GDPR and prospecting data
Last updated: 1 October 2026
Mailbase helps its customers prospect French companies from public sources. This page explains what is collected, why, who is responsible, how long it is kept, and how to object if you are one of the people concerned.
1. Who is responsible for what
- Prospecting for a customer. A Mailbase customer decides whom to contact and why, and signs its messages: it is the controllerof that prospecting. Mailbase finds the companies, reads their public contact details, checks the address, helps write the message and sends it on the customer's behalf: it acts as processor, on the customer's instructions.
- Mailbase's own platform. For accounts, billing, security, abuse screening, this website, the contact form and product analytics, Mailbase is the controller. See the privacy policy.
2. What Mailbase finds, and where it comes from
Prospecting reads only these public sources:
- Recherche d’entreprises API (data.gouv.fr — INSEE SIRENE register and RNE). Public open data on French companies and their registered leaders. Mailbase reads it; nothing is sent to it but the search filters.
- The company's own website and legal notice. Public pages the company published itself. Mailbase reads the contact email and the name of the person responsible from them.
For each company in a customer's prospecting pool, Mailbase can store:
- the company's register record: SIREN/SIRET, name, activity code, size band, address, and the names and roles of the leaders the register lists (register records marked non-public are skipped);
- its website, the page the contact details came from, a contact email, and the name, role and phone number of the person responsible when the company publishes them;
- public facts used to personalise a message (for example its specialties or opening year);
- the result of checking the address (the domain accepts mail; Mailbase asks the mail server whether the mailbox exists, and sends nothing);
- the emails written for it, whether and when they were sent, and the status of the exchange. Replies live in the customer's own inbox.
Some of these companies are sole traders: for them, company data is also data about a person. Mailbase treats every record the same way.
3. Why it is lawful
Business-to-business prospecting by email can rely on legitimate interestrather than prior consent, according to the French data protection authority (CNIL), provided that the message relates to the recipient's professional activity, that the recipient is told who is writing and where the address comes from, and that the recipient can object easily at any time. Mailbase builds these conditions into the product: prospecting targets professional contact details published by the company itself, every first email says where the address comes from, and every email carries an opt-out link that works with one click.
The customer is responsible for the relevance of its offer to the recipient's profession and for its own message. Mailbase refuses to send to an address that unsubscribed, bounced or complained.
4. Information for people we did not collect data from (Article 14)
If you are contacted, you receive an email that says, in one line, where the address comes from and gives a link to stop receiving messages. This page is the complete information the GDPR asks for when data is not collected from you:
- Who: the customer whose name is in the email signature is the controller; Mailbase is its processor (section 1).
- Purpose: proposing a professional offer to a company, to the person responsible for the relevant activity.
- Categories of data and source: section 2.
- Recipients: the customer and the services in section 8.
- Retention: section 7.
- Your rights: section 5, and the right to lodge a complaint with a supervisory authority — in France, the CNIL (cnil.fr).
5. Your rights, and how to object
You can ask to access the data held about you, have it corrected or erased, restrict its use, and — above all — object to receiving prospecting at any time, without giving a reason.
- Stop immediately:use the link at the end of any email from Mailbase. Your address is added to the sender's blocklist and it will not be contacted again by that sender through Mailbase.
- Any other request: write to contact@mailbase.studio or use the contact form (topic “My personal data”), saying which address or company is concerned. We act on our side and pass the request to the customer concerned. We answer within one month.
- Erasure keeps a trace on purpose: to make sure you are not contacted again, a minimal record (the address on a blocklist) outlives the erasure of the rest.
6. Safeguards in the product
- Sending is refused to addresses that unsubscribed, bounced or complained, and to people erased on request.
- Every prospecting email carries a visible opt-out line and one-click unsubscribe headers.
- Outgoing email is screened for scams and phishing before it is sent, and abusive senders are suspended.
- Sending volume is capped per day and per domain, with a gradual warm-up.
More in Security.
7. How long prospect data is kept
A prospect record is kept while the customer's workspace uses it. Mailbase includes an automatic purge that deletes companies in the prospecting pool that have had no contact, enrichment or update for a set period — 36 months by default — together with the emails drafted for them. A company with a live conversation or an email still waiting to go out is never purged, and an opt-out is always kept. When a workspace is deleted, all of its prospecting data is deleted with it.
8. Services involved
Prospecting data passes through the services below. The full list, with the data and location of each, is on the sub-processors page.
| Service | Purpose | When |
|---|---|---|
| Amazon Web Services (Amazon SES and SNS) | Sending email through Mailbase's managed sending, receiving replies, and reporting deliveries, bounces and complaints back. | Always |
| Stripe | Subscriptions, invoices and payment for plans and for domains bought through Mailbase. Card details are entered on Stripe and never reach Mailbase. | Always |
| Google (sign-in with Google, optional Gmail mailbox) | Signing in with a Google account, and — only if the customer connects a Gmail mailbox — reading and sending mail from it. | If the customer connects it |
| Google (Analytics 4 and Google Ads measurement) | Audience measurement and advertising conversion measurement on the public website. The tag runs in Google Consent Mode with every category denied until the visitor accepts the cookie banner. | After consent |
| PostHog | Product analytics. Loaded in the browser only after the visitor accepts the cookie banner; server-side events carry hashed workspace identifiers and no email address or message content. | After consent |
| AI model endpoint (OpenRouter by default, optionally Cloudflare AI Gateway) and the model provider behind it (DeepSeek by default) | The AI assistant, the drafting of prospecting emails, reply triage and the content check of outgoing mail, for workspaces that do not bring their own AI account. | Always |
| AI providers a customer connects itself (OpenAI / ChatGPT, DeepSeek, OpenRouter, MiniMax, Groq, Mistral, or any compatible endpoint) | The same AI features, run on the customer's own account and at its own cost. The credential is stored encrypted. | If the customer connects it |
| TypeSafe (TypeSafe AI) | Scam and phishing screening of outgoing email before it is sent, and a fit check of prospecting results against the target the customer described. | Always |
| Porkbun | Registering and renewing domain names a customer buys through Mailbase, and writing their DNS records. | If the customer connects it |
| Serper (google.serper.dev) | Prospecting: finding a company's website from its name and city. Used only when the operator has set a Serper key; a self-hosted search instance is the alternative. | If configured |
| Browserless (headless Chrome rendering) | Prospecting: rendering company websites whose content only appears with JavaScript, to read the legal notice and contact page. Used only when configured. | If configured |
| [À COMPLÉTER : nom de l’hébergeur de l’application et de la base de données] | Hosting of the application and of its PostgreSQL database. | Always |