
Mailkit
Partially CompliantLong-running Czech email marketing and automation platform from Prague, with Article 28 processor terms written into its own contract rather than a separate DPA.

GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | Czech Republic |
| Ownership | European-owned |
| Foreign Disclosure Exposure | Not yet verified |
| Data Hosting Location | Unknown |
| EU Servers Available | |
| Data Processing Agreement | View DPA |
| Sub-processor List | Not verified |
| Schrems II Risk | Unknown |
| SCCs in Place | |
| Last Verified | 1 September 2026 |
How we reached this
Czech legal entity: Mailkit s.r.o., Prague 8, from the contact page read 2026-09-01. dpaEvidence is PUBLISHED, and unusually so: rather than a separate document, the Article 28 processor terms are written into the published conditions at mailkit.com/about-us/privacy-policy, read in full on 2026-09-01. The text establishes the controller-processor relationship ("the Provider, acting as a processor, performs processing of personal data for the User, acting as a controller, according to the instructions of the User"), covers processing on documented instructions including third-country transfers, and covers erasure or return of all personal data plus deletion of copies on termination. It also places controller obligations on the customer with an indemnity, which is what a real Article 28 arrangement looks like rather than a compliance page. Still PARTIAL because the operational facts are absent: no hosting country is named (the security section mentions "servers with personal data locked in the server room", implying controlled infrastructure but not saying where), no sub-processor list is published, and no transfer mechanism is stated. Google reCAPTCHA runs on the site.
About Mailkit
An Old Hand at Deliverability
Mailkit has been sending email for longer than most platforms in this directory have existed, and the product reflects that: the emphasis is on delivery engineering and support rather than on the newest editor.
The Contract Detail That Stands Out
Most vendors this size handle Article 28 badly. They either publish nothing, or they say a DPA is "available on request" and leave you chasing it through sales.
Mailkit does something better and less common: the processor terms are written directly into its published conditions. The text states that "the Provider, acting as a processor, performs processing of personal data for the User, acting as a controller, according to the instructions of the User", and then works through the Article 28 obligations properly — processing only on documented instructions including for third-country transfers, erasure or return of all personal data on termination along with deletion of copies, and the allocation of liability if the customer's own controller obligations are not met.
It also does the thing that separates a real agreement from a compliance page: it puts obligations on you. The customer warrants that it has informed data subjects, enables them to exercise their rights, and indemnifies Mailkit for damage caused by failing to do so. That is what an actual Article 28 arrangement looks like, and it is a reasonable reason to rate this above vendors with glossier privacy pages and nothing behind them.
What Is Not Published
The physical security description mentions "servers with personal data locked in the server room", which implies infrastructure the company controls, but no country is named for it. There is no published sub-processor list. Google reCAPTCHA runs on the site.
So the listing reads PARTIAL: the legal instrument is genuinely there and genuinely readable, but the operational facts this site also rates on, where the data physically sits and who else touches it, are not stated.
Czech, and Independent
Published by Mailkit s.r.o., Prague 8, with no parent company disclosed.
Where It Fits
Against Ecomail and SmartEmailing, Mailkit is the option that has been doing this longest and has the clearest processor terms; the other two are better documented on pricing. See email marketing.
Key Features
Pros & Cons
Categories
Mailkit GDPR & data protection: common questions
Is Mailkit GDPR compliant?
Partly. Mailkit meets some of the requirements, with caveats worth reading before you commit. Mailkit is a European company headquartered in Czech Republic, and a Data Processing Agreement is published.
Where does Mailkit store data?
We could not locate a clear statement of where Mailkit hosts data. Ask the vendor directly, or check their privacy policy and sub-processor list before signing.
Does Mailkit offer a Data Processing Agreement (DPA)?
Yes. Mailkit publishes a DPA at https://www.mailkit.com/about-us/privacy-policy. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.
What a DPA has to cover →Is Mailkit a European company?
Yes. Mailkit is headquartered in Czech Republic and, as far as we can establish, European-owned.
Related Tools

Brevo
All-in-one marketing platform with email, SMS, CRM, and automation. French company, EU data hosting.

MailerLite
Email marketing and automation platform from Lithuania. EU data processing.

rapidmail
German email marketing with data exclusively hosted in Germany.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at Mailkit and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.