
EmailOctopus
Partially CompliantLondon email marketing platform that stores contact lists in AWS Ireland and names its sending providers, at a price well under the mainstream alternatives.
Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.
Freemiumfrom $12/mo
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | United Kingdom |
| Ownership | Non-European |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | European Union"Your contact lists are stored in Ireland, within the European Economic Area ('EEA'), on the secure servers of Amazon Web Services ('AWS')... Our ESPs are SendGrid and SparkPost" and "The account details and IP address that we collect from you are stored on our AWS servers in Ireland, inside the UK and European Economic Area" (emailoctopus.com/legal/privacy, read 2026-09-01). |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | Medium Risk |
| SCCs in Place | |
| Last Verified | 1 September 2026 |
How we reached this
UK legal entity: Three Hearts Digital Ltd, 86-90 Paul Street, London EC2A 4NE, Companies House number 09897211, trading as EmailOctopus, named as data controller in the privacy policy read 2026-09-01. Hosting is EU: contact lists and account data sit in Ireland on AWS, which is more specific than most EU-headquartered vendors manage. Exposure is US_CLOUD_ACT for two separate reasons, both disclosed by the vendor. The storage provider is Amazon, a US company, and the sending providers are SendGrid (Twilio) and SparkPost (Bird), both American, and the policy states they have access to the customer's list during a send. Credit is due for saying so, and for offering EmailOctopus Connect, which routes sending through the customer's own AWS SES account and removes the third-party ESPs from the chain. Ownership is NON_EU because the UK is a third country under GDPR: transfers are lawful under the Commission's adequacy decision, but that decision is reviewable and the Investigatory Powers Act reaches data held by UK providers in a way no EU law does. Schrems II risk MEDIUM. The policy also notes that staff and service providers operating outside the UK and EEA may process the data. A processor and sub-processor list is referenced from the policy. No standalone DPA was located at a public URL. Stripe handles payments with no card data on EmailOctopus servers.
About EmailOctopus
Cheap, Simple, and Unusually Honest About the Plumbing
EmailOctopus made its name by being substantially cheaper than the mainstream platforms for straightforward newsletter sending. Paid plans start around $12/month, and there is a free tier for small lists.
The product is deliberately narrow: lists, forms, campaigns, basic automation, landing pages and reporting. If you want a customer data platform or e-commerce revenue attribution, this is not it, and it does not pretend to be.
Where Your List Actually Lives
The privacy policy is more specific than most:
Your contact lists are stored in Ireland, within the European Economic Area ("EEA"), on the secure servers of Amazon Web Services ("AWS"). Unless you are using our 'EmailOctopus Connect' service, they will also be available to our email service providers ("ESPs"). ESPs will only have access to your lists when you are sending an email. Once the email is sent, the ESPs no longer have access to your contact list. Our ESPs are SendGrid and SparkPost.
Read that carefully, because it contains the two facts that matter and most vendors will not give you either.
First, your list sits in Ireland, in the EEA, which is better than a lot of the EU-headquartered tools on this site can demonstrate.
Second, the actual sending goes through SendGrid (Twilio) and SparkPost (Bird), both American, and they see your list during a send. EmailOctopus tells you this, and tells you the access ends when the send does. It also offers EmailOctopus Connect, which routes sending through your own AWS SES account instead, removing the third-party ESPs from the chain entirely. If the US exposure is your concern, Connect is the answer and it exists precisely for that.
Payments run through Stripe, with no card data on EmailOctopus servers, and there is a published processor and sub-processor list.
The Company
Three Hearts Digital Ltd, 86-90 Paul Street, London EC2A 4NE, registered at Companies House under 09897211, trading as EmailOctopus.
Being a UK company means UK jurisdiction: the Investigatory Powers Act reaches data held by UK providers, and the EU adequacy decision covering transfers to the UK is a Commission decision that can be reviewed. Account data and IP addresses are stored on AWS servers in Ireland "inside the UK and European Economic Area", and staff and service providers outside the UK and EEA may process the data.
Where It Fits
Against MailerLite and Sender, which are EU-owned and comparably priced, and Mailrelay, which is free at volumes EmailOctopus charges for. EmailOctopus wins on transparency about the delivery chain; the others win on ownership. See email marketing.
Key Features
Pros & Cons
Categories
EmailOctopus GDPR & data protection: common questions
Is EmailOctopus GDPR compliant?
Partly. EmailOctopus meets some of the requirements, with caveats worth reading before you commit. EmailOctopus is based in United Kingdom, outside the EU/EEA, data is hosted within the European Union.
Where does EmailOctopus store data?
EmailOctopus states: ""Your contact lists are stored in Ireland, within the European Economic Area ('EEA'), on the secure servers of Amazon Web Services ('AWS')... Our ESPs are SendGrid and SparkPost" and "The account details and IP address that we collect from you are stored on our AWS servers in Ireland, inside the UK and European Economic Area" (emailoctopus.com/legal/privacy, read 2026-09-01).". Data is hosted within the European Union.
Does EmailOctopus offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for EmailOctopus. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover โIs EmailOctopus a European company?
No. EmailOctopus is based in United Kingdom, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.
Is EmailOctopus subject to the US CLOUD Act?
Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.
Schrems II compliance checklist โRelated Tools

Brevo
All-in-one marketing platform with email, SMS, CRM, and automation. French company, EU data hosting.

MailerLite
Email marketing and automation platform from Lithuania. EU data processing.

rapidmail
German email marketing with data exclusively hosted in Germany.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at EmailOctopus and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.