Back to Tools
Mailkit logo

Mailkit

Partially Compliant

Long-running Czech email marketing and automation platform from Prague, with Article 28 processor terms written into its own contract rather than a separate DPA.

🇨🇿Czech RepublicPaid
Mailkit website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryCzech Republic
OwnershipEuropean-owned
Foreign Disclosure ExposureNot yet verified
Data Hosting Location
Unknown
EU Servers Available
Data Processing AgreementView DPA
Sub-processor ListNot verified
Schrems II Risk
Unknown
SCCs in Place
Last Verified1 September 2026

How we reached this

Czech legal entity: Mailkit s.r.o., Prague 8, from the contact page read 2026-09-01. dpaEvidence is PUBLISHED, and unusually so: rather than a separate document, the Article 28 processor terms are written into the published conditions at mailkit.com/about-us/privacy-policy, read in full on 2026-09-01. The text establishes the controller-processor relationship ("the Provider, acting as a processor, performs processing of personal data for the User, acting as a controller, according to the instructions of the User"), covers processing on documented instructions including third-country transfers, and covers erasure or return of all personal data plus deletion of copies on termination. It also places controller obligations on the customer with an indemnity, which is what a real Article 28 arrangement looks like rather than a compliance page. Still PARTIAL because the operational facts are absent: no hosting country is named (the security section mentions "servers with personal data locked in the server room", implying controlled infrastructure but not saying where), no sub-processor list is published, and no transfer mechanism is stated. Google reCAPTCHA runs on the site.

About Mailkit

An Old Hand at Deliverability

Mailkit has been sending email for longer than most platforms in this directory have existed, and the product reflects that: the emphasis is on delivery engineering and support rather than on the newest editor.

The Contract Detail That Stands Out

Most vendors this size handle Article 28 badly. They either publish nothing, or they say a DPA is "available on request" and leave you chasing it through sales.

Mailkit does something better and less common: the processor terms are written directly into its published conditions. The text states that "the Provider, acting as a processor, performs processing of personal data for the User, acting as a controller, according to the instructions of the User", and then works through the Article 28 obligations properly — processing only on documented instructions including for third-country transfers, erasure or return of all personal data on termination along with deletion of copies, and the allocation of liability if the customer's own controller obligations are not met.

It also does the thing that separates a real agreement from a compliance page: it puts obligations on you. The customer warrants that it has informed data subjects, enables them to exercise their rights, and indemnifies Mailkit for damage caused by failing to do so. That is what an actual Article 28 arrangement looks like, and it is a reasonable reason to rate this above vendors with glossier privacy pages and nothing behind them.

What Is Not Published

The physical security description mentions "servers with personal data locked in the server room", which implies infrastructure the company controls, but no country is named for it. There is no published sub-processor list. Google reCAPTCHA runs on the site.

So the listing reads PARTIAL: the legal instrument is genuinely there and genuinely readable, but the operational facts this site also rates on, where the data physically sits and who else touches it, are not stated.

Czech, and Independent

Published by Mailkit s.r.o., Prague 8, with no parent company disclosed.

Where It Fits

Against Ecomail and SmartEmailing, Mailkit is the option that has been doing this longest and has the clearest processor terms; the other two are better documented on pricing. See email marketing.

Key Features

Campaign building and drag-and-drop editing
Marketing automation workflows
Transactional and marketing sending in one platform
Deliverability engineering and reputation management
Segmentation and list management
Reporting on delivery, opens and clicks
Article 28 processor terms written into the contract
Hands-on professional support

Pros & Cons

Article 28 processor terms are published in the contract, not held behind a sales request
The terms place real obligations on both sides, which is rare at this size
Long track record in deliverability rather than a recent entrant
Independent Czech company with no disclosed parent
Commits to erasing or returning all personal data and deleting copies on termination
No hosting country named anywhere in the published documents
No sub-processor list published
No public pricing, so evaluation starts with contact
No transfer mechanism stated for any third-country processing
Smaller ecosystem of integrations than Ecomail or the international platforms

Mailkit GDPR & data protection: common questions

Is Mailkit GDPR compliant?

Partly. Mailkit meets some of the requirements, with caveats worth reading before you commit. Mailkit is a European company headquartered in Czech Republic, and a Data Processing Agreement is published.

Where does Mailkit store data?

We could not locate a clear statement of where Mailkit hosts data. Ask the vendor directly, or check their privacy policy and sub-processor list before signing.

Does Mailkit offer a Data Processing Agreement (DPA)?

Yes. Mailkit publishes a DPA at https://www.mailkit.com/about-us/privacy-policy. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.

What a DPA has to cover →

Is Mailkit a European company?

Yes. Mailkit is headquartered in Czech Republic and, as far as we can establish, European-owned.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Mailkit and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.