Aller au contenu
Vérifié indépendamment · Ré-audit trimestriel
EU VETTED

EmailOctopus

VéRIFIé
Marketing par e-mail · United Kingdom
Founded 2014 · emailoctopus.com ↗

London-based low-cost email marketing (Three Hearts Digital, 2014), generous free tier, indie-friendly, Amazon SES-backbone.

Pourquoi ce score ?

Three Hearts Digital Ltd (London, 86-90 Paul Street, EC2A 4NE) operates EmailOctopus as a low-cost subscriber-based email marketing service with a generous free tier — GDPR-compliant, indie-friendly, and competitively priced ($480/year at 100k subscribers); but UK post-Brexit jurisdiction + no public certifications (ISO 27001 / SOC 2) + hosting provider not disclosed (AWS likely at this low-cost scale, given EmailOctopus's historical relationship with Amazon SES as the underlying delivery backbone) — score 3/5 with material CLOUD Act exposure.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About EmailOctopus

EmailOctopus is the low-cost email-marketing service operated by **Three Hearts Digital Ltd** at 86-90 Paul Street, London EC2A 4NE, United Kingdom. The product targets indie creators, bloggers, small SMBs, and price-sensitive marketers who want a Mailchimp / MailerLite / ConvertKit alternative with a particularly generous free tier (free up to a meaningful subscriber count) and competitive paid pricing — for example approximately $480/year at 100,000 subscribers. The brand is well-known in the indie-hacker and content-creator community. For an EU-sovereignty audit the listing has structural caveats. The operating entity is UK-incorporated post-Brexit (UK adequacy decision under Art. 45 GDPR keeps transfers EU↔UK legally clean), but EmailOctopus historically built its product as a thin layer on top of **Amazon Simple Email Service (Amazon SES)** for the actual mail delivery — a US-owned hyperscaler dependency for the core product workload. No public ISO 27001 / SOC 2 certifications, no named sub-processors page, and the hosting region for application data is not publicly disclosed. The brand is GDPR-compliant per the homepage, but procurement-grade buyers needing detailed transfer documentation should request the DPA directly. Pricing in EUR / USD: free tier with no credit card required; paid tiers scale by subscriber count with monthly or annual billing (10% discount for annual). Best fit: indie creators, low-volume bloggers, small SMBs, and price-sensitive marketers who want a serviceable Mailchimp alternative and accept the UK + Amazon SES dependency. Procurement-grade EU buyers should choose CleverReach (DE) or rapidmail (DE) at SMB tier, or Maileon / Inxmail at enterprise.
SUB-PROCESSORS

Carte des sous-traitants · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Référentiels & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-11).
FEATURES

Matrice de fonctionnalités

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Tarifs & paliers

FREEMIUM
à partir de €0/mois
Voir la page tarifs ↗
PUBLIC DOCUMENTS

Documents publics

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives dans cette catégorie