GDPR Policy
Last updated: June 25, 2026
This GDPR Policy explains how Miztrace complies with the EU General Data Protection Regulation (GDPR) and the UK GDPR, and the rights you have if you are in the European Economic Area, the United Kingdom, or Switzerland. It supplements our Privacy Policy.
1. Data controller and roles
For personal data about our account holders, Mizton ([Mizton mailing address — street, city, country]) is the controller. When you use Miztraceto send and track emails to your own recipients, you are the controller of your recipients’ data and Mizton acts as a processor on your behalf. You are responsible for having a lawful basis to contact and track those recipients.
If you require an EU/UK representative contact under Article 27, contact us at the address below. [If applicable, name your appointed EU/UK representative here.]
2. Legal bases for processing
We process personal data under the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you sign up for, including sending and tracking your emails.
- Legitimate interests (Art. 6(1)(f)) — to secure, maintain, and improve the Service and prevent abuse, balanced against your rights.
- Consent (Art. 6(1)(a)) — where required, for example for optional notification emails; you can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — to comply with our legal and tax obligations.
3. Your rights
Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase your data (“right to be forgotten”); restrict or object to processing; data portability; and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, email privacy@miztrace.com. We will respond within the timeframes the GDPR requires (generally within one month). You can also delete content and your account, and disconnect Gmail, directly in the dashboard.
4. Data we process
The categories of personal data we process — account details, Google profile and Gmail send permission, email tracking data (including IP address and user-agent of opens/clicks), content you create, and billing data — are described in our Privacy Policy.
5. Sub-processors
We use the following sub-processors to process personal data on our behalf. Each is bound by data-processing terms:
| Sub-processor | Purpose | Privacy policy |
|---|---|---|
| Google LLC | Google Sign-In and sending campaign emails via the Gmail API. | View |
| Convex, Inc. | Application hosting, database, and serverless backend. | View |
| Stripe, Inc. | Subscription billing and payment processing. | View |
| Resend (Plus Five Five, Inc.) | Sending transactional emails such as alerts and digests. | View |
6. International data transfers
Some of our sub-processors are located in the United States or other countries outside the EEA/UK. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or an adequacy decision.
7. Data processing agreement
If you are a business customer acting as a controller of your recipients’ data and require a Data Processing Agreement (DPA), contact us at privacy@miztrace.com.
8. Retention
We retain personal data only as long as necessary for the purposes described in our Privacy Policy, after which we delete or de-identify it, unless a longer period is required by law.
9. Contact us
For any GDPR-related request, contact us at privacy@miztrace.com.
Mizton, [Mizton mailing address — street, city, country].
This document is provided as a tailored template describing how Miztrace actually handles data. It is not legal advice; please have qualified counsel review it for your jurisdiction before relying on it.