Legal
Data processing
What personal data we process on your behalf, where it lives, how long we keep it, and who else touches it.
Last updated 18 September 2026
Processing on your instructions
The service processes sender and recipient addresses, message content, attachments, delivery events and suppression data to send and receive your email. This page describes the implementation; it is not an executed data processing agreement.
Storage and retention
Message metadata and stored bodies support the sent and inbox interfaces. Incoming raw messages and attachments remain in the receiving archive. Mailbox retention settings and archive lifecycle policies must both be configured; changing one does not automatically prove deletion from the other.
Deleting an organization removes its application data. DNS records, provider sender registrations and raw archive objects may require separate cleanup under the deployment's retention policy.
Processors and locations
SMTP2GO processes outbound email. The existing Amazon Web Services receiving pipeline handles inbound mail. Application hosting, provider account settings and archive regions determine data location; request the deployment-specific details for contractual review.
Export and access
Authenticated API clients can retrieve message history, stored content and incoming attachments within their organization and scope. Keep API keys on trusted servers and revoke them when an integration ends.
Contractual requirements
Contact security@mycompany.email to discuss a signed agreement, retention requirements and applicable subprocessors before sending data that depends on those commitments.