or warranties that the Data Processing Agreement will satisfy the Controller’s obligations, whether express, implied, statutory, arising under a trade treaty or otherwise. The Controller acknowledges that compliance with the GDPR is a shared responsibility and that MailBlue is responsible solely for the obligations it bears as Processor under the GDPR.