Hi there @saraolesen,
We do follow GDPR rules. Your subscriber’s list is stored on your website’s database only, along with any information they fill in when subscribing through your forms. I can confirm we do not store or keep any data from your subscribers.
However, if you’re sending with us, we do process all the emails to be sent via a sending server located in Germany. It means MailPoet only logs email addresses to ensure that our service runs effectively. We track nothing else.
Data at MailPoet is not shared with or sold to any third party, not even Amazon S3. Also, after 3 months, all the data and stats are deleted from our system.
Regarding any other data that could be shared or accessed by Automattic, it’s part of the DPA that we will not: (a) collect, retain, use, disclose or otherwise process the Controller Data for any purpose other than as necessary for the specific purpose of performing the services on behalf of the User; (b) collect, retain, use or disclose the Controller Data for a commercial purpose other than providing the services on behalf of the User; or (c) sell the Controller Data.
You can see more details here:
https://kb.mailpoet.com/article/303-is-mailpoet-gdpr-compliant