Data Processing Agreement
Last updated 16 August 2026
What this is
This Data Processing Agreement (DPA) explains how Dalysie AS(“Mailhuset”) processes personal data on your behalf when you send and receive email through the service. It forms part of our Terms of Service and applies where the GDPR or similar data-protection law governs your use of Mailhuset. For this data, you are the controller and Mailhuset is your processor.
What we process and why
We process the personal data contained in the email you send and receive, and the related contacts and logs, for one purpose: to provide the Mailhuset service on your instructions, which means accepting, delivering, receiving and tracking your email and giving you the dashboard and API to manage it. We process it for as long as you use the service and until deletion as described below.
Whose data, and what kind
The data subjects are the people you choose to send to or receive from, such as your users, customers and contacts. The personal data is whatever you include in your email and contacts, which typically means:
- email addresses and names of senders and recipients;
- the subject and, for stored message types, the content of messages;
- contact list fields you add, and inbound message bodies and attachments;
- delivery metadata such as timestamps, status and bounce or complaint reasons.
You decide what to put in your email, so you control which categories of data are involved. You should not send special-category data unless you have a lawful basis and appropriate safeguards.
We act on your instructions
We process this personal data only on your documented instructions, which are given through your configuration and use of the service and this DPA, unless the law requires otherwise (in which case we will tell you, where allowed). We will not use your email data for our own purposes, and we do not sell it or use it for advertising.
Confidentiality
The people who process your data for us are bound by confidentiality and only get the access they need to do their job.
Security
We keep appropriate technical and organisational measures to protect your data, taking into account the risk. These include encryption in transit (HTTPS and TLS) and at rest for stored content, hashing of passwords and API keys, two-factor authentication, keyless federated access to our cloud backends, least-privilege access controls, and isolation of each account’s data. We review and improve these measures over time.
Sub-processors
You give us general authorisation to use the sub-processors below to help provide the service. We put appropriate data-protection terms in place with each of them, and we remain responsible for their processing. The authoritative, always-current list lives on our sub-processors page; if we add or replace a sub-processor we update it there and, where we can, give you notice so you can object on reasonable data-protection grounds.
Amazon Web Services (Amazon SES and Amazon S3)
Delivering the email you send, receiving inbound email, and storing inbound message content and attachments.
Location: European Union: Stockholm (sending) and Ireland (inbound storage). AWS is a US company.
Microsoft Azure
Hosting and running the service, including the database that holds message logs, contacts and inbound content.
Location: European Union: Sweden.
Our payment providers (Polar and Paystack) process your own billing details, not your recipients’ data, so they are covered by our Privacy Policy rather than this list.
International transfers
Your email data is processed in the European Union. One of our sub-processors, Amazon Web Services, is a US company, so where personal data is transferred to it we rely on appropriate safeguards, such as the European Commission’s standard contractual clauses, to keep it protected.
Helping you meet your obligations
Taking into account the nature of the processing, we will help you respond to requests from data subjects (for example to access or delete their data), and support your data-protection impact assessments and security obligations, using the tools in the service and reasonable assistance on request. If a data subject contacts us directly, we will refer them to you.
Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and give you the information you reasonably need to meet your own notification duties.
Deletion and return
When you close your account, or on your request, we delete the personal data we hold for you, except where we are legally required to keep some of it. You can also delete much of your data yourself while your account is open, for example by removing contacts, templates and inbound messages.
Audits and information
On reasonable request, we will make available the information needed to show we meet these obligations, and support audits within a sensible scope and frequency, in a way that respects the security and confidentiality of our other customers.
Contact
Questions about this DPA, or need a signed copy for your records? Email us at support@mailhuset.com.