Skip to content
FlackEmail

LEGAL

GDPR Compliance

How FlackEmail meets EU data protection law.

Last updated May 24, 2026.

Our role: controller vs. processor

Under GDPR, FlackEmail wears two hats.

For data we collect about you as a customer (your name, login, billing) we are the data controller. Our Privacy Policy covers that processing.

For the subscriber data you upload and the email content you ask us to send, you are the controller and we are the processor. Our Data Processing Addendum (DPA) covers that processing. The DPA is automatically part of your contract with us.

Lawful bases for processing

When we act as controller, we rely on the bases in Article 6 GDPR: contract (to deliver the service), legitimate interests (to run, secure, and improve it), and consent (where we ask for it specifically).

When we act as processor on your behalf, the lawful basis for the processing is yours to establish with your subscribers. FlackEmail does not contact your subscribers for our own purposes.

Data subject rights and how to exercise them

If you are a FlackEmail customer in the EU, UK, or another comparable jurisdiction, you have the right to access, correct, delete, restrict, or object to processing of your personal data, and to receive a portable copy.

Most requests can be made from your account settings. For anything else, email hi@flackemail.com. We respond within 30 days.

If you are a subscriber on one of our customer's lists, please reach the customer first; they control your data. We will route requests to them and help where we can.

Data Protection Officer

Given the scale and nature of our processing, we are not required to appoint a formal Data Protection Officer under Article 37 GDPR.

Privacy questions are handled directly by the founder and reach a real person at hi@flackemail.com.

International transfers and safeguards

We are based in Germany. Some of our subprocessors are in the United States or other countries outside the EEA.

Where personal data leaves the EEA we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where appropriate, additional safeguards such as encryption in transit and at rest and access controls. Our subprocessor list shows where each provider operates.

Breach notification commitment

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware, in line with Article 33 GDPR.

The notice will tell you what happened, the data and people involved as far as we know, the likely consequences, and the steps we are taking. It will be sent to the security or admin contact on your account.

Records of processing

We maintain records of processing activities (ROPA) as required by Article 30 GDPR, both as a controller and as a processor.

These records are internal but available to supervisory authorities and to customers on reasonable request under the DPA.

Complaint route

If you believe we have mishandled your data, please email hi@flackemail.com first; we would rather fix the issue directly.

You also have the right to complain to your local data protection supervisory authority. In Germany the lead authority for us is the Berliner Beauftragte fuer Datenschutz und Informationsfreiheit.