Hosted in France

A GDPR compliant email API,
hosted in Europe

All Maillog data lives in France, nothing is transferred to third countries, and a data processing agreement is available. Email delivery over the API is GDPR compliant by default.

Free tier: 100 emails/day · Upgrade only when you grow

GDPR compliance without the fine print

No opt-in for EU storage, no transfer mechanisms to arrange: at Maillog it's the default.

Data storage in France

Servers, databases, and backups run in French data centers. Email content, logs, and metadata stay inside the EU.

No third-country transfers

Maillog is Dutch and hosted in the EU. You don't need standard contractual clauses or other transfer mechanisms.

Data processing agreement available

Maillog acts as a processor. A DPA is available for you to sign as the data controller.

TLS encryption in transit

Email is sent and received encrypted over TLS. With the MTA-STS add-on you enforce TLS on inbound delivery too.

What does the GDPR ask of email delivery?

Three obligations apply to every email containing personal data.

A lawful basis for processing

Every email address is personal data. You may only send email with a valid lawful basis: a contract (order confirmation), a legal obligation, a legitimate interest, or consent. Transactional email usually rests on the contract with your customer; newsletters on consent.

Appropriate security

The GDPR requires appropriate technical and organisational measures. For email that means at least encryption in transit (TLS), sound key management, and an assessment of whether the content is sensitive enough for extra measures such as end-to-end encryption or a secure portal.

Agreements with your processors

When a third party sends email on your behalf, that party is a processor and you must sign a data processing agreement. If that processor handles data outside the EU, additional transfer rules apply. With a European provider like Maillog, the latter stays out of scope.

How email delivery works technically is on the email API page.

Extra security as add-ons

Not included in any plan. Add them per team, pay per use or a fixed monthly fee.

Secure Portal

€0,25 per message

or €19/month

The recipient reads the content in a secure portal; nothing sensitive travels over regular email.

E2E Encryption

€0,10 per encrypted email

or €15/month

End-to-end encryption for emails whose content must never be readable in transit.

MTA-STS

€9/month

per domain

Enforce TLS for inbound email on your domain and receive reports on failed connections.

Simple, predictable pricing

Free

€0/month

100/day

  • 1 domain
  • 7-day logs
  • Basic analytics
  • Community support
Start free
MOST POPULAR

Pro

€29/month

50k/month

  • 5 domains
  • 30-day logs
  • Advanced analytics
  • Webhooks
  • Email support
Start 14-day trial

Business

€99/month

500k/month

  • Unlimited domains
  • 90-day retention
  • Dedicated IP
  • SLA
  • Priority support
Contact sales

Frequently asked questions

Where is my data hosted?
All Maillog infrastructure — servers, databases, and backups — is located in France. Email content, logs, and metadata never leave the European Union.
Can I sign a data processing agreement (DPA) with Maillog?
Yes. Maillog acts as a processor for the personal data you send through the platform. A data processing agreement is available for you to sign as the controller.
How does Maillog compare to US providers like Mailgun or SendGrid?
With US providers, your data falls under US legislation even when stored in the EU. Maillog is Dutch, hosts in France, and performs no third-country transfers — so you don't need transfer mechanisms such as standard contractual clauses.
What does the MTA-STS add-on do for GDPR compliance?
MTA-STS forces other mail servers to deliver your email only over an encrypted TLS connection. It prevents email from being sent unencrypted or intercepted in transit — a concrete part of the security the GDPR requires.
When do I need E2E encryption?
TLS protects email in transit between servers, but the content is readable on every intermediate server. If you send medical, legal, or financial data, end-to-end encryption — or the Secure Portal, where the content never travels by email at all — is the appropriate extra measure.

Ready for GDPR compliant email delivery?

Start free with email that stays in Europe by default. Sign the DPA when you grow.