When you use MailBlue’s services, you are the controller and MailBlue is the processor. Pursuant to Article 35 of the GDPR, it may be necessary to carry out a Data Protection Impact Assessment (DPIA) before you commence the processing. This page provides the information you need in order to carry out a DPIA in respect of the use of MailBlue’s services.
Do you have any further questions? Please contact our Privacy Officer at avg@mailblue.nl.
MailBlue B.V.
Akkerstraat 227
4811 JL Breda, the Netherlands
Chamber of Commerce (KvK) number: 68740077
MailBlue processes personal data exclusively on the instructions of the controller. The processing takes place for the purposes of the following services:
The personal data is processed exclusively on the basis of the controller’s instructions and not for MailBlue’s own purposes.
| Category | Explanation |
|---|---|
| Identification data | Name, email address |
| Contact details | Telephone number, address details |
| Behavioural data | Open and click behaviour in emails (where tracking is enabled) |
| Technical data | IP address (where open tracking or link tracking is enabled) |
| Other data | All other fields created by the controller itself within the system |
By default, MailBlue does not process special categories of personal data (such as health data, biometric data or criminal-offence data) unless the controller enters such data itself. In that case, the controller is itself responsible for the lawfulness of that processing.
| Situation | Retention period |
|---|---|
| During an active subscription | For the duration of the agreement |
| After termination of the subscription | The account is archived; data is deleted no later than 12 months after the expiry date |
| Reactivation possible | Within 6 months of the expiry date, for a minimum period of 1 month |
| Statutory retention obligation | Where applicable, only for the duration of that obligation |
| Situation | Retention period |
|---|---|
| During an active subscription | For the duration of the agreement |
| After termination of the subscription | The account is archived; data is deleted no later than 12 months after the expiry date |
| Reactivation possible | Within 6 months of the expiry date, for a minimum period of 1 month |
| Statutory retention obligation | Where applicable, only for the duration of that obligation |
MailBlue is certified in accordance with ISO 27001. The following measures apply:
Technical measures
Organisational measures
The current ISO 27001 certificate, where applicable, and the accompanying Statement of Applicability can be requested via avg@mailblue.nl.
MailBlue uses sub-processors in the performance of its services. A current and complete list of all sub-processors engaged, including their place of establishment and the nature of the processing, is available at mailblue.nl/legal/sub-verwerkers/.
Transfers outside the EEA – To the extent that personal data is transferred to parties outside the European Economic Area (EEA), this takes place exclusively on the basis of one of the following lawful transfer mechanisms:
The primary sub-processor for email marketing is ActiveCampaign (established in the US, DPF-certified). Depending on the data centre location, personal data is stored in the US or within the EU.
Access to personal data is limited to:
MailBlue supports the controller in handling requests from data subjects under the GDPR (access, rectification, erasure, restriction, data portability). MailBlue provides the required information within 5 business days of receipt of a request.
Requests may be submitted via avg@mailblue.nl.
The following elements are relevant to the risk assessment in your DPIA:
Risk factor | MailBlue’s assessment |
|---|---|
Large-scale processing | Possible, depending on usage |
Special categories of personal data | Not by default; depends on how the controller configures its account |
Profiling or automated decision-making | Possible via lead scoring and automations; the controller is itself responsible |
Transfers outside the EEA | Yes, see “Sub-processors and international transfers”; appropriate safeguards are in place |
Access by third parties | Limited to sub-processors bound by contractual obligations |
Data breach risk | Addressed by ISO 27001, the incident response process and the data breach procedure |
For additional information for the purposes of your DPIA, such as technical documentation, the Statement of Applicability or specific questions about the processing, please contact:
Privacy Officer, MailBlue B.V.
avg@mailblue.nl