Aller au contenu
Vérifié indépendamment · Ré-audit trimestriel
EU VETTED

rapidmail

VéRIFIé
Marketing par e-mail · Germany
Founded 2008 · rapidmail.com ↗

Freiburg-based German email marketing tool hosting customer data exclusively in a Frankfurt ISO 27001 data centre, no public cloud.

Pourquoi ce score ?

Freiburg-based GmbH (Positive Group) hosting customer email data exclusively on a German data-centre campus in Frankfurt that holds ISO 27001 and PCI-DSS, with explicit avoidance of public hyperscaler clouds for customer data and SCC-protected US transfers limited to marketing-site analytics — minor CLOUD Act exposure earns 4/5.

SCORE
4.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About rapidmail

rapidmail is a Freiburg-headquartered German email marketing platform operated by rapidmail GmbH (Positive Group Deutschland GmbH, Amtsgericht Freiburg HRB 706983), founded in 2008. It positions itself as a fully GDPR-compliant ESP for SMBs in DACH and is one of the cleanest "Made in Germany" data-residency stories in the email-marketing category: customer email data and subscriber lists are hosted exclusively in a Frankfurt data centre that holds ISO 27001 and PCI-DSS certifications, and the company explicitly avoids public hyperscaler clouds (no AWS, no GCP, no Azure) for product workloads. The privacy policy (last updated May 2025) is transparent about marketing-site sub-processors — Google Analytics/Ads/reCAPTCHA, HubSpot, Hotjar, Mixpanel, LinkedIn Insight, Bing Ads, Matomo, Axeptio — but these touch the website and lead funnel rather than customer email data, and any US transfers are covered by Standard Contractual Clauses under Art. 46 GDPR. The data protection officer is Nils Möllers of Keyed GmbH, a German external DPO firm. Customer satisfaction signals are strong (97% across 2,600+ reviews), and OMR Reviews has ranked rapidmail as a category Leader. The product is in German and English. Best fit: small and mid-sized German-speaking businesses, associations, and e-commerce shops who want a no-fuss, DSGVO-konformes Newsletter tool with an unambiguous "data stays in Germany" answer for procurement and a German-speaking support team. Limitations to verify before procurement-grade buying: SSO/SAML and audit-log capabilities are not advertised on the public pages reviewed, and the public DPA download URL was not directly resolvable at audit — DPA accessibility for non-enterprise tiers should be confirmed with the vendor.
SUB-PROCESSORS

Carte des sous-traitants · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Référentiels & certifications

ISO/IEC 27001
ACTIVE
FEATURES

Matrice de fonctionnalités

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Tarifs & paliers

PAYANT
Tarifs sur mesure

Contactez l’éditeur pour les tarifs par palier ou volume.

Voir la page tarifs ↗
PUBLIC DOCUMENTS

Documents publics

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    www.rapidmail.com/data-protection…
    Open ↗
  • Terms of Service
    www.rapidmail.com/general-terms-and-conditions…
    Open ↗
ALTERNATIVES

Alternatives dans cette catégorie