Legal

Data processing

What personal data we process on your behalf, where it lives, how long we keep it, and who else touches it.

Last updated 18 September 2026

Processing on your instructions

The service processes sender and recipient addresses, message content, attachments, delivery events and suppression data to send and receive your email. This page describes the implementation; it is not an executed data processing agreement.

Storage and retention

Message metadata and stored bodies support the sent and inbox interfaces. Incoming raw messages and attachments remain in the receiving archive. Mailbox retention settings and archive lifecycle policies must both be configured; changing one does not automatically prove deletion from the other.

Deleting an organization removes its application data. DNS records, provider sender registrations and raw archive objects may require separate cleanup under the deployment's retention policy.

Processors and locations

SMTP2GO processes outbound email. The existing Amazon Web Services receiving pipeline handles inbound mail. Application hosting, provider account settings and archive regions determine data location; request the deployment-specific details for contractual review.

Export and access

Authenticated API clients can retrieve message history, stored content and incoming attachments within their organization and scope. Keep API keys on trusted servers and revoke them when an integration ends.

Contractual requirements

Contact security@mycompany.email to discuss a signed agreement, retention requirements and applicable subprocessors before sending data that depends on those commitments.

Questions a page cannot answer go to security@mycompany.email. There is no sales team in front of it.