Who is who
Self-hosted. You deploy MailySend into your own Cloudflare account. Personal data in contacts, messages, events and attachments is created and stored there and reaches no system we operate. You are the controller (or your customer's processor, if you send on their behalf); Cloudflare is your processor under Cloudflare's own DPA. We are not a processor at all, because we process nothing. This document is then a template for the agreement you give your customers.
Hosted. If you use the hosted offering, [legal entity] is your processor for the personal data your instance holds, and the terms below apply between us.
What is processed
- Categories of data: email addresses, names and any contact properties you define; message headers, subjects and bodies; attachments; delivery, bounce, complaint, open and click events; IP addresses and user agents attached to those events.
- Categories of subject: your recipients, your contacts, and the members of your own team who use the dashboard.
- Purpose and duration: sending, receiving and reporting on the mail you instruct the software to handle, for as long as your retention configuration keeps it.
Processing happens only on your documented instructions — an API call, a dashboard action or a scheduled automation you configured. There is no secondary use: no profiling, no training on your message content, no resale.
Sub-processors
- Cloudflare, Inc. — compute and storage for every deployment (Workers, Email Sending and Routing, Queues, Durable Objects, D1, KV, R2, Workflows, Analytics Engine).
- Any provider you configure — Amazon Web Services (SES) or Resend, if you route sending through them. You choose these; adding one adds a sub-processor to your own list.
- For the hosted offering only: [hosted sub-processor list]. We give notice before a new one is added, and you may object.
International transfers
Cloudflare runs the network, so transfers follow Cloudflare's arrangements — Standard Contractual Clauses and its Data Localisation Suite. You pick the jurisdiction for Durable Objects and R2 buckets at deploy time, which is the practical lever: if your data must stay in one region, set it there rather than relying on a promise. Where the hosted offering transfers data out of the EEA or UK, it does so under the SCCs with [transfer mechanism reference].
Security measures
- TLS in transit and encryption at rest for every Cloudflare storage primitive used.
- Dashboard access behind Cloudflare Access, supporting SSO, MFA and device posture. API keys are scoped, stored hashed, and revocable.
- Least privilege by construction: the Worker's bindings are the only credentials, and there is no standing human access to a self-hosted deployment — including ours.
- Audit logging of dashboard, API and agent actions, with the actor attributed.
- Vulnerabilities reported through the repository's security policy are fixed in a patch release with an advisory.
Breach notification
For the hosted offering we notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach, with what we know about its nature, likely consequences and remediation. For a self-hosted deployment we cannot detect a breach — you hold the logs and the alerts — so that duty is yours, and a vulnerability in the software itself is disclosed publicly through the advisory process.
Data-subject requests and assistance
MailySend ships the mechanics rather than a ticket queue: deleting a contact cascades through D1, KV suppressions, R2 attachments and the event stream, and every contact, message and event is exportable through the API. For the hosted offering we assist you with access, rectification, erasure, portability, DPIAs and prior consultation, taking into account the nature of the processing.
Audit
The strongest audit right available here is the source: the whole platform is MIT-licensed and readable before you run it. For the hosted offering we make available the information needed to demonstrate compliance and will accept a reasonable audit, no more than once a year, at your cost. Cloudflare's own certifications cover the underlying infrastructure.
Deletion and return on termination
Self-hosted, termination is a decision you make about your own account: export everything to R2 and delete the Worker, and the data goes with it. For the hosted offering we delete or return your personal data within 30 days of termination at your choice, except where law requires us to keep it, and delete existing copies at the end of that period.
Contact
Data protection questions go to [privacy contact address]. There is no appointed [DPO name, if required] stated in this template — an operator publishing it must decide whether one is required for them.