Back to Tools
Folderly logo

Folderly

Partially Compliant

Email deliverability platform that audits, fixes and monitors inbox placement, operated by Folderly Inc. of Dover, Delaware, despite being widely described as Ukrainian.

πŸ‡ΊπŸ‡ΈUnited StatesNon-EU Β· United States

Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.

Paid
Folderly website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryUnited States
OwnershipNon-European
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
Unknown
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
High Risk
SCCs in Place
Last Verified1 September 2026

How we reached this

Listed as United States, not Ukraine. The source map places Folderly under Ukraine, which reflects a real origin story: the company grew out of Belkins, the Ukrainian-founded agency, and much of the team is there. The registration is American. From folderly.com/compliance/privacy-policy read 2026-09-01: "Company... refers to Folderly Inc., 8 The Green Suite #10781, Dover, DE 19901, United States" and "Country refers to Delaware, United States". 8 The Green in Dover is a well-known registered-agent address. The entity a customer contracts with, and that a US court can compel, is American, so ownershipOrigin is NON_EU and exposure US_CLOUD_ACT. Schrems II risk HIGH: the policy states that data "is processed at the Company's operating offices and in any other places where the parties involved in the processing are located" and "may be transferred to and maintained on computers located outside of Your state, province, country or other governmental jurisdiction", and for EEA residents that "in certain cases, we may transfer your data outside the EEA to provide our services" with safeguards described only in general terms and no named transfer mechanism. The policy is drafted against the CCPA alongside GDPR. No hosting region is stated, no sub-processor list and no DPA were located at a public URL. This carries more weight than it would for a lower-touch tool: a deliverability platform connects to the customer's sending domains and mailboxes and observes their mail flow.

About Folderly

Deliverability as an Ongoing Programme

Folderly's proposition is that inbox placement is not a setting you fix once. It runs continuous placement testing against seed accounts, monitors spam folder placement in real time, alerts through email, Slack and SMS when something changes, and works through the causes: authentication records, domain and IP reputation, content triggers, and sending patterns.

For a team whose pipeline depends on cold outbound, that is a real category of spend, and Folderly is one of the better-known names in it.

On the Country

The source map lists Folderly under Ukraine, and that reflects a real story: the company grew out of Belkins, the Ukrainian-founded agency, and much of the team is there.

The registration is not. From folderly.com/compliance/privacy-policy:

Company (referred to as "the Company", "We", "Us" or "Our") refers to Folderly Inc., 8 The Green Suite #10781, Dover, DE 19901, United States.

Country refers to Delaware, United States.

That is a Delaware corporation, and 8 The Green in Dover is one of the best-known registered-agent addresses in the state. So this directory lists Folderly as United States. The Ukrainian engineering heritage is real and worth knowing; the entity you would contract with, and that a US court could compel, is American.

The Data Position

The privacy policy commits to no EU hosting and states the opposite of a data residency guarantee:

Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to and maintained on computers located outside of Your state, province, country or other governmental jurisdiction.

For EEA residents it adds that "in certain cases, we may transfer your data outside the EEA to provide our services", with technical and organisational safeguards but no named transfer mechanism. The policy is written against the CCPA as well as GDPR, which tells you where the centre of gravity is.

No hosting region is stated, and no sub-processor list or DPA was located at a public URL.

This matters more than it would for a template builder. A deliverability platform is connected to your sending domains and mailboxes and sees your mail flow.

Where It Fits

If you want this function with the data in Europe, Re:Shark states EU-only processing, Bouncer's Deliverability Kit covers placement testing on EU-stored data, and DMARC Advisor covers the authentication side from the Netherlands. See email deliverability.

Key Features

Full email deliverability audit across domain and mailbox health
Continuous spam placement monitoring
Alerts by email, Slack and SMS
SPF, DKIM and DMARC authentication diagnosis and fixes
Content and subject line spam-trigger analysis
Domain and IP reputation monitoring
Inbox placement testing against seed accounts
Mailbox warm-up and recovery programmes

Pros & Cons

Treats deliverability as continuous monitoring rather than a one-off audit
Alerting through Slack and SMS, not just a dashboard you have to remember to open
Diagnoses causes across authentication, reputation and content rather than only reporting symptoms
Well-established name with a track record in cold outbound
Publishes a clear, readable privacy policy even though what it says is unfavourable here
Folderly Inc. is a Delaware corporation, not a Ukrainian or European company
States that data may be transferred outside the EEA, with no named transfer mechanism
No hosting region published anywhere
No sub-processor list or DPA located at a public URL
Connects to your sending domains and mailboxes, so the exposure is your live mail flow

Folderly GDPR & data protection: common questions

Is Folderly GDPR compliant?

Partly. Folderly meets some of the requirements, with caveats worth reading before you commit. Folderly is based in United States, outside the EU/EEA.

Where does Folderly store data?

We could not locate a clear statement of where Folderly hosts data. Ask the vendor directly, or check their privacy policy and sub-processor list before signing.

Does Folderly offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Folderly. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover β†’

Is Folderly a European company?

No. Folderly is based in United States, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.

Is Folderly subject to the US CLOUD Act?

Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.

Schrems II compliance checklist β†’

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Folderly and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.