MBX Reach
🌐 English

Data Processing Agreement

Last updated: 2026-09-12 · MediaBoxEnt Digital Studio LLC

This is the agreement European, United Kingdom and Swiss law requires between you, the controller of your subscribers' personal data, and MediaBoxEnt Digital Studio LLC, the processor that holds and sends it for you. It applies automatically to every account, with no signature and no request, and it is part of the Terms of Service.

It is written to be read rather than filed. If you need a signed copy for your records, the first section says how to get one.

1.What This Agreement Is

European, United Kingdom and Swiss data protection law requires a written agreement between a controller and the processor acting on its behalf. This is that agreement. It applies to you automatically, without a signature, from the moment you accept the Terms of Service, and it covers every workspace on your account.

If your organisation needs a copy signed by us, write to privacy@mbxreach.com with the name and address of the contracting entity and we will send one. The signed copy says the same thing this page says; nothing is negotiated away in private that is not offered here in public.

Where this agreement and the Terms of Service disagree about personal data, this agreement wins. On everything else, the Terms govern.

2.The Two Roles

About your subscribers you are the controller and we are your processor. You decide whose addresses go into MBX Reach, what you store about them and what you send them. We hold and send it on your instruction and for no purpose of our own.

About you we are the controller: the account, the people on your team, what you are billed and how you use the panel. That side is the Privacy Policy, not this agreement, and no part of this page turns us into your processor for it.

You confirm that you have a lawful basis for every address you put into MBX Reach, and that the notices your subscribers were given cover what happens here. We cannot check that for you and we do not.

3.What We Process, and For How Long

The subject matter is the operation of MBX Reach for you. The nature and purpose of the processing is storing your subscribers, sending the campaigns and automations you create, recording what happened to each message, and running the signup, preference and unsubscribe pages your subscribers see. The categories of data subject are your subscribers and contacts. The personal data is what you choose to put in, which is normally:

  • The email address, and any name, custom fields and tags you store with it.
  • Which lists and segments the address belongs to, and where it came from.
  • The date, the IP address and the page of a signup, and of a double opt-in confirmation where one was used. This is consent evidence and the law expects it to exist.
  • Delivery results: delivered, bounced, complained, unsubscribed, with the date and, for an unsubscribe, the reason if one was given.
  • Opens and clicks, with the date and the link, and the IP address stored as a one-way hash rather than as an address.
  • Behaviour events you send us yourself through the API, with whatever you put in them.
  • The content of your campaigns and automations, which is yours and may mention people.

The processing lasts as long as your workspace exists, and then as long as the Deletion and Return section says. The writing assistant is the one thing that never receives any of this: it is sent the brief or the campaign text you type, and your workspace name, and never your contacts.

4.Your Instructions

We process personal data only on your documented instructions. Using the product is the instruction: an import, a campaign, an automation, an API call, a deletion. These documents and the settings in your panel are the rest of it.

We will tell you if an instruction of yours appears to us to break data protection law, and we may decline it until it is resolved. We will also tell you, unless the law forbids it, if an authority asks us for your data. We do not hand over a customer's subscribers without a legal obligation to.

One thing we do that is ours and not yours, and it is named here so it is not a surprise: a count of how many addresses on an import have complained about mail from other workspaces is used to decide whether that import is held for review. Only the number crosses between customers. No address ever does.

5.Confidentiality

Everyone who can reach customer data is bound to keep it confidential, and that obligation outlasts their involvement. Access is limited to the people who need it to run the service, and what they open is written to an audit trail.

Operator access to a workspace is for support and abuse handling only. It is never used to read a customer's campaigns or contacts out of curiosity, and it is never used to build anything of ours.

6.Security

The measures in place today, stated as they are rather than as a list of ambitions:

  • Every seat signs in with a second step: a passkey or an authenticator app. This is not optional and cannot be turned off.
  • Roles inside a workspace, so a member cannot do an owner's work, and an audit trail of what was done and by whom.
  • Data in transit is encrypted with TLS. Data at rest is encrypted by the platform that stores it.
  • Each workspace is isolated by the application: every query is scoped to a workspace, and a request that does not name one is refused.
  • Credentials and keys are held in the platform's secret store, never in the code, and API keys are stored as hashes.
  • The IP address recorded on an open or a click is stored as a one-way hash, so a report cannot become a location history.
  • Bounces and complaints are suppressed automatically and permanently, and sending pauses by itself when a campaign's complaint or bounce rate crosses the thresholds published in the Anti-Spam Policy.
  • Rate limits on sign-in, on the API and on the public pages, and a bot check on the hosted signup forms.
  • Backups, from which a workspace can be restored, kept for 30 days and no longer.

We hold no ISO 27001 certification and no SOC 2 report today. Saying so is the point of this section: you are entitled to know what you are relying on, and a claim we cannot evidence would be worth less than the truth.

7.Subprocessors

You give us general authorisation to engage subprocessors. There is one today for your subscribers' personal data.

Cloudflare, Inc. (United States) provides the infrastructure the whole service runs on: the application, the database, the object storage where uploaded images sit, the queues, the delivery of every email we send for you, and the bot check on the public signup pages. Every subprocessor we engage is bound by written terms at least as protective as these, and we remain responsible to you for what it does.

Two things are not subprocessors of your subscribers' data, and are named here so the list cannot be accused of hiding them. Stripe, Inc. (United States) processes payments, which is your billing data and not your subscribers'. The writing assistant reaches a language model through the OpenRouter marketplace, and is sent only the text you type into it and your workspace name; your contacts are never sent to it, and you can leave the assistant switched off for your workspace by asking us.

If we add or replace a subprocessor we will say so on this page at least 30 days before it starts, and by email to the address on your account. If you object on reasonable data protection grounds within those 30 days, write to privacy@mbxreach.com. If we cannot offer you an alternative, you may terminate the affected part of the service and we will refund the unused part of what you paid.

8.Where the Data Is, and Transfers

MediaBoxEnt Digital Studio LLC is a company in New Jersey, United States, and MBX Reach stores personal data in the United States. The database runs in Cloudflare's Eastern North America region. The application itself runs on Cloudflare's global network, so a request is handled at the point of presence nearest the person making it, but the data it reads and writes lives in the region named above.

For personal data protected by European Union law, the Standard Contractual Clauses approved by the European Commission on 4 June 2021, Module Two (controller to processor), are incorporated into this agreement and are entered into between you as data exporter and MediaBoxEnt as data importer. Clause 7, the docking clause, applies. Clause 9 applies with Option 2, general written authorisation, with the 30 days' notice set out in the Subprocessors section. Clause 11 applies without the optional independent dispute resolution body. Clauses 17 and 18 are governed by the law and the courts of Ireland. Annex I is the What We Process section together with the Contact section, Annex II is the Security section, and Annex III is the Subprocessors section.

For the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner is incorporated, with the Standard Contractual Clauses above as its approved clauses, Tables 1 to 3 completed by the same sections, and neither party able to end the Addendum under Table 4 as permitted by section 19. For Switzerland, the Clauses apply with the Swiss Federal Data Protection and Information Commissioner as the supervisory authority, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and with the protection extended to data about legal entities while Swiss law provides it.

9.Helping You Answer Your Subscribers

Most of what a subscriber can ask for, you can do yourself and immediately: the panel shows everything held about a contact, exports it, corrects it and deletes it, and the hosted preference and unsubscribe pages let the subscriber act without going through you at all.

If a request reaches us instead of you, we will not answer it on your behalf. We forward it to the address on your account and help you respond, at no charge, as far as the law requires.

10.If There Is a Breach

If we become aware of a personal data breach affecting your subscribers, we will tell you without undue delay and in any event within 72 hours of becoming aware of it, by email to the address on your account.

The notice will describe what happened, the categories and approximate number of records and people involved as far as we know them, the likely consequences, what we have done and what we advise you to do. If we do not know everything at the time, we will send what we have rather than wait, and follow it with the rest. Notifying your supervisory authority and your subscribers is yours to do, because you are the controller, and we will give you what you need to do it.

11.Impact Assessments

If you have to carry out a data protection impact assessment, or consult a supervisory authority before processing, we will give you reasonable help with the parts that concern MBX Reach. In practice most of what such an assessment asks for is already written down in these documents, and you may use them.

12.Deletion and Return

You can export your contacts and their data at any time while the workspace exists, in CSV, from the panel and from the API. Do that before you close anything, because closing does what it says.

When you close a workspace, or when the agreement ends, the personal data we hold for you is deleted from the live service at once and from backups within 30 days. We do not keep a copy for ourselves and we do not need you to ask twice.

Two things survive, and both are required rather than convenient. Suppression entries, which are the addresses that unsubscribed, bounced hard or complained, are kept so that a later import cannot mail somebody who told us to stop. Records we are obliged to keep by law, such as invoices, are kept for as long as the law says.

13.Audits and the Information We Give

On request we will give you the information you reasonably need to show that we meet our obligations under this agreement. These documents, kept current, are the first answer to most of it.

If that is not enough for you, you may audit us, or have an independent auditor bound to confidentiality do it, once in any twelve months, with 30 days' written notice, during business hours, without disturbing the service and without any access to another customer's data. You bear the cost, except where an audit finds us in material breach of this agreement, in which case we bear it. A supervisory authority exercising its own powers is not limited by this section.

14.United States Privacy Laws

For the California Consumer Privacy Act as amended, and for the comparable laws of other states, we are a service provider or processor and you are the business or controller. We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not retain, use or disclose it for any purpose other than performing the service for you, we do not combine it with personal information from anyone else except as those laws permit, and we will not do any of that in the future without telling you.

We understand and will comply with these obligations, and you may take reasonable steps to confirm that we do.

15.Liability

The limitations and exclusions of liability in the Terms of Service apply to this agreement and to the Standard Contractual Clauses, in the aggregate across all of them, except where the law does not allow that. Nothing here limits the rights a data subject has under the Clauses themselves.

16.Changes to this Agreement

We may update this agreement, and the version date at the top says which one you are reading. Where a change materially reduces the protection this agreement gives, we give at least 30 days' notice by email to the address on your account before it takes effect, on the same terms as the Terms of Service. A change required by law, or by a supervisory authority, takes effect when the law does.

17.Contact

Data protection questions, signed copies, subprocessor objections and anything else in this agreement: privacy@mbxreach.com.

MediaBoxEnt Digital Studio LLC · 479 State Rt 17 Ste 6#3008, Mahwah, NJ 07430. MediaBoxEnt Technologies. Website: mbxreach.com.

We have not appointed a representative in the European Union or the United Kingdom under Article 27. We are a small company and we will say so rather than name one that does not exist. Write to the address above and a person reads it.

Let's keep in touch

New products when there are any, and the occasional note about the ones we already make. One click to leave.

We handle it as described in our Privacy Policy.