MailerLite
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Lithuanian-founded email marketing platform with EU data storage, a generous free tier, and broad automation plus transactional features.
MailerLite offers EU hosting in the Netherlands, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Email marketing.
Assessment notes
EU-owned (Polish parent cyber_Folks via Vercom) with EU primary email storage and ISO 27001, but a US legal entity (MailerLite Inc., San Francisco) for non-EEA customers plus multiple US sub-processors (Intercom, Stripe, OpenAI, Google Vertex AI, Zoom, NetSuite) and no public DPA or dedicated sub-processors page: material CLOUD Act exposure, no public sub-processors disclosure.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 2 · 1 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About MailerLite
MailerLite is a Vilnius-founded email marketing and automation platform offering newsletters, automation flows, landing pages, signup forms, and transactional email through its sister product MailerSend. Founded in 2010 by Ignas Rubezius, the company was acquired by Polish e-mail communications group Vercom in April 2022 for around €84M, and public reporting indicates a further 2025 transition under Polish-listed cyber_Folks; both moves keep MailerLite under EU ownership.
The legal structure splits by region: MailerLite Limited (Dublin, Ireland) is the data controller for EEA, UK, and Swiss customers, while MailerLite, Inc. (San Francisco, California) handles other regions. Primary subscriber storage runs from an EU data center carrying ISO 27001 certification (Bureau Veritas), but the US legal entity together with several US sub-processors (Intercom for support, Stripe/Braintree/PayPal for payments, OpenAI and Google Vertex AI for AI-assistant features, Zoom for events, Oracle NetSuite for accounting) introduce material CLOUD Act exposure, especially for customers handled by the US Inc.
MailerLite competes on price and UX against Mailchimp: a free tier covers up to 500 subscribers and 12,000 monthly emails, paid plans start at roughly €9/month, and a long-running 30%-recurring affiliate program with a 45-day cookie remains a strong distribution lever. Marketing-site internationalization covers EN, ES, and PL; in-product UI localization in those languages was not directly verified during this audit. Best fit: SMBs and creators who want a credible EU primary-hosting story and low-cost entry, and can accept a US legal entity for non-EEA accounts plus US sub-processors for support and AI features. Procurement teams with strict no-CLOUD-Act requirements should pair this with legal review or look at higher-scoring alternatives in the category.
Sub-processor map · 2
-
Google Ireland Limited USIreland
Data center operations (DE for Legacy MailerLite, NL for new MailerLite)
-
Vercom S.A. EUPoland
Shareholder; managing and improving MailerLite services
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Google Ireland Limited | Ireland | Data center operations (DE for Legacy MailerLite, NL for new MailerLite) | US |
| Vercom S.A. | Poland | Shareholder; managing and improving MailerLite services | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of MailerLite
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
France · €8/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €15/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
United Kingdom · €0/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€8/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€15/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€0/mo |