Back to Tools
Maileon logo

Maileon

GDPR Compliant

German email marketing and automation platform from XQueue GmbH, ISO 27001 certified, running exclusively on German servers with no US infrastructure in the chain.

๐Ÿ‡ฉ๐Ÿ‡ชGermany๐Ÿ‡ช๐Ÿ‡บEU Hosted๐Ÿ‡ช๐Ÿ‡บ EuropeanPaid
Maileon website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountryGermany
OwnershipEuropean-owned
Foreign Disclosure ExposureNone known
Data Hosting Location
European Union"Data centres in the EU (Germany) ensure optimal data protection", "100% EU server locations", and "As a German company with German servers, Maileon offers you full security for your customer data... we guarantee a significantly higher level of security for personal data by exclusively using German servers" (maileon.com/security/, read 2026-09-01). The same page states ISO 27001 certification and describes data centres as meeting ISO 27001 and SOC 2 standards.
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Low Risk
SCCs in Place
Last Verified1 September 2026

How we reached this

German legal entity: XQueue GmbH, Christian-PleรŸ-Str. 11-13, 63069 Offenbach am Main, register court Offenbach am Main, HRB 12442, VAT DE 221794621, managing director Frank Strzyzewski, from the imprint read 2026-09-01. A second office is in Freiburg im Breisgau. The privacy policy confirms XQueue GmbH as controller under Art. 4(7) GDPR. COMPLIANT on the hosting position, which is stated four separate ways on maileon.com/security/ and is unqualified: German servers exclusively, 100% EU server locations, no US infrastructure claimed anywhere. The vendor cites the Schrems II ruling of 16 July 2020 by name as the reason. Exposure NONE and Schrems II risk LOW follow from that. ISO 27001 certified, data centres described as ISO 27001 and SOC 2, member of the Certified Sender Alliance (which materially helps inbox placement at German mailbox providers) and of eco. The gap: no sub-processor list was located and no standalone DPA document was found at a public URL. German B2B software conventionally handles Article 28 through an Auftragsverarbeitungsvertrag signed at contract stage rather than published, which is lawful but leaves dpaEvidence at NOT_LOCATED. Third parties named on the website itself are all EU-based: Zoho Corporation GmbH (Dรผsseldorf) for live chat with EU servers, heyData GmbH (Berlin) for the privacy seal.

About Maileon

German Servers, Said Plainly and Repeatedly

Plenty of vendors imply EU hosting. Maileon says it four different ways on the same page, which is why this listing rates as well as it does:

Data centres in the EU (Germany) ensure optimal data protection.

100% EU server locations

As a German company with German servers, Maileon offers you full security for your customer data... we guarantee a significantly higher level of security for personal data by exclusively using German servers.

The vendor also names the reason it is telling you this, citing the July 2020 Schrems II ruling directly and noting that "information about European consumers on US servers is not sufficiently protected from access by US authorities and intelligence services". That is an unusually specific argument for a marketing page, and it is the correct one.

The Certifications Are Real Ones

ISO 27001 certified, with data centres described as meeting ISO 27001 and SOC 2 standards. Member of the Certified Sender Alliance, the German whitelisting programme run with eco and the DDV, which matters practically: CSA membership improves inbox placement at German mailbox providers such as GMX and Web.de in a way no amount of warm-up will replicate. Also a member of eco, the German internet industry association.

For a buyer sending into the German market specifically, CSA membership is arguably a bigger deliverability lever than any feature in the product.

The Platform

Standard full-stack email marketing: campaign creation, drag-and-drop editing, segmentation, behavioural automation, transactional sending, reporting, and API access. Maileon is a mature product rather than a novel one, and the pitch is the infrastructure and the certifications rather than a feature nobody else has.

Pricing is not published; the pricing page routes to contact.

The Company

Published by XQueue GmbH, Christian-PleรŸ-Str. 11-13, 63069 Offenbach am Main, registered at the Offenbach am Main local court under HRB 12442, VAT DE 221794621, managing director Frank Strzyzewski, with a second office in Freiburg im Breisgau.

The one gap: no sub-processor list was located, and no standalone DPA document was found at a public URL. German B2B software normally handles Article 28 through an Auftragsverarbeitungsvertrag signed at contract stage rather than published, which is lawful, but it means the paper trail here is not as complete as the hosting statement is.

Where It Fits

Against CleverReach, rapidmail and Inxmail in the German market, Maileon is the one with the most explicit hosting position and ISO 27001. Compare in email marketing.

Key Features

Campaign creation with drag-and-drop editing
Behaviour-driven marketing automation
Segmentation and contact management
Transactional sending alongside marketing campaigns
Reporting and campaign analytics
API access for integration
Certified Sender Alliance membership for German inbox placement
ISO 27001 certified infrastructure

Pros & Cons

States German-only server locations without qualification, and cites Schrems II as the reason
ISO 27001 certified, with data centres meeting ISO 27001 and SOC 2
Certified Sender Alliance member, which materially helps delivery at GMX and Web.de
Even the website's own third parties are German: Zoho GmbH and heyData
Long-established German company with a published register entry
No published pricing at all
No sub-processor list located
No DPA at a public URL; Article 28 is presumably handled at contract stage
A mature rather than a distinctive product; the pitch is infrastructure, not features
German-market focus means less relevant if you never send into DACH

Maileon GDPR & data protection: common questions

Is Maileon GDPR compliant?

Yes. On the evidence we checked, Maileon meets the requirements European businesses usually need. Maileon is a European company headquartered in Germany, data is hosted within the European Union.

Where does Maileon store data?

Maileon states: ""Data centres in the EU (Germany) ensure optimal data protection", "100% EU server locations", and "As a German company with German servers, Maileon offers you full security for your customer data... we guarantee a significantly higher level of security for personal data by exclusively using German servers" (maileon.com/security/, read 2026-09-01). The same page states ISO 27001 certification and describes data centres as meeting ISO 27001 and SOC 2 standards.". Data is hosted within the European Union.

Does Maileon offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Maileon. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover โ†’

Is Maileon a European company?

Yes. Maileon is headquartered in Germany and, as far as we can establish, European-owned.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Maileon and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.