Skip to content

Inxmail

Email marketing · Germany
Founded 1999 · inxmail.de

Freiburg-based premium German enterprise email marketing platform with ISO 27001 (TÜV Rheinland) and EU-only hosting.

Inxmail is a European service hosted in Germany, with at most minor, transient US exposure under the CLOUD Act. It is listed under Email marketing.

Assessment notes

Freiburg-based GmbH with EU-only hosting, ISO 27001 certified by TÜV Rheinland, SCC for the small US sub-processor footprint that exists for marketing-site analytics, and 'Software Made in Germany' designation: EU-owned and EU-hosted with minor CLOUD Act exposure, but no publicly-linked DPA or sub-processors document (enterprise sales model gates these documents to the contracting flow).

Findings

CLOUD Act
Ownership
Sub-processors
— not disclosed

Verified signals

Jurisdiction
  • EU / adequacy hosting: Yes
  • EU / adequacy operator: Yes
  • No US CLOUD Act exposure: Not assessed
Transparency
  • Public DPA: No
  • Sub-processors disclosed: No
  • Open-source clients: No
  • Third-party certification: Yes
Jump to

About Inxmail

Inxmail is a Freiburg-headquartered German email marketing platform operated by Inxmail GmbH (Wentzingerstr. 17, 79106 Freiburg im Breisgau), founded in 1999 and one of the longest-running independent ESPs in DACH. The product is positioned as a premium enterprise solution for media and publishing, energy utilities, banking and insurance, and retail/e-commerce, with a modular platform covering newsletter campaigns, marketing automation, transactional / trigger-based emails, and an SMTP Mail Relay. Inxmail reports more than 2,000 corporate customers.

The compliance posture is strong on the technical side: customer data is hosted exclusively on EU servers, the company is certified to ISO/IEC 27001:2022 by TÜV Rheinland for the development and operation of its email marketing applications, and it carries the BITMi "Software Made in Germany" industry seal. The privacy policy notes that any transatlantic transfers (e.g. for Google Analytics or LinkedIn marketing pixels on the corporate website) are covered by Standard Contractual Clauses; the external Data Protection Officer is DDSK GmbH. Where Inxmail is weaker for a procurement-grade assessment is transparency: the dedicated DPA (AVV), security, and sub-processor pages are still not publicly resolvable, and the enterprise contracting flow gates the AVV, so small EU buyers cannot self-serve a copy of the DPA; the absence of a public DPA and sub-processors disclosure is the primary gap in an otherwise solid EU-hosted, EU-owned, ISO 27001-certified profile.

Pricing is now published rather than sales-gated: the Email Marketing Platform starts from €200 per month and the SMTP Mail Relay from €70 per month, billed by sending volume with unlimited contacts and no per-contact fee, sold as flexible monthly packages or annual quotas. Fees cover hosting, administration, the deliverability team and monthly user support; there is still no free tier. Best fit: mid-market and enterprise marketers in DACH (publishers, utilities, financial services) who want a long-running independent German vendor, ISO 27001 attestation, and white-glove deliverability support, and are comfortable with sales-mediated procurement. Buyers who need a freemium entry tier or self-serve DPA download should look at CleverReach or rapidmail in this category.

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.

Frameworks & certifications

ISO/IEC 27001
Active

Capability matrix

Table 1Capabilities of Inxmail

Automation Yes
Landing pages No
A/B testing Yes
Transactional email Yes
SMS marketing No
Built-in CRM No
Dedicated IP Yes
Free tier No

Integration & access

REST API Yes
SSO (SAML / OIDC) No

Compliance & governance

Audit log No
Self-host / on-prem option No

Pricing & tiers

from €200/mo
Paid
View pricing page

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement. This is recorded as no public DPA (see How we assess).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing

Alternatives in this category

  • France · €8/mo
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: No
  • Germany · €15/mo
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: No
  • United Kingdom · €0/mo
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: No