GDPR & data processing
Northbound operates infrastructure that transmits personal data on behalf of clients. This page summarises the data-protection posture that underlies every client engagement.
Last updated: 1 April 2026.
Role
Under the UK and EU GDPR, Northbound Mail Systems Limited acts as a data processor for personal data contained in client messages transmitted through our infrastructure. The client remains the data controller.
Data Processing Agreement
A Data Processing Agreement (DPA) is included with every executed engagement. The DPA covers: nature and purpose of processing; categories of data subject and personal data; retention; security measures; use of sub-processors; cross-border transfer mechanisms; data subject rights; audit rights; and breach notification.
Categories of personal data processed
- Message envelope data (sender, recipient, message-id, timestamp).
- Message content in transit.
- Delivery-response metadata (SMTP responses, feedback loop reports, bounce diagnostics).
- Recipient engagement telemetry where the client operates open- or click-tracking through Northbound infrastructure.
Retention
Full message content is not retained after delivery unless the client instructs otherwise for a defined operational purpose. Envelope and delivery metadata are retained per the DPA, defaulting to 60 days hot and 12 months archived. Retention parameters are configurable per engagement.
Sub-processors
Northbound engages a limited set of sub-processors for infrastructure hosting, DNS, monitoring and finance. A current list is provided to clients on request and enumerated in the DPA. Sub-processor changes are notified with 30 days advance notice; the client may object to a proposed sub-processor and, if the objection cannot be resolved, terminate the affected services without penalty.
International transfers
Where personal data is transferred across borders in the course of providing the service, the transfer is covered by Standard Contractual Clauses (2021), the UK International Data Transfer Addendum, or the applicable adequacy decision. A Transfer Impact Assessment is available on request.
Data subject rights
Requests from data subjects should in the first instance be directed to the client (data controller). Where a request reaches Northbound directly, we route it to the applicable controller within one business day and cooperate with the response in accordance with the DPA.
Breach notification
Northbound will notify the affected client of any personal data breach without undue delay, and in any event within 24 hours of confirmation. Notifications include the nature of the breach, affected data categories, likely consequences, and remedial measures taken or proposed.
Security posture
A written security posture document is available to clients under NDA. It covers physical security, network security, host hardening, key management, access control, logging, incident response and personnel security.
Contact
Data protection enquiries: legal@northboundmail.net.