Security and data location: where your email data sits and how it is protected
All data you send through 2Mail — addresses, content, logs and statistics — is processed and stored on JAAN bv's own servers in Belgium, inside the EU. Connections to and from the platform are encrypted with TLS, every application has its own revocable login or API key, and the platform is monitored 24/7 with 99.99% availability under the SLA.
This page describes the technical and organisational side: where the data sits, how it is protected in transit, who can reach it and what happens if something goes wrong. It complements the data processing agreement and does not replace it.
Where your data sits
One infrastructure, one country. Sending, storage, logging, tracking and support all run at JAAN bv itself; your data is not placed with a third party to be sent or analysed.
Sending and storage
The SMTP relay, the API and campaign management run on servers JAAN bv manages itself, in Belgium. Sending lists and templates you keep in the platform sit there as well.
Logs and statistics
Deliveries, bounces, rejections and open and click data are kept on the same infrastructure. The retention period is set out in the data processing agreement.
Tracking
Open and click tracking runs through our own servers. No third-party tracking script or pixel is placed in your emails.
Support
Whoever you call or email sits in Zelzate and works on the same systems. There is no support layer outside the EU that needs access to your account.
Security in transit and at access
Email security is a chain: from your application to 2Mail, from 2Mail to the receiving server, and access to your account in between.
TLS from your application to 2Mail
You connect over SMTP with STARTTLS on port 587, and over HTTPS for the API. Your login and the content of your messages therefore never travel unencrypted.
TLS to the receiving server
To mail servers that support it — the large majority today — email is delivered encrypted. If a recipient does not support TLS, that last hop cannot be encrypted; that is down to the recipient, not to you.
A separate login and key per application
Every application gets its own SMTP login and its own API key. If one leaks, you revoke it without touching the rest. Webhooks are signed, so your system can verify they genuinely come from 2Mail.
Access to the portal
The customer portal supports strong sign-in with an additional verification step. Who in your organisation has access is up to you.
Availability, backups and incidents
An email platform has to be there the moment your web shop confirms an order, not just on an average day.
24/7 monitoring and 99.99% SLA
The platform is monitored around the clock. The SLA guarantees 99.99% availability and presentation of every message to the receiving server within ten seconds.
Redundancy and backups
The infrastructure is built redundantly and regular backups are taken, which also stay in Belgium. Exactly what is kept and how often is explained in the data processing agreement.
Data breach procedure
If we detect a breach affecting your data, we notify you without undue delay, as the GDPR requires, with what we know about its nature, scope and the data concerned. That lets you inform the supervisory authority and the data subjects in time.
Sub-processors
Sending, storage, logging and support are handled by JAAN bv itself, on its own infrastructure. For a limited number of supporting services — for instance the payment provider for invoicing or the party supplying the server space — other companies may be involved. The current list forms part of the data processing agreement and is available on request; a new sub-processor is only engaged after notifying you.
If you request the list, you receive it in writing, with each party's role and country of processing.
What is in your own hands
The strongest infrastructure does not help if the key is on a sticky note. These are the measures on your side.
Six technical questions for any provider
The organisational questions are on the European email platform page; these are their technical counterparts. 2Mail's answers are above.
Each of these questions has a short, factual answer. If you get a long answer without a country, port or timeframe, you do not have an answer yet.
How to put your sending into service securely
Four steps at the start, less than half a day's work in total, that you never have to repeat afterwards.
Create a separate login or API key per application
Web shop, CRM, invoicing: each its own access, with a name that says what it is for. That way you see in the logs who sent what, and you revoke precisely.
Connect encrypted
Set your SMTP client to STARTTLS on port 587 and test the connection. If your software refuses TLS, update it before going any further.
Publish SPF, DKIM and DMARC
From the dashboard, in one click. After publishing, check with a test email to an external address that all three pass.
Request the data processing agreement and the sub-processor list
File them with your record of processing activities, together with the answers to the six questions above. That completes the file in case anyone asks.