Terms of Service

Last Updated: 1 July 2026

By accessing or using the services of EmailConsul LLC (“EmailConsul”, “we”, “us”), you agree to these Terms of Service (“Terms”) and our Privacy Policy (emailconsul.com/privacy-policy) . If you do not agree with these Terms, please do not use our services.

These Terms apply to all customers worldwide. Where legal requirements differ by jurisdiction, both US and EU/EEA/UK obligations are addressed within each section.

1. Data Processing & GDPR Compliance

  • 1.1 Data Processing & Storage Location

    EmailConsul processes and stores all data primarily in the United States. We do not operate our own servers in the EU/EEA; accordingly, all EU/EEA personal data transferred to our services will be processed in the U.S. A current list of sub-processors and their processing locations is published at emailconsul.com/legal/sub-processors.

  • 1.2 Legal Basis for Data Transfers from the EU/EEA

    For customers transferring EU/EEA or UK personal data to our US-based services, we rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914) as the legal mechanism for the transfer. For UK transfers, we additionally rely on the UK International Data Transfer Addendum (IDTA). The SCCs and IDTA are incorporated into our Data Processing Agreement (DPA), which is available at emailconsul.com/legal/dpa. The DPA must be formally signed before you process EU/EEA or UK personal data through our services; acceptance of these Terms alone does not fulfil this requirement under GDPR Art. 28.

    For US-based customers, no cross-border transfer mechanism is required for domestic data processing. Your use of our services is governed by applicable US federal and state law, including applicable state privacy statutes.

2. Your Rights Under GDPR and Applicable Privacy Law

If you are an EU/EEA (or UK) data subject, you have the following rights regarding your personal data:

  • Right to Access — Request a copy of your personal data that we hold.

  • Right to Rectification — Correct inaccurate or incomplete data.

  • Right to Erasure (“Right to be Forgotten”) — Request deletion of your data where there is no compelling ground for its continued processing.

  • Right to Restriction — Request that we limit the processing of your data in certain circumstances.

  • Right to Data Portability — Receive your data in a structured, commonly used, machine-readable format.

  • Right to Object — Object to the processing of your data where we rely on legitimate interests as our legal basis.

  • Right to Withdraw Consent — Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

  • Right to Lodge a Complaint — You have the right to lodge a complaint with your national data protection supervisory authority at any time. A list of EU supervisory authorities is available at edpb.europa.eu.

To exercise these rights, contact us at: [email protected]. EU/EEA data subjects may also contact our EU representative — see §10.2.

We will respond to your request within 45 days of receipt. For EU/EEA and UK data subjects, we will respond within one (1) month. Where a request is complex or we receive a high volume of requests, we may extend this by a further 45 days (or two months for EU/EEA and UK data subjects), with prior notice explaining the reason.

3. Responsibilities of Users (Customers)

You must ensure that any personal data you provide to EmailConsul is lawfully obtained and that your use of our services complies with all applicable privacy and data protection laws, including, where relevant, US state privacy statutes, the GDPR, and the UK GDPR.

Where you use our services to process personal data of other individuals, you act as the Data Controller (or equivalent under applicable law) and EmailConsul acts as the Data Processor (or Service Provider). You are responsible for having a lawful basis for that processing, for providing required notices to data subjects, and for ensuring your instructions to us comply with applicable law.

For customers processing EU/EEA or UK personal data, the Controller-Processor relationship and associated obligations are governed by our DPA (available at emailconsul.com/legal/dpa), which must be formally executed. Acceptance of these Terms alone does not constitute a valid data processing agreement under GDPR Art. 28.

4. Security & Data Protection

  • 4.1 Security Measures

    We implement technical and organisational security measures to protect user data, including:

    • Encryption — of data in transit and at rest.

    • Access controls — to limit access to authorised personnel only.

    • Regular security audits — to ensure compliance with best practices.

  • 4.2 Sub-processors & Third-Party Services

    We use trusted third-party service providers (sub-processors) to support our services. All sub-processors are bound by written data processing agreements that impose data protection obligations equivalent to those in our DPA and must comply with GDPR-equivalent data protection standards.

    A current and complete list of sub-processors, including their name, role, and processing location, is published at emailconsul.com/legal/sub-processors. We will provide prior notice of any intended addition or replacement of sub-processors (see your DPA for notice and objection procedures).

5. Data Retention & Deletion

Personal data is retained only as long as necessary to provide our services or as required by applicable law.

If you terminate your use of EmailConsul, we will delete or anonymise your personal data unless a legal retention obligation applies. To request data deletion, contact [email protected].

Detailed retention periods and the data return and deletion procedures applicable to Customer data, including obligations under GDPR Art. 28(3)(g), are set out in the DPA.

6. U.S. Government Data Requests

If we receive a U.S. government request for access to personal data, we will:

  • – assess the legality of the request and challenge any unlawful or overbroad demands;

  • – notify you (the Customer, as Data Controller or equivalent) as promptly as legally permitted, unless we are legally prohibited from doing so — for customers processing EU/EEA or UK personal data, this notification obligation is consistent with Clause 15 of the SCCs and the IDTA;

  • – minimise any required disclosure to protect privacy, disclosing only data strictly necessary to comply with the legal obligation.

7. Limitation of Liability

To the fullest extent permitted by applicable law, EmailConsul is not liable for any indirect, incidental, special or consequential damages resulting from the use of our services.

Our total aggregate liability under these Terms shall not exceed the amount paid by you for the services in the previous twelve (12) months preceding the event giving rise to the claim.

Nothing in these Terms excludes or limits liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) any other liability that cannot be lawfully excluded or limited under applicable law. For EU/EEA and UK data subjects, the liability cap above does not limit claims for material or non-material damages arising from a breach of the GDPR or UK GDPR under Art. 82 GDPR; where such a claim is brought against EmailConsul as a processor, we may seek exoneration where we can demonstrate we are not responsible for the damage (Art. 82(3) GDPR).

8. Updates to These Terms

We may update these Terms to reflect changes in legal, security, or business changes. Continued use of EmailConsul after an update constitutes acceptance of the new Terms. We will announce material updates via our website or email.

9. Governing Law & Dispute Resolution

These Terms are governed by the laws of the United States and the State of New York. Any disputes shall be resolved in the courts of New York.

For EU/EEA and UK customers, mandatory provisions of EU, EEA, and UK law, including data subject rights under the GDPR and UK GDPR, continue to apply notwithstanding this governing law clause, and customers and data subjects in those jurisdictions retain the right to bring claims before competent EU/EEA or UK courts and supervisory authorities where required by applicable law.

10. Contact Information

For GDPR-related inquiries and all privacy matters, contact us at:

  • [email protected]

  • EmailConsul LLC, 90 State Street, STE 700, Office 40, Albany, NY 12207, USA

EU/EEA data subjects may also contact our EU representative — see §11 below.

11. EU/EEA Data Subjects & EU Representative

EmailConsul has appointed Admonto BV as its representative in the European Union under Article 27 of the General Data Protection Regulation (EU) 2016/679:

Admonto BV
Hannie Schafstraat 62, 2033PJ Haarlem, Netherlands
Email: [email protected]

EU/EEA data subjects and EU supervisory authorities may contact Admonto BV directly in relation to any matter concerning the processing of personal data by EmailConsul. When contacting the EU representative, please use the subject line format: [GDPR] [EmailConsul] – [request type], and include your name and a brief description of your request. This contact point is for EU/EEA residents and supervisory authorities only. For all other enquiries, please use [email protected].