Trust Center

SecureMailMerge is private by default. Your spreadsheet, recipients and messages are processed in Outlook on your computer and sent from your own Microsoft 365 mailbox. The add-in never sends campaign data to our servers; you only share it with us if you choose to send examples to support.

At a glance

Your campaign data

Spreadsheets, recipients and messages are processed in Outlook on your computer and sent through your own mailbox via Microsoft Graph.

See the data flows

Data we store

Account and licensing data (identifiers, name, email address), billing contacts and transaction numbers, support conversations and server logs. No campaign data.

See the full table

Hosting

Our licensing server runs in Microsoft Azure data centers in Europe. The website and add-in files are served by Cloudflare Pages.

See hosting and providers

Assurance

We have no SOC 2 report or ISO 27001 certification of our own. Cloudflare, which hosts our website and add-in, is ISO 27001 certified and has a SOC 2 Type II attestation.

See compliance and contracts

Documents and guides

Frequently asked questions

Are you SOC 2 or ISO 27001 certified?
No. We do not have a SOC 2 report or ISO 27001 certification. Because campaigns are processed locally in Outlook, the add-in never sends your campaign data to us. The data we do receive, such as account, licensing, billing and support data, logs, usage counts and error reports, is listed in full in our security overview, which also describes the controls we apply.
Does recipient or message data leave our Microsoft 365 tenant?
Only as the emails you send. Messages are assembled in Outlook on your computer and sent from your own mailbox through Microsoft Graph to your recipients. No campaign data is sent to SecureMailMerge. The one exception is your choice: if you send us examples for support, we receive what you send.
What data do you store about us, and for how long?
Account and licensing data (user identifiers, name, email address), billing contact details and transaction numbers, support conversations, and web server logs for about 30 days. Free users' email addresses are not stored after the license check. Unless we must keep it for legal or legitimate business reasons, we delete stored data within 30 days after your account is deleted, and usually immediately. Under our DPA, data processed on your behalf is deleted within 10 business days after the service ends. See the full table.
Where is our data hosted?
Campaign data stays on your computer and in your own Microsoft 365 mailbox. Our licensing server runs in Microsoft Azure data centers in Europe. The website and add-in files are served by Cloudflare Pages and store no campaign data.
Who are your subprocessors?
Microsoft Azure, Cloudflare, Sentry, Help Scout, Fathom Analytics and HelloSign, each for a narrow purpose. Paddle and Microsoft act as Merchants of Record under their own privacy policies. See providers and subprocessors for what each one receives.
Why does Microsoft warn that the add-in "can send your data to the internet"?
Microsoft shows this warning for every add-in that works with Microsoft 365 data, because once access is granted Microsoft cannot limit what an add-in does with it. SecureMailMerge uses the access only on your computer to talk to Microsoft Graph. That Microsoft Graph token is never sent to our servers. See each permission and why we need it.
Can we block analytics and error reporting?
Yes. Besides the Microsoft 365 endpoints your tenant already allows, only www.securemailmerge.com is required. The analytics host (analytics.solinventum.com) and Sentry are optional and can be blocked at the firewall without affecting the add-in. The license management portal (licensing.solinventum.com) is only needed by the people who manage your licenses. See the firewall requirements.
Can we control who in our organization uses it?
Yes. A Microsoft 365 admin can deploy the add-in to specific users, groups or the whole organization from "Integrated apps".
Do you sign a Data Processing Addendum?
Yes. Download our standard DPA or request a signed copy. We send it for signature through HelloSign and countersign it.
Will you notify us of a data breach?
Yes. Under our DPA we notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own reporting obligations.
Will you complete our security questionnaire?
We do not have the resources to complete custom questionnaires. This Trust Center, our security overview, permissions guide and DPA are available for your review.
Is SecureMailMerge Microsoft 365 Certified?
No. We have published a Publisher Attestation with Microsoft. It is a self-reported questionnaire, not a Microsoft security review.
How do we report a security issue?
Email [email protected]. Our security contact is also published in security.txt.

Contact us

Send security questions, vulnerability reports and requests for a signed DPA to our team.

[email protected]