Trust Center
SecureMailMerge is private by default. Your spreadsheet, recipients and messages are processed in Outlook on your computer and sent from your own Microsoft 365 mailbox. The add-in never sends campaign data to our servers; you only share it with us if you choose to send examples to support.
At a glance
Your campaign data
Spreadsheets, recipients and messages are processed in Outlook on your computer and sent through your own mailbox via Microsoft Graph.
See the data flowsData we store
Account and licensing data (identifiers, name, email address), billing contacts and transaction numbers, support conversations and server logs. No campaign data.
See the full tableHosting
Our licensing server runs in Microsoft Azure data centers in Europe. The website and add-in files are served by Cloudflare Pages.
See hosting and providersAssurance
We have no SOC 2 report or ISO 27001 certification of our own. Cloudflare, which hosts our website and add-in, is ISO 27001 certified and has a SOC 2 Type II attestation.
See compliance and contractsDocuments and guides
- Security overview
How the add-in works, the data we process, our providers and the controls we apply.
- Where your data goes
A plain-language walk through the path your campaign data takes.
- Microsoft 365 permissions
Each permission the add-in requests and what it is used for.
- Firewall requirements
The one required host, the two optional ones, and which can be blocked.
- Data Processing Addendum
Our standard DPA and how to request a signed copy.
- DPA template (PDF)
Download the standard Data Processing Addendum template.
- Privacy Policy
What we collect, why, and how long we keep it.
- Providers and subprocessors
The services that process personal data on our behalf, and the other providers we use.
- Deploy to your organization
How Microsoft 365 admins deploy the add-in to users, groups or everyone.
- Microsoft Publisher Attestation
Our self-reported questionnaire, published by Microsoft. It is not a Microsoft security review.
Frequently asked questions
Are you SOC 2 or ISO 27001 certified?
Does recipient or message data leave our Microsoft 365 tenant?
What data do you store about us, and for how long?
Where is our data hosted?
Who are your subprocessors?
Why does Microsoft warn that the add-in "can send your data to the internet"?
Can we block analytics and error reporting?
www.securemailmerge.com is required. The analytics host (analytics.solinventum.com) and Sentry are optional and can be blocked at the firewall without affecting the add-in. The license management portal (licensing.solinventum.com) is only needed by the people who manage your licenses. See the firewall requirements.Can we control who in our organization uses it?
Do you sign a Data Processing Addendum?
Will you notify us of a data breach?
Will you complete our security questionnaire?
Is SecureMailMerge Microsoft 365 Certified?
How do we report a security issue?
Contact us
Send security questions, vulnerability reports and requests for a signed DPA to our team.
[email protected]