Inxmail
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Freiburg-based premium German enterprise email marketing platform with ISO 27001 (TÜV Rheinland) and EU-only hosting.
Inxmail is a European service hosted in Germany, with at most minor, transient US exposure under the CLOUD Act. It is listed under Email marketing.
Assessment notes
Freiburg-based GmbH with EU-only hosting, ISO 27001 certified by TÜV Rheinland, SCC for the small US sub-processor footprint that exists for marketing-site analytics, and 'Software Made in Germany' designation: EU-owned and EU-hosted with minor CLOUD Act exposure, but no publicly-linked DPA or sub-processors document (enterprise sales model gates these documents to the contracting flow).
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: No
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Inxmail
Inxmail is a Freiburg-headquartered German email marketing platform operated by Inxmail GmbH (Wentzingerstr. 17, 79106 Freiburg im Breisgau), founded in 1999 and one of the longest-running independent ESPs in DACH. The product is positioned as a premium enterprise solution for media and publishing, energy utilities, banking and insurance, and retail/e-commerce, with a modular platform covering newsletter campaigns, marketing automation, transactional / trigger-based emails, and an SMTP Mail Relay. Inxmail reports more than 2,000 corporate customers.
The compliance posture is strong on the technical side: customer data is hosted exclusively on EU servers, the company is certified to ISO/IEC 27001:2022 by TÜV Rheinland for the development and operation of its email marketing applications, and it carries the BITMi "Software Made in Germany" industry seal. The privacy policy notes that any transatlantic transfers (e.g. for Google Analytics or LinkedIn marketing pixels on the corporate website) are covered by Standard Contractual Clauses; the external Data Protection Officer is DDSK GmbH. Where Inxmail is weaker for a procurement-grade assessment is transparency: the dedicated DPA (AVV), security, and sub-processor pages are still not publicly resolvable, and the enterprise contracting flow gates the AVV, so small EU buyers cannot self-serve a copy of the DPA; the absence of a public DPA and sub-processors disclosure is the primary gap in an otherwise solid EU-hosted, EU-owned, ISO 27001-certified profile.
Pricing is now published rather than sales-gated: the Email Marketing Platform starts from €200 per month and the SMTP Mail Relay from €70 per month, billed by sending volume with unlimited contacts and no per-contact fee, sold as flexible monthly packages or annual quotas. Fees cover hosting, administration, the deliverability team and monthly user support; there is still no free tier. Best fit: mid-market and enterprise marketers in DACH (publishers, utilities, financial services) who want a long-running independent German vendor, ISO 27001 attestation, and white-glove deliverability support, and are comfortable with sales-mediated procurement. Buyers who need a freemium entry tier or self-serve DPA download should look at CleverReach or rapidmail in this category.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Inxmail
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
Alternatives in this category
-
France · €8/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €15/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
United Kingdom · €0/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€8/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€15/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€0/mo |