This page is written for the person doing the vendor review, not the person signing up. It summarizes how EmailFig meets the GDPR and UK GDPR for EU and UK customers and their subscribers. For the fuller, plain-language description of what we collect and why, see our Privacy Policy.
Controller & processor roles
EmailFig is the controller for your own account and billing data: the data you give us as our customer. EmailFig is the processor for the subscriber data you upload or collect through our forms; you are the controller for that data, and we process it only on your documented instructions, as set out in our Terms of Service and the Data Processing Addendum below.
Legal basis
We process account and billing data under contract, and subscriber data as your processor under the same contract. The basis your own collection of that data relies on (typically consent or legitimate interest) is between you and your subscribers. We process a narrow set of data under legitimate interest for security and abuse prevention, and under legal obligation where record-keeping law requires it. The full breakdown is in the Privacy Policy's Legal basis for processing section.
Subprocessors
Every subprocessor we use, what it does, where it runs, and the safeguard that covers moving EU/UK personal data there:
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting, database, and email-sending infrastructure | United States (or the customer's own AWS region, for bring-your-own-AWS accounts) | EU-U.S. Data Privacy Framework |
| Stripe | Payment processing and billing | United States | EU-U.S. Data Privacy Framework |
| PostHog | Product analytics and error tracking for the app itself: never for recipient-facing pages (unsubscribe, preference center, hosted forms) | United States | Standard Contractual Clauses |
| Cloudflare | Bot and abuse protection on public signup forms | Global network | EU-U.S. Data Privacy Framework |
| Google (Google Analytics) | Traffic analytics for our marketing pages, blog, and help centre: pageviews and referrers, not account or subscriber data | United States | EU-U.S. Data Privacy Framework |
We'll update this table before adding or replacing a subprocessor, and email the address on your account with at least 10 days' notice first. If you want to confirm we have the right address, or ask a question before that notice arrives, write to contact@emailfig.com.
International transfers
EmailFig is based in Canada, and the subprocessors above run primarily in the United States. Where the GDPR or UK GDPR requires a safeguard for data leaving the EEA or UK, our subprocessors are each covered by their own certification under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), or, where a subprocessor isn't DPF-certified, by Standard Contractual Clauses, noted per subprocessor in the table above and incorporated into our Data Processing Addendum.
Data Processing Addendum
If your organization needs a signed Data Processing Addendum (covering the processor terms, subprocessor list, transfer safeguards, and security commitments in one document your legal team can countersign), write to contact@emailfig.com and we'll send one over, usually within a business day.
Data subject rights
EU and UK data subjects have the right to access, rectify, erase, restrict, or port their personal data, to object to processing, and to lodge a complaint with a supervisory authority. For your own account, exercise these directly in the app or by writing to us. For your subscribers, you're the controller of their data, so their requests should go to you first; the app gives you the tools to answer them (per-contact export, and a permanent erasure action distinct from a soft delete). If a subscriber contacts EmailFig directly, we'll redirect them to you and help you fulfill the request.
Breach notification
If we become aware of a personal data breach, we'll notify affected customers without undue delay so you can meet your own notification obligations as controller, and we'll notify the relevant supervisory authority ourselves where the law requires it of us directly.
Supervisory authority & contact
EmailFig doesn't currently have a formal Data Protection Officer or an appointed EU/UK representative. For a company our size, this isn't yet a legal requirement, and we'll update this page if that changes. For any GDPR-related question, request, or complaint, write to contact@emailfig.com; if you're an EU or UK resident, you also have the right to complain directly to your local supervisory authority at any time.