EmailOctopus
VERIFIEDLondon-based low-cost email marketing (Three Hearts Digital, 2014), generous free tier, indie-friendly, Amazon SES-backbone.
Why this score?
Three Hearts Digital Ltd (London, 86-90 Paul Street, EC2A 4NE) operates EmailOctopus as a low-cost subscriber-based email marketing service with a generous free tier — GDPR-compliant, indie-friendly, and competitively priced ($480/year at 100k subscribers); but UK post-Brexit jurisdiction + no public certifications (ISO 27001 / SOC 2) + hosting provider not disclosed (AWS likely at this low-cost scale, given EmailOctopus's historical relationship with Amazon SES as the underlying delivery backbone) — score 3/5 with material CLOUD Act exposure.
- SCORE
- 3.0/5
- CLOUD ACT
- CLOUD ACT EXPOSURE
How exposed customer data is to US authorities under the CLOUD Act.
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- OWNERSHIP
- OWNERSHIP
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
US-owned US-headquartered, or has a US parent company.
-
Other This listing Swiss, UK or another non-EU jurisdiction.
-
- SUB-PROCS
- — not disclosed
JUMP TO
About EmailOctopus
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
Alternatives in this category
German enterprise email marketing (XQueue GmbH, Offenbach, 2002), ISO 27001, EU data centres, 3k+ customers, 10 offices worldwide.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
German email marketing platform with EU-only customer data storage in Germany and a permanently free Lite tier.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Freiburg-based German email marketing tool hosting customer data exclusively in a Frankfurt ISO 27001 data centre, no public cloud.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.