Skip to content

/ Legal

Data Processing Agreement.

When a customer processes personal data through our infrastructure, a Data Processing Agreement spells out how we handle that data on their behalf. Here's what it covers, how it's executed, and the obligations on each side.

Last updated: 2026-05-25

01 — What this is

A Data Processing Agreement is a contract between a data controller (our customer) and a data processor (us) that sets out how the processor will handle personal data on the controller's behalf. Under GDPR-style regimes, controllers are required to put a contract of this kind in place before letting a processor handle personal data — and as customers who are themselves controllers will appreciate, the substance of the contract matters a lot more than the existence of one.

Our DPA is designed to satisfy GDPR Article 28 expectations and the equivalent provisions of comparable regimes (UK GDPR, Swiss FADP, Brazil's LGPD, and others), so customers can use it as the processor agreement for processing under those laws without needing bespoke addenda for each one.

02 — When it applies

The DPA forms part of the service agreement for every customer whose mail includes personal data of individuals — which, for practical purposes, means essentially every B2C and most B2B senders. It is executed alongside the main service contract at the start of the engagement.

For customers whose sending genuinely involves no personal data (a narrow case), the DPA still sits in the contract stack but is effectively dormant. The bar for "no personal data" is genuinely high; if you think you might qualify, raise it during scoping.

03 — Scope of processing

The DPA specifies, for each customer engagement, the subject matter and duration of processing, the nature and purpose, the categories of data subjects (typically the customer's own recipients), and the types of personal data involved (typically email addresses, names where supplied, engagement metadata, and message content in transit).

We process this data only on the documented instructions of the customer, only for the purpose of delivering the agreed service, and only for as long as the engagement requires.

04 — Our obligations as processor

We process personal data only on the customer's instructions, except where required by law to do otherwise (and in that case we tell the customer first, unless the law forbids it). We ensure that personnel authorized to process the data are bound by confidentiality. We implement appropriate technical and organizational security measures (see Security, below). We assist the customer in responding to data-subject rights requests. We assist the customer in meeting their obligations around security, breach notification, impact assessments, and prior consultations with supervisory authorities, to the extent the customer needs that support and we're positioned to provide it.

At the end of the engagement, we return or delete personal data as the customer instructs, except where retention is required by applicable law.

05 — Sub-processors

The customer authorizes us to engage sub-processors to operate the service. A current list of sub-processors is provided on request and to active customers. We bind sub-processors to substantively equivalent data-protection obligations and remain responsible to the customer for sub-processor performance.

We notify customers in advance of material changes to the sub-processor list, with a window during which the customer can object on reasonable grounds. If we cannot accommodate a reasonable objection, the customer may terminate the affected services without penalty.

06 — Cross-border transfers

Where personal data crosses borders, we rely on appropriate transfer mechanisms — typically the EU Standard Contractual Clauses or their equivalents under other regimes — and implement supplementary measures where required. Customers who need EU-only termination can architect the engagement that way during scoping, which is the cleanest way to avoid cross-border transfer questions for personal data originating in the EU.

07 — Security measures

The DPA incorporates by reference the technical and organizational measures detailed on our security page, including encryption in transit, access controls, logging and monitoring, personnel security, and incident response. These measures evolve as the threat landscape and the service evolve; the DPA commits us to maintaining protections appropriate to the risk.

08 — Data-subject rights

When a customer's recipient exercises a right (access, deletion, correction, portability, restriction), the customer is the primary respondent because they're the controller. We assist by providing the technical means to fulfill the request — extracting or deleting the relevant data from our systems on the customer's instruction — within the timeframes the applicable law requires.

If a data subject contacts us directly about data we hold as a processor, we refer them to the relevant customer and notify the customer promptly.

09 — Personal data breaches

We notify customers without undue delay after becoming aware of a personal data breach affecting their data, with the information needed for the customer to meet their own notification obligations to supervisory authorities and data subjects. We cooperate with the customer in investigating, mitigating, and documenting the incident.

Notification is operational, not legalistic — the goal is to give the customer the information they need to act, in the format and within the timeframes that match the regulatory clock they're on.

10 — How to execute the DPA

For customers entering a new engagement, the DPA is included in the service contract pack signed at the start of the relationship. No separate execution step is required.

For existing customers who need to update their DPA, or prospects who want to review the document before committing, contact legal@emaildeliveryplatform.com and we'll provide the current text and any addenda your jurisdiction requires.