1. Parties and scope
This Data Processing Agreement ("DPA") forms part of, and is subject to, the MailStrike Terms of Service available at https://www.mailstrike.ai/terms (the "Agreement") between:
- IT Monks Sp. z o.o., ul. Dobrego Pasterza 19A/U4, 31-416 Kraków, Poland, KRS 0000765502 ("MailStrike", "we", "us", the "Processor"); and
- the customer that has entered into the Agreement (the "Customer", "you", the "Controller").
This DPA applies where, and to the extent that, MailStrike processes Personal Data on behalf of the Customer in connection with the MailStrike service (the "Service"), and the processing is subject to Regulation (EU) 2016/679 (the "GDPR") or the equivalent data-protection law of an EEA member state or the United Kingdom.
Where there is a conflict between this DPA and the Agreement on the subject of data protection, this DPA prevails.
2. Definitions
Terms such as "Personal Data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given to them in the GDPR. "Data Protection Law" means the GDPR and any applicable national data-protection law implementing or supplementing it.
3. Roles of the parties
The parties agree that, for the Personal Data processed under the Service, the Customer is the Controller and MailStrike is the Processor. Where the Customer is itself a processor acting on behalf of a third-party controller, MailStrike acts as a sub-processor, and the Customer warrants that it has the authority of that controller to engage MailStrike on these terms.
MailStrike processes Personal Data relating to its own account, billing, and security records (for example the identity and contact details of the Customer's account holders, and payment records) as an independent Controller. That processing is governed by the MailStrike Privacy Policy at https://www.mailstrike.ai/privacy, not by this DPA.
4. Subject matter and details of processing
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are set out in Annex 1.
5. Customer instructions
MailStrike processes Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to process it by Union or member-state law to which MailStrike is subject. In that case MailStrike will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
The Agreement, this DPA, and the Customer's use and configuration of the Service (including connecting a mailbox and setting warmup parameters) constitute the Customer's complete documented instructions. MailStrike will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
6. Customer responsibilities
The Customer warrants that:
- it has a valid legal basis under Article 6 GDPR (and, where relevant, has met the conditions of applicable ePrivacy and anti-spam law) for the processing it instructs MailStrike to carry out;
- it has provided all notices and obtained all consents required for MailStrike to process the Personal Data as instructed; and
- the mailboxes it connects, and the recipients it interacts with through the Service, comply with the Agreement and the Acceptable Use Policy.
7. Confidentiality
MailStrike ensures that persons authorised to process the Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and are made aware of the confidential nature of the Personal Data.
8. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, MailStrike implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2. MailStrike may update those measures over time, provided the level of protection is not materially reduced.
9. Sub-processing
The Customer grants MailStrike general authorisation to engage sub-processors to process Personal Data, subject to this section. The sub-processors engaged as at the effective date are listed in Annex 3.
MailStrike will impose on each sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
MailStrike will give the Customer prior notice of the addition or replacement of any sub-processor by email to the account owner, giving the Customer at least 30 days to object on reasonable data-protection grounds. If the Customer objects and the parties cannot agree a resolution, the Customer may terminate the affected part of the Service as its sole remedy.
10. Assistance to the Customer
Taking into account the nature of the processing, MailStrike will:
- assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection);
- assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the information available to MailStrike.
If MailStrike receives a request from a data subject relating to Personal Data processed on the Customer's behalf, it will, unless legally prohibited, direct the data subject to the Customer and promptly inform the Customer.
11. Personal data breach
MailStrike will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's Personal Data, and will provide the Customer with the information reasonably available to enable the Customer to meet its own notification obligations under Articles 33 and 34 GDPR.
12. Deletion or return of data
On termination of the Service, MailStrike will, at the Customer's choice, delete or return the Personal Data processed on the Customer's behalf, and delete existing copies, unless Union or member-state law requires storage of the Personal Data. In line with the Privacy Policy, Personal Data is deleted or anonymised within 30 days of account deletion, subject to any legal retention requirement.
13. Audits and information
MailStrike will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
To the extent permitted, the Customer will first accept relevant third-party audit reports, certifications, or a completed security questionnaire that MailStrike makes available. Any on-site audit will be limited to once per 12 months, on reasonable prior notice, during business hours, subject to confidentiality, and at the Customer's cost, except where a supervisory authority requires otherwise or following a personal data breach.
14. International transfers
Where processing under this DPA involves a transfer of Personal Data to a country outside the EEA that is not the subject of an adequacy decision, the transfer is carried out under an appropriate safeguard recognised by Data Protection Law, in particular the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this DPA by reference and completed as set out in Annex 3, together with any supplementary measures required. For transfers subject to UK law, the UK International Data Transfer Addendum applies.
Primary processing and backups take place in the EU (Germany). The only transfers outside the EEA are onward transfers by the Stripe, SendGrid and OpenAI sub-processors, each carried out under the SCCs, as set out in Annex 3.
15. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
16. Governing law and jurisdiction
This DPA is governed by the laws of Poland, and the parties submit to the exclusive jurisdiction of the courts competent for the registered seat of IT Monks Sp. z o.o. in Kraków, Poland, consistent with the Agreement.
Annex 1: Details of processing
Subject matter: provision of the MailStrike email deliverability and warmup Service to the Customer.
Duration: for the term of the Agreement, plus any period until deletion or return of Personal Data under section 12.
Nature and purpose of processing: connecting to the Customer's email mailbox(es) to send Service-generated warmup messages and to relabel and adjust the placement of those messages, in order to build and maintain the sending reputation of the Customer's mailbox and domain; recording engagement signals for those messages; and providing related reporting.
Types of Personal Data:
- account and identity data of the Customer's users (name, email address, company name);
- mailbox connection data (OAuth tokens for Google and Microsoft; IMAP/SMTP connection details and application passwords);
- content and metadata of Service-generated messages and their engagement signals (opens, replies, link clicks, spam-folder rescues, reputation scores);
- any Personal Data contained in inputs the Customer provides to the Service.
MailStrike does not store the existing contents of the Customer's mailbox.
Categories of data subjects:
- the Customer's authorised users and account administrators;
- the holders of the mailboxes connected to the Service;
- recipients of, and senders interacting with, Service-generated warmup messages.
Special categories of data: none intended. The Customer must not use the Service to process special-category data under Article 9 GDPR.
Retention:
| Data | Retention |
|---|---|
| Generated warmup email text | Removed 90 days after the conversation ends |
| Deliverability test messages written by the Customer | Subject and body removed 90 days after the test |
| Engagement and activity events | 13 months |
| Audit log (may contain account email addresses) | 2 years |
| Application logs | 14 days (warmup activity log: 30 days) |
| Mailbox credentials of a mailbox disconnected by the provider | Deleted after 30 days |
| Offsite backups | Up to 6 months |
When an account is terminated, its stored mailbox credentials are deleted immediately and all remaining account data is deleted 30 days later. Deleted data may persist in encrypted backups until those backups expire, at most 6 months.
Annex 2: Technical and organisational measures
Taking into account the state of the art and the risk to data subjects, MailStrike maintains the following measures.
Hosting and data location. All customer data is processed on a dedicated server (Hetzner) in Nuremberg, Germany (EU). The application, database and cache each run in their own isolated container. Encrypted backup copies are stored with a second provider (Wasabi) in Frankfurt, Germany (EU).
Encryption in transit. All access uses HTTPS with TLS 1.2 or 1.3; older versions are refused, certificates renew automatically, and plain HTTP is redirected to HTTPS. HTTP Strict Transport Security is enforced for one year including subdomains. Response headers prevent framing (clickjacking) and content-type sniffing. Session cookies are restricted to HTTPS, are not readable by page scripts, and are same-site. Connections to Google Workspace and Microsoft 365 mailboxes use their HTTPS APIs; other IMAP/SMTP mailboxes use TLS by default.
Encryption at rest. Mailbox access credentials (OAuth tokens and IMAP/SMTP passwords) are encrypted with AES-256 before storage, with the key held outside the source code. Two-factor authentication secrets and recovery codes are encrypted the same way. User passwords are stored only as one-way bcrypt hashes. Partner API keys and access tokens are stored only as one-way hashes. No payment card data is stored; only the Stripe customer reference and the last four digits of the card are kept. Backups are encrypted with AES-256 before they leave the server.
Mailbox access. MailStrike requests only the mailbox permissions the Service needs; if they are not granted, the connection is refused. When a customer disconnects or deletes a mailbox, its stored credentials are deleted, and for Google mailboxes MailStrike revokes its access at Google. Stored credentials are also deleted when an account is terminated, and 30 days after a mailbox is disconnected by the provider. MailStrike works on warmup messages it generates itself and does not store the contents of the customer's own mailbox; the only exception is deliverability test messages the customer writes in the application, which are removed after 90 days.
Administrator access. The administration panel requires a password and a time-based one-time code (TOTP) on every login, and only administrator-role accounts can reach it. Automated tests check that the two-factor step cannot be bypassed. An administrator can open a customer's account only through a single-use link that expires after 60 seconds, and each use is recorded in an audit log. Administrative changes to accounts, mailboxes, plans and personas are recorded in an audit log.
Customer account security. Passwords must be at least 12 characters with mixed case, numbers and symbols, and are checked against known breach corpora. Email addresses must be verified before an account can be used. Password reset links expire after 60 minutes. Login, registration and password reset are rate-limited. Forms are protected against cross-site request forgery. Each customer's data is scoped to their own account.
Environment separation. Changes are previewed in a staging environment that sits behind an additional network-edge password, is excluded from search engines, and has debug output switched off. Staging uses its own encryption key and so cannot decrypt production mailbox credentials or two-factor secrets.
Infrastructure security. A firewall blocks all incoming traffic except web traffic (HTTP/HTTPS) and SSH; the database and cache are not reachable from the internet. Server administration uses SSH keys, and password login for the administrator account is disabled. Operating-system security updates install automatically. Credentials are held in a dedicated secrets manager, written with owner-only file permissions and never stored in source code. Every code change runs automated tests, static analysis and a known-vulnerable-dependency check before deployment, and a deployment is blocked if the server configuration differs from the reviewed version. Automated monitoring runs every 10 minutes and alerts the engineering team; alerts contain no customer data. Log files are rotated and capped in size.
Backups and resilience. The database is backed up nightly and each backup is integrity-checked. Each backup is encrypted with AES-256 on the server before upload to the EU backup provider. Offsite copies are kept as 14 daily, 8 weekly and 6 monthly backups; local copies are kept 7 days and are readable only by the system administrator. The engineering team is alerted if a backup fails or if the latest offsite copy is more than 26 hours old. A full database restore was tested on 17 September 2026 and is re-verified after major changes.
Annex 3: Sub-processors
As at the effective date, MailStrike engages the following sub-processors to process Personal Data:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting and data processing | Germany (EU) | None required (processed in the EU) |
| Wasabi Technologies | Encrypted backup storage | Frankfurt, Germany (EU) | None required (stored in the EU) |
| Stripe Payments Europe, Ltd | Payment processing | Ireland (EEA); onward transfers to Stripe, LLC (USA) | EU SCCs (2021/914) for onward transfers |
| Twilio SendGrid | Transactional/service email (e.g. password resets) | USA | EU SCCs (2021/914) |
| OpenAI Ireland Ltd | Generating Service warmup message content | Ireland (EEA); onward transfers to OpenAI OpCo, LLC (USA) | EU SCCs (2021/914) for onward transfers |
Google and Microsoft are the mailbox providers the Customer connects at the Customer's own request, not MailStrike sub-processors, and are governed by the Customer's own terms with those providers.
OpenAI receives only sender and recipient names, company names, company description and industry, and no email addresses, for the purpose of generating warmup content. This is consistent with MailStrike's statement that connected-mailbox contents are not sent to third-party AI services.
Because primary processing and backups are in the EU (Germany), the only sub-processor transfers outside the EEA are onward transfers by Stripe, SendGrid and OpenAI, each covered by the EU Standard Contractual Clauses.
Customer support is handled over email only (hello@mailstrike.ai), so no separate support-tool sub-processor is engaged.