Privacy & Trust

GDPR Compliance &
Data Protection.

At OfniMail, privacy isn't a feature—it's the foundation of our architecture. We are fully committed to complying with the General Data Protection Regulation.

Our Responsibility

Controller vs. Processor

For the purposes of the GDPR, OfniMail acts as a Data Processor on behalf of our customers (the Data Controllers). We process data only according to the written instructions provided via our API and DPA.

  • Strict Sub-processor Vetting
  • Data Encryption at Rest (AES-256)
  • TLS 1.3 for Data in Transit
  • Regular Privacy Impact Assessments

Infrastructure

We use a limited number of third-party sub-processors to provide our services. Each has been audited for GDPR compliance.

Amazon Web Services (AWS)
Google Cloud Platform
Cloudflare
Stripe (Payments)

Upholding Individual Rights

We provide the tools necessary for our customers to fulfill data subject requests seamlessly through our API and Dashboard.

Right to Access

Know exactly what personal data we process and how it is used.

Right to Rectification

Request the correction of inaccurate or incomplete personal data.

Right to Erasure

Also known as the 'right to be forgotten'—request data deletion.

Data Portability

Request a copy of your data in a structured, machine-readable format.

Restrict Processing

Request that we limit the way we use your personal information.

Right to Object

Object to the processing of data for marketing or research purposes.

Data Processing Addendum (DPA)

We offer a standard DPA that incorporates the European Commission’s Standard Contractual Clauses (SCCs) to meet the adequacy and security requirements for our customers.

Privacy Officer

Directly contact our DPO for any compliance concerns.

privacy@ofnimail.com