[{"data":1,"prerenderedAt":332},["ShallowReactive",2],{"legal-\u002Fdpa":3},{"id":4,"title":5,"body":6,"description":323,"extension":324,"meta":325,"navigation":326,"path":327,"seo":328,"stem":329,"updated":330,"__hash__":331},"legal\u002Fdpa.md","Data Processing Agreement",{"type":7,"value":8,"toc":305},"minimark",[9,29,32,37,40,44,68,72,75,79,86,90,113,117,120,134,138,145,149,164,168,175,179,188,192,199,202,206,212,218,224,230,236,242,246,252,258,264,270,276,282,288,294,298],[10,11,12,13,18,19,23,24,28],"p",{},"This Data Processing Agreement (\"DPA\") forms part of the ",[14,15,17],"a",{"href":16},"\u002Fterms","Terms of Service"," between ",[20,21,22],"strong",{},"Epostix"," (\"Processor\", \"we\") and the Customer (\"Controller\", \"you\") and applies automatically to every customer — no signature is required. If you need a countersigned copy for your records, email ",[14,25,27],{"href":26},"mailto:legal@epostix.com","legal@epostix.com"," and we will execute one.",[10,30,31],{},"It governs all processing of personal data contained in Customer Content that we carry out on your behalf, as required by Article 28(3) GDPR. In case of conflict, this DPA prevails over the Terms for data protection matters.",[33,34,36],"h2",{"id":35},"_1-definitions","1. Definitions",[10,38,39],{},"\"GDPR\" means Regulation (EU) 2016\u002F679; \"personal data\", \"processing\", \"controller\", \"processor\", \"data subject\", \"personal data breach\", and \"supervisory authority\" have the meanings given there. \"Customer Content\" means the data you submit to the Service for sending and audience management, as defined in the Terms. Where you act as a processor for your own clients, you warrant that you are authorised to engage us as a sub-processor and that your instructions reflect your controller's instructions; references to \"Controller\" then apply to you accordingly.",[33,41,43],{"id":42},"_2-subject-matter-roles-and-instructions","2. Subject matter, roles, and instructions",[45,46,47,55,62,65],"ul",{},[48,49,50,51,54],"li",{},"You are the controller of personal data in Customer Content; we process it exclusively on your behalf. The details of processing are set out in ",[20,52,53],{},"Annex 1",".",[48,56,57,58,61],{},"We process Customer Content only on your ",[20,59,60],{},"documented instructions",", including regarding transfers to third countries, unless required to do otherwise by EU or member-state law — in which case we inform you of that legal requirement before processing, unless the law prohibits it. Your instructions are: the Terms, this DPA, your configuration of the Service, and your use of its APIs. Additional instructions must be agreed in writing.",[48,63,64],{},"We will inform you without delay if, in our opinion, an instruction infringes the GDPR or other applicable data protection law.",[48,66,67],{},"We do not use Customer Content for our own purposes. Aggregate operational signals (bounce, complaint, and block rates) are processed to enforce sending thresholds as part of providing the Service.",[33,69,71],{"id":70},"_3-confidentiality","3. Confidentiality",[10,73,74],{},"Persons authorised to process Customer Content are bound by confidentiality obligations (contractual or statutory) and process it only as needed to perform their role. Access is limited to what each role requires.",[33,76,78],{"id":77},"_4-security-art-32","4. Security (Art. 32)",[10,80,81,82,85],{},"We implement and maintain the technical and organisational measures described in ",[20,83,84],{},"Annex 2",", taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. We may update Annex 2 as technology evolves, provided the changes do not materially reduce the level of protection.",[33,87,89],{"id":88},"_5-sub-processors","5. Sub-processors",[45,91,92,103,110],{},[48,93,94,95,98,99,102],{},"You grant a ",[20,96,97],{},"general written authorisation"," to engage the sub-processors listed at ",[14,100,101],{"href":101},"\u002Fsubprocessors",", which shows, for each: identity, purpose, location, and transfer mechanism.",[48,104,105,106,109],{},"We will give you at least ",[20,107,108],{},"30 days' notice"," by email to account owners before adding or replacing a sub-processor. You may object in writing on reasonable data protection grounds within that period; if we cannot offer a workaround, you may terminate the affected services and we refund prepaid fees for the period after termination pro rata.",[48,111,112],{},"We impose on every sub-processor, by written contract, data protection obligations materially equivalent to this DPA, and we remain fully liable to you for their performance.",[33,114,116],{"id":115},"_6-assistance","6. Assistance",[10,118,119],{},"Taking into account the nature of the processing, we assist you:",[45,121,122,128],{},[48,123,124,127],{},[20,125,126],{},"with data subject rights"," (Arts. 15–22): the Service provides suppression, export, and deletion tooling; requests reaching us directly that identify your sending are forwarded to you without undue delay, and we do not respond on your behalf beyond confirming you are the controller;",[48,129,130,133],{},[20,131,132],{},"with security, breach notification, DPIAs, and prior consultation"," (Arts. 32–36), by providing the information reasonably available to us. Assistance beyond what the Service already provides may be charged at reasonable cost where your requests are excessive or repetitive.",[33,135,137],{"id":136},"_7-personal-data-breach","7. Personal data breach",[10,139,140,141,144],{},"We notify you ",[20,142,143],{},"without undue delay, and in any event within 48 hours",", after becoming aware of a personal data breach affecting Customer Content, with the information required by Art. 33(3) GDPR to the extent available (nature of the breach, categories and approximate numbers affected, likely consequences, measures taken), supplementing it as investigation proceeds. Notification is not an admission of fault.",[33,146,148],{"id":147},"_8-deletion-and-return","8. Deletion and return",[45,150,151,154,161],{},[48,152,153],{},"During the term you can export and delete Customer Content at any time via the dashboard and API.",[48,155,156,157,160],{},"On termination of the agreement, we ",[20,158,159],{},"delete all Customer Content within 30 days",", and purge it from encrypted backups within a further 60 days, unless EU or member-state law requires continued storage. On request made within those 30 days, we first return the data in a structured, commonly used, machine-readable format, and we confirm deletion in writing on request.",[48,162,163],{},"Suppression records may be retained in hashed form where needed to keep honouring recipients' opt-outs.",[33,165,167],{"id":166},"_9-audits","9. Audits",[10,169,170,171,174],{},"On request, we make available the information necessary to demonstrate compliance with Art. 28 GDPR — including Annex 2, sub-processor agreements' relevant terms, and available third-party attestations of our infrastructure providers. Where that is insufficient, you (or an independent auditor you mandate, not a competitor of ours) may audit our processing ",[20,172,173],{},"once in any 12-month period",", on at least 30 days' written notice, during business hours, under confidentiality, without access to other customers' data, and at your cost. Where an audit reveals material non-compliance, we remediate at our cost.",[33,176,178],{"id":177},"_10-international-transfers","10. International transfers",[10,180,181,182,185,186,54],{},"Customer Content is stored and processed in the ",[20,183,184],{},"EU"," (Hetzner data centres in Germany and Finland). We will not transfer Customer Content outside the EU\u002FEEA except: on your instructions; where the destination benefits from an adequacy decision; or under appropriate safeguards pursuant to Art. 46 GDPR — and in every case subject to the sub-processor notice mechanism in Section 5. Ancillary sub-processors with third-country elements, and their transfer mechanisms, are identified at ",[14,187,101],{"href":101},[33,189,191],{"id":190},"_11-liability-term-and-law","11. Liability, term, and law",[10,193,194,195,198],{},"Liability under this DPA is subject to the limitations in the ",[14,196,197],{"href":16},"Terms",", except where the GDPR mandates otherwise (Art. 82). This DPA takes effect with the agreement and remains in force until all Customer Content is deleted under Section 8. Governing law and venue follow the Terms.",[200,201],"hr",{},[33,203,205],{"id":204},"annex-1-details-of-processing","Annex 1 — Details of processing",[10,207,208,211],{},[20,209,210],{},"Subject matter."," Sending, receiving-related handling (bounces, complaints), storage, and management of email and audience data through the Epostix platform.",[10,213,214,217],{},[20,215,216],{},"Duration."," The term of the agreement, plus the deletion periods in Section 8.",[10,219,220,223],{},[20,221,222],{},"Nature and purpose."," Transmission of email to recipients designated by the Controller; management of contact lists, segments, and suppression; collection of delivery and engagement events; provision of analytics on the foregoing.",[10,225,226,229],{},[20,227,228],{},"Categories of data subjects."," Recipients and intended recipients of the Controller's email: customers, users, subscribers, players (for licensed gambling senders), employees, and other contacts of the Controller.",[10,231,232,235],{},[20,233,234],{},"Categories of personal data."," Email addresses; names and salutations; message content and any personal data the Controller includes in it (including template variables); IP addresses and technical metadata of recipient interactions; delivery, open, click, bounce, complaint, and unsubscribe events; consent and suppression records.",[10,237,238,241],{},[20,239,240],{},"Special categories (Art. 9)."," The Service is not intended for special-category data. The Controller instructs that none be included in Customer Content unless the Controller has a valid Art. 9 basis and has agreed the use with us in writing.",[33,243,245],{"id":244},"annex-2-technical-and-organisational-measures-art-32","Annex 2 — Technical and organisational measures (Art. 32)",[10,247,248,251],{},[20,249,250],{},"Hosting and physical security."," All Customer Content is hosted in ISO 27001-certified data centres in Germany and Finland (Hetzner); physical access controls are operated by the data-centre provider.",[10,253,254,257],{},[20,255,256],{},"Encryption."," TLS 1.2+ for data in transit (API, SMTP submission, dashboard); opportunistic TLS for outbound delivery; encryption at rest for storage volumes and backups.",[10,259,260,263],{},[20,261,262],{},"Access control."," Role-based access on least-privilege principles; personal accounts with strong authentication for administrative access; secrets and credentials managed in a dedicated vault with audited access; administrative actions logged.",[10,265,266,269],{},[20,267,268],{},"Separation."," Logical tenant separation throughout the platform; per-customer sending domains and authentication; dedicated, isolated IP allocations per brand for reviewed sender categories.",[10,271,272,275],{},[20,273,274],{},"Availability and resilience."," Redundant infrastructure; encrypted backups stored in the EU with regular restore testing; capacity monitoring; DDoS mitigation at the network edge.",[10,277,278,281],{},[20,279,280],{},"Operations."," Centralised logging and monitoring with alerting; vulnerability management and timely patching; change management with peer review; incident-response procedure covering detection, escalation, containment, and customer notification.",[10,283,284,287],{},[20,285,286],{},"Personnel."," Confidentiality undertakings; access revoked on role change or departure; data protection awareness as part of onboarding.",[10,289,290,293],{},[20,291,292],{},"Data minimisation and lifecycle."," Retention limits on operational logs; deletion and export tooling exposed to the Controller; suppression enforcement at the platform level.",[33,295,297],{"id":296},"annex-3-authorised-sub-processors","Annex 3 — Authorised sub-processors",[10,299,300,301,304],{},"The current list, including purpose, location, and transfer mechanism for each sub-processor, is maintained at ",[14,302,303],{"href":101},"epostix.com\u002Fsubprocessors"," and forms part of this DPA.",{"title":306,"searchDepth":307,"depth":307,"links":308},"",2,[309,310,311,312,313,314,315,316,317,318,319,320,321,322],{"id":35,"depth":307,"text":36},{"id":42,"depth":307,"text":43},{"id":70,"depth":307,"text":71},{"id":77,"depth":307,"text":78},{"id":88,"depth":307,"text":89},{"id":115,"depth":307,"text":116},{"id":136,"depth":307,"text":137},{"id":147,"depth":307,"text":148},{"id":166,"depth":307,"text":167},{"id":177,"depth":307,"text":178},{"id":190,"depth":307,"text":191},{"id":204,"depth":307,"text":205},{"id":244,"depth":307,"text":245},{"id":296,"depth":307,"text":297},"The Art. 28 GDPR agreement under which Epostix processes personal data in Customer Content as processor on the customer's behalf — including security measures, sub-processors, and deletion.","md",{},true,"\u002Fdpa",{"title":5,"description":323},"dpa","2026-08-17","dtXDe_FMLpGcWy-jpP9SadnMVg5m6bOj4oIqEZu0TVs",1787001450046]