Last updated: 28 May 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Code Cutter Limited, a company registered in England and Wales (company number 08453060) with registered office at Unit 96 The Maltings Business Centre, Stanstead Abbotts, Ware, Herts, SG12 8HG, trading as Mailbuttons (the "Processor," "we," "our," or "us"), and you (the "Controller," "you," or "your"). It governs the processing of personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation, the EU General Data Protection Regulation, and the UK Data Protection Act 2018.
The Processor implements security controls aligned with the ISO/IEC 27001:2022 control framework. The Processor's policies have been authored to this framework; the formal certification audit commences on the first paid Business contract — see the Trust Center for current compliance status.
"Controller" means the natural or legal person who determines the purposes and means of processing personal data.
"Processor" means Code Cutter Limited (trading as Mailbuttons), which processes personal data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on personal data, including collection, storage, use, and deletion.
"Data Subject" means the natural person whose personal data is being processed.
"Sub-processor" means any third party engaged by the Processor to assist in processing personal data.
The Processor may process the following categories of personal data on behalf of the Controller:
The Processor will process personal data for the following purposes:
The Processor shall:
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
The Processor shall assist the Controller in fulfilling data subject rights requests, including:
The Controller provides general authorization for the Processor to engage sub-processors, provided that:
The Processor currently engages the following sub-processors. This list mirrors the canonical sub-processor list maintained at /trust. If the two surfaces diverge, the Trust Center is authoritative.
| Sub-processor | Purpose | Region |
|---|---|---|
| Stripe Payments UK Ltd | Payment card processing | UK / EU |
| Stalwart Labs | Email server software (operated by us) | UK |
| Fasthosts Internet Ltd | VPS hosting (UK data centres) | UK |
| Cloudflare, Inc. | DNS and edge protection | Global; UK Addendum / SCCs |
| Anthropic, PBC | LLM inference for hosted agents (opt-in) | US; UK Addendum / SCCs |
| Backblaze, Inc. | Encrypted off-site backup (client-side encryption) | EU Central (Amsterdam); UK Addendum / SCCs |
Customer data, including email content and the audit logs derived from it, is stored within the United Kingdom and the European Economic Area. Where a sub-processor located outside the UK / EEA is engaged (notably Cloudflare for DNS and edge protection, and Anthropic for opt-in LLM inference), the Processor may transfer personal data to that sub-processor subject to appropriate safeguards, including:
In the event of a personal data breach, the Processor shall:
The Processor shall:
The Processor shall:
Each party shall be liable for any damages caused by its breach of this DPA. The Processor's liability for data protection violations shall be limited to direct damages, excluding indirect, consequential, or punitive damages.
The Controller shall indemnify the Processor against any claims arising from the Controller's violation of applicable data protection laws or breach of this DPA.
This DPA shall remain in effect for as long as the Processor processes personal data on behalf of the Controller. Upon termination:
This DPA is governed by and construed in accordance with the laws of England and Wales. Any disputes arising from this DPA are subject to the exclusive jurisdiction of the courts of England and Wales.
For any questions regarding this Data Processing Agreement, please contact us:
Data Protection Officer: dpo@mailbuttons.com
Legal Team: legal@mailbuttons.com
Privacy Inquiries: privacy@mailbuttons.com
Postal address: Code Cutter Limited (trading as Mailbuttons), Unit 96 The Maltings Business Centre, Stanstead Abbotts, Ware, Herts, SG12 8HG, United Kingdom