Security and Compliance

Earn trust with every email

Permission-based sending, clear consent records and control over your data. MailGraf brings the tools for responsible email marketing together, with practical support for your UK GDPR and PECR obligations.

Clear boundaries for your account

Data access is scoped to your account and user permissions.

Account-level data separation
Your account

Contacts · Campaigns · Reports

Integration access

Revoke an API key when it is no longer needed

UK GDPR and PECR

Permission first. Trust built in.

We expect MailGraf customers to send to people who have agreed to hear from them. Our permission-based approach connects subscriber consent, clear records and an easy way to stop receiving emails.

UK GDPR

Covers how personal data is collected, used and protected. For subscriber data you manage in MailGraf, you are the controller and we process that data on your behalf.

PECR

Sets the rules for electronic marketing, including consent and opt-outs. MailGraf’s sending policy requires prior, verifiable permission, including where the law may allow exceptions.

01

Double opt-in, with a clear confirmation

Give new subscribers a confirmation step before they join your audience. MailGraf supports double opt-in and we recommend it for new sign-ups to help establish that the person behind the address wants your emails.

02

Consent you can trace

Contact profiles show the recorded sign-up source and permission type. Where confirmation evidence is available, you can review when consent was confirmed. MailGraf form records also preserve the source page and the consent wording shown at sign-up.

03

Preferences people can change

Let subscribers update their interests, pause emails or unsubscribe through your branded preference centre. Their choices help you keep your audience relevant and respect when they no longer want to hear from you.

Explore the preference centre
04

A way to act on ‘Forget me’ requests

Use the Forget action to remove a contact’s profile and associated personal data from active records. A minimal blocking record helps prevent the address from being added back accidentally. This supports your handling of erasure requests.

Know who can access your account

Who can access your data and how you manage connections matter.Manage team permissions and review account activity in one place.

Your data stays within your account’s boundaries

Access to your contact lists, campaigns and reports is restricted to authorised users and connections for your account.

Another customer account cannot access your contact list.

Role-based access for your team

The actions team members can perform are checked against their roles within the account.

Access to your account does not mean permission to perform every action.

API connections you can control

Review API request logs from your account.

Close off a connection you no longer use.

A record of sign-ins and sign-outs

Review recorded sign-ins and sign-outs in your account’s user activity history.

See which team member accessed the account and when.

Delivery Standards

Established standards behind your sending

Our partner-operated email delivery service combines information security standards with responsible sending practices.

ISO 27001

Information security

Our delivery partner is ISO 27001 certified. Its data centres follow the same security standard.

CSA

Certified email delivery

Our partner-operated sending platform is CSA certified. Its sending standards cover permission-based email, sender transparency and responsible unsubscribe handling.

PECRGDPRISO27001

Policies that support your review

Understand our privacy commitments, sending rules and data processing arrangements.

Before you decide

Is double opt-in a UK legal requirement?

UK rules do not require double opt-in in every case. It is a useful way to confirm a sign-up and keep evidence. MailGraf recommends it, while requiring prior, verifiable permission under our sending policy.

Can I import a purchased contact list?

No. Purchased, rented, scraped and harvested lists are prohibited. Having an email address or verifying that it works does not establish marketing permission.

Does every contact have a consent record?

Profiles show the information actually recorded. An imported or API-created contact does not automatically have a MailGraf confirmation record. You should retain the original permission evidence for those contacts.

What is the difference between unsubscribe and Forget?

Unsubscribe stops marketing while retaining the contact’s opt-out status. Forget removes the contact profile and associated personal data from active records, with a minimal blocking record to help prevent accidental re-import. Neither action replaces your review of data held in other systems or retained copies.

Get Started

Drive more engagement and sales with MailGraf

Enterprise infrastructure, high deliverability and advanced tools to help you build stronger, more effective campaigns.

MailGraf

Professional email marketing platform.

We Love Email

Don't miss out

Get the latest email marketing tips and exclusive updates.

PECRGDPRISO27001

MailGraf is a trading name of MailGraf Digital Ltd, registered in England and Wales, No. 13282175. ICO ZB250899.