Data Processing Addendum

Last updated September 2, 2026

This addendum forms part of the Terms of Service and governs our processing of personal data contained in your contact lists. It is designed to satisfy Article 28(3) of the GDPR and applies automatically — you do not need to request or sign a separate copy.

In this document, you are the controller and we are the processor. Where you are yourself a processor acting for your own customer, we are the sub-processor and these terms flow down.

1Subject matter and duration

The subject matter is the provision of email sending, contact storage, and delivery reporting under the Terms of Service. Processing lasts for the term of your account plus the deletion window in section 9.

2Nature and purpose of processing

Storage, retrieval, transmission, and deletion of contact data for the purpose of delivering the messages you instruct us to send, recording the outcome of those deliveries, maintaining suppression lists, and detecting abuse of the platform.

3Categories of data subject and personal data

Data subjects: the recipients of your email — your customers, subscribers, users, or prospects.

Personal data: email addresses, names where you supply them, any custom fields you choose to upload, subscription status, and delivery event records including opens, clicks, bounces, and complaints.

You must not upload special category data under Article 9 — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or sex life or orientation — as a custom field. The service is not designed for it and we do not apply the additional safeguards such data requires.

4Our obligations

We will:

  • Process personal data only on your documented instructions, which the Terms and your use of the service constitute. If we believe an instruction breaches data protection law, we will tell you.
  • Ensure personnel authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures described in section 6.
  • Respect the conditions in section 7 for engaging sub-processors.
  • Assist you, insofar as possible and taking into account the nature of the processing, in responding to data subject requests.
  • Assist you with data protection impact assessments and prior consultations where Articles 32 to 36 require them.
  • Delete or return the data at your choice when processing ends, subject to section 9.
  • Make available the information necessary to demonstrate compliance and allow for audits as described in section 8.

5Your obligations

  • You warrant that you have a valid lawful basis for holding each contact and for the mail you send them.
  • You are responsible for the accuracy and legality of the data you upload and for giving data subjects the privacy information their jurisdiction requires.
  • You must not instruct us to process data in a way that breaches data protection law.
  • You must configure the service appropriately, including honouring the consent record on each audience.

6Security measures

Taking into account the state of the art, cost, and the risks to data subjects, we implement:

  • Encryption of personal data in transit using TLS, and encryption at rest for the database.
  • Logical isolation of each customer's data, with every application query scoped to a single organization, and isolation of each customer's sending reputation in a separate upstream tenant.
  • Credential handling that does not store recoverable secrets: passwords as salted hashes, API keys as SHA-256 digests.
  • Role-based access control over production data, restricted to personnel with an operational need, with access logged.
  • An append-only audit log recording who did what, including actions taken via the AI assistant.
  • Regular backups with defined retention, and the ability to restore availability after an incident.
  • Vulnerability patching of dependencies and infrastructure on a regular cadence.

7Sub-processors

You give general authorisation for us to engage sub-processors. The current list, including what each receives and where it is located, is at /subprocessors.

We will give at least 30 days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot address your objection, you may terminate the affected part of the service and receive a prorated refund of prepaid fees.

Each sub-processor is bound by written terms imposing obligations no less protective than these, and we remain fully liable to you for their performance.

8Audit

On reasonable written notice, no more than once in any twelve-month period unless a supervisory authority requires otherwise, we will provide the information necessary to demonstrate compliance with this addendum.

Where you require an on-site audit, it must be conducted during business hours, must not unreasonably disrupt operations, must be subject to confidentiality, and is at your cost.

9Deletion and return

You can delete contacts, audiences, and message content at any time from the application or the API. On termination you may export your data for 30 days, after which we delete it, including from backups on their normal expiry cycle.

Two exceptions. We retain suppression records — an address, a reason, and a date — indefinitely, so that a person who unsubscribed is never mailed again if a list is re-imported or an account reactivated. We also retain records that tax, accounting, or anti-fraud law requires us to keep. Both are the minimum necessary and are not used for any other purpose.

10Personal data breach

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

Notification is not an acknowledgement of fault. Where information is not available at the time, we will provide it in phases as it becomes available.

11International transfers

Where we transfer personal data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 are incorporated into this addendum by reference, with Module Two (controller to processor) or Module Three (processor to processor) applying as appropriate.

For UK transfers, the ICO's International Data Transfer Addendum applies. For Swiss transfers, references to the GDPR are read as references to the FADP and the competent authority is the FDPIC.

We conduct transfer impact assessments for each such transfer. The AI model provider transfer is separately disclosed on the sub-processor page and can be eliminated by disabling the assistant.

12Order of precedence

If this addendum conflicts with the Terms of Service, this addendum governs for matters of data protection. If it conflicts with the Standard Contractual Clauses, the Clauses govern.

13Contact

Data protection enquiries, including requests for a countersigned copy: privacy@www.sendkernel.com