Security and data location: where your email data sits and how it is protected

All data you send through 2Mail — addresses, content, logs and statistics — is processed and stored on JAAN bv's own servers in Belgium, inside the EU. Connections to and from the platform are encrypted with TLS, every application has its own revocable login or API key, and the platform is monitored 24/7 with 99.99% availability under the SLA.

This page describes the technical and organisational side: where the data sits, how it is protected in transit, who can reach it and what happens if something goes wrong. It complements the data processing agreement and does not replace it.

Where your data sits

One infrastructure, one country. Sending, storage, logging, tracking and support all run at JAAN bv itself; your data is not placed with a third party to be sent or analysed.

Sending and storage

The SMTP relay, the API and campaign management run on servers JAAN bv manages itself, in Belgium. Sending lists and templates you keep in the platform sit there as well.

Logs and statistics

Deliveries, bounces, rejections and open and click data are kept on the same infrastructure. The retention period is set out in the data processing agreement.

Tracking

Open and click tracking runs through our own servers. No third-party tracking script or pixel is placed in your emails.

Support

Whoever you call or email sits in Zelzate and works on the same systems. There is no support layer outside the EU that needs access to your account.

Security in transit and at access

Email security is a chain: from your application to 2Mail, from 2Mail to the receiving server, and access to your account in between.

TLS from your application to 2Mail

You connect over SMTP with STARTTLS on port 587, and over HTTPS for the API. Your login and the content of your messages therefore never travel unencrypted.

TLS to the receiving server

To mail servers that support it — the large majority today — email is delivered encrypted. If a recipient does not support TLS, that last hop cannot be encrypted; that is down to the recipient, not to you.

A separate login and key per application

Every application gets its own SMTP login and its own API key. If one leaks, you revoke it without touching the rest. Webhooks are signed, so your system can verify they genuinely come from 2Mail.

Access to the portal

The customer portal supports strong sign-in with an additional verification step. Who in your organisation has access is up to you.

How the SMTP relay works The email API

Availability, backups and incidents

An email platform has to be there the moment your web shop confirms an order, not just on an average day.

24/7 monitoring and 99.99% SLA

The platform is monitored around the clock. The SLA guarantees 99.99% availability and presentation of every message to the receiving server within ten seconds.

Redundancy and backups

The infrastructure is built redundantly and regular backups are taken, which also stay in Belgium. Exactly what is kept and how often is explained in the data processing agreement.

Data breach procedure

If we detect a breach affecting your data, we notify you without undue delay, as the GDPR requires, with what we know about its nature, scope and the data concerned. That lets you inform the supervisory authority and the data subjects in time.

Sub-processors

Sending, storage, logging and support are handled by JAAN bv itself, on its own infrastructure. For a limited number of supporting services — for instance the payment provider for invoicing or the party supplying the server space — other companies may be involved. The current list forms part of the data processing agreement and is available on request; a new sub-processor is only engaged after notifying you.

If you request the list, you receive it in writing, with each party's role and country of processing.

What is in your own hands

The strongest infrastructure does not help if the key is on a sticky note. These are the measures on your side.

Use a separate SMTP login or API key per application, and revoke a key as soon as an application is retired.
Choose long, unique passwords and keep them in a password manager, not in a configuration file in your source code.
Publish SPF, DKIM and DMARC on every sending domain and move DMARC to an enforcing policy after a test period.
Limit who in your organisation has access to the portal and review that regularly.
Do not put sensitive data in emails unless necessary: a link to a secured page is safer than an attachment containing the whole file.
Verify the signature of webhooks in your own system before processing their content.
Set up SPF, DKIM and DMARC

Six technical questions for any provider

The organisational questions are on the European email platform page; these are their technical counterparts. 2Mail's answers are above.

1 Do sending, storage and tracking run on the same infrastructure, or do parts go to a third party?
2 Is the connection from my application to the platform encrypted, and which ports are supported?
3 Can I create a separate login or key per application and revoke each one individually?
4 What availability is guaranteed contractually, and how is the platform monitored?
5 Within what timeframe and with what information am I notified of a data breach?
6 Which sub-processors are there, with what role and in which country — in writing?

Each of these questions has a short, factual answer. If you get a long answer without a country, port or timeframe, you do not have an answer yet.

How to put your sending into service securely

Four steps at the start, less than half a day's work in total, that you never have to repeat afterwards.

1

Create a separate login or API key per application

Web shop, CRM, invoicing: each its own access, with a name that says what it is for. That way you see in the logs who sent what, and you revoke precisely.

2

Connect encrypted

Set your SMTP client to STARTTLS on port 587 and test the connection. If your software refuses TLS, update it before going any further.

3

Publish SPF, DKIM and DMARC

From the dashboard, in one click. After publishing, check with a test email to an external address that all three pass.

4

Request the data processing agreement and the sub-processor list

File them with your record of processing activities, together with the answers to the six questions above. That completes the file in case anyone asks.

Request the documents Read about the European platform

Frequently asked questions

In Belgium, on JAAN bv's own infrastructure, inside the EU. Sending, storage, logs, tracking and support all run there; no data is placed with a third party to be sent or analysed.
Yes. SMTP with STARTTLS on port 587, and HTTPS for the API. Towards receiving mail servers TLS is used as soon as they support it, which is the case for the large majority today.
JAAN bv notifies you of the incident without undue delay, as the GDPR requires, with the information on nature, scope and affected data you need to inform the supervisory authority and the data subjects yourself.
The retention periods for logs, statistics and content are set out in the data processing agreement, which you receive on request. They are kept on the same Belgian infrastructure as the rest of your data.
Sending, storage and support are handled by JAAN bv itself. For supporting services such as payment or server space other parties may be involved; the current list is in the data processing agreement and available on request.
Yes. The measures are an annex to the data processing agreement, which includes a right of audit. We answer questions about the setup in writing; call +32 9 328 03 83 or use the contact form.
Call us
Send an email