Legal
GDPR Compliance
Last updated: June 29, 2026
1. Overview
This statement explains how Boostmail, a product of AdPerfect ("Boostmail", "we", "us"), supports compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR in connection with our Shopify email and SMS marketing application (the "Service"). It should be read together with our Privacy Policy and Terms of Service.
2. Controller and processor roles
For the subscriber data a Merchant imports and sends to through Boostmail, the Merchant is the data controller and Boostmail acts as a data processor, processing that data only on the Merchant's documented instructions to deliver the Service. For our own business data, for example merchant account details, billing records, and website analytics, Boostmail acts as a controller, as described in our Privacy Policy.
3. Lawful basis
As controller of the subscriber data, the Merchant is responsible for establishing a valid lawful basis under Article 6 GDPR, typically the consent of the subscriber or the Merchant's legitimate interests, for sending marketing communications. Where consent is the basis, the Merchant must obtain and be able to demonstrate it. Boostmail processes that data under the lawful basis of performing its contract with the Merchant.
4. Data-subject rights
Data subjects have the right to access, rectify, erase, restrict, and port their personal data, and to object to processing. Because the Merchant is the controller of subscriber data, data subjects should direct requests to the relevant Merchant. Boostmail provides tooling, including unsubscribe handling and data export and deletion, and will assist Merchants in responding to data-subject requests within the timeframes required by law.
5. International data transfers
Personal data processed through the Service may be transferred to and processed in countries outside the European Economic Area or the United Kingdom. Where such transfers occur, we rely on appropriate safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses and equivalent UK transfer mechanisms, together with supplementary measures where required.
6. Sub-processors
We engage vetted sub-processors, such as cloud hosting, email and SMS delivery, AI content, and analytics providers, to deliver the Service. Each is bound by data-protection terms consistent with the GDPR. A current list of sub-processors is available on request from [email protected].
7. Data Processing Agreement
We make a Data Processing Agreement (DPA) available to Merchants who require one to meet their GDPR obligations. The DPA sets out the subject matter, duration, nature, and purpose of processing, the types of personal data and categories of data subjects, and the security and sub-processor terms that apply. To request a copy, contact [email protected].
8. Security measures
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, least-privilege practices, and monitoring, to protect personal data against unauthorized access, loss, or disclosure.
9. Breach notification
If we become aware of a personal-data breach affecting data we process on a Merchant's behalf, we will notify the affected Merchant without undue delay and provide the information reasonably needed to help the Merchant meet its own notification obligations to supervisory authorities and data subjects.
10. Contact us
Questions about GDPR or data protection at Boostmail? Email [email protected]. Boostmail is a product of AdPerfect.