1. When this applies
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SentientMail, Inc. ("Processor", "we") and the customer identified in the account ("Controller", "you").
It applies automatically, with no signature needed, wherever you use the Service to process personal data protected by the EU GDPR, the UK GDPR, the Swiss FADP, or another law imposing comparable processor obligations. Where this DPA conflicts with the Terms of Service on a question of personal-data processing, this DPA prevails.
If your procurement process requires a countersigned copy, request one at legal@sentientmail.com and we will return it executed. We do not require you to negotiate it first.
2. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" have the meanings given in the GDPR. "Customer Personal Data" means personal data contained in Your Content that we process on your behalf. "Subprocessor" means a third party we engage to process Customer Personal Data. "Data Protection Law" means every privacy and data protection law applicable to the processing.
3. Roles of the parties
For Customer Personal Data, you are the Controller and we are the Processor. You determine the purposes and means; we act only on your instructions.
You are responsible for the lawfulness of the data you put into the Service: for having a lawful basis to hold and mail each contact, for the notices and consents your own privacy policy requires, and for the accuracy of what you upload. We have no direct relationship with your contacts and no way to verify their consent.
We act as a Controller for account, billing, and security data relating to your users, described in our Privacy Policy. That processing is outside this DPA.
4. Processing on your instructions
We process Customer Personal Data only on your documented instructions, which consist of this DPA, the Terms of Service, and your use of the Service's features. We will not process it for any other purpose.
In particular, and for the avoidance of doubt, we will not:
- sell, rent, or otherwise disclose Customer Personal Data to a third party except as this DPA permits;
- use it to build profiles, derive insights for our own purposes, or enrich our own datasets;
- use it to train, fine-tune, or evaluate any AI or machine learning model, whether ours or a third party's; or
- combine it with data from another customer or another source.
If we believe an instruction breaches Data Protection Law we will tell you promptly, and we may suspend that processing until it is resolved. If a legal requirement compels us to process beyond your instructions, we will inform you first unless that law forbids it on important grounds of public interest.
5. Confidentiality
We ensure that everyone authorized to process Customer Personal Data is bound by an appropriate duty of confidentiality that survives the end of their engagement, and that access is limited to those who need it to provide the Service or to answer your support request.
6. Security
We implement appropriate technical and organizational measures under Article 32, described in Annex B. We may update them as technology develops, provided the level of protection is not reduced.
7. Subprocessors
You give general authorization for us to engage Subprocessors. The current list is published at sentientmail.com/subprocessors.
Before a new Subprocessor begins processing Customer Personal Data we will give you at least 30 days' notice, by email to account owners who have subscribed to subprocessor notifications and by updating that page. You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and we will refund the unused portion of any prepaid fee. That is your exclusive remedy for an objection.
We impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for a Subprocessor's performance.
8. Data subject rights
The Service gives you the tools to access, correct, export, and delete Customer Personal Data yourself, which is normally the fastest route to answering a request.
Where a Data Subject contacts us directly about data we process on your behalf, we will not respond on the substance. We will tell them to contact you, and where we can identify you, notify you promptly. We will provide reasonable assistance with a request you cannot fulfil through the Service, at no charge unless the assistance is substantial and repeated.
9. Personal data breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point, to the extent that information is available. We will send further information as the investigation develops rather than delaying the first notice until everything is known.
We will assist you with your own notification obligations to supervisory authorities and data subjects. Notifying you is not an admission of fault or liability.
10. Impact assessments and audits
We will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the nature of the processing and the information available to us.
We will make available the information reasonably necessary to demonstrate compliance with Article 28. You may audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. You bear your own audit costs. Where a supervisory authority requires an audit, or where we have suffered a breach affecting your data, these frequency and notice limits do not apply.
11. International transfers
We process Customer Personal Data in the United States, except that outbound message delivery is processed on a mail server we operate in France, which handles recipient addresses and message content while a message is being sent. Where you transfer personal data from the EEA, the UK, or Switzerland to us, the transfer is made under the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, which are incorporated into this DPA by reference, on the following basis:
- Module Two (controller to processor) applies, with you as data exporter and us as data importer.
- Clause 7 (docking) applies.
- Clause 9: Option 2, general written authorization, with the 30-day notice period in section 7 above.
- Clause 11: the optional independent dispute resolution body is not selected.
- Clause 17: governed by the law of Ireland. Clause 18(b): the courts of Ireland.
- Annex I and Annex II are populated by Annex A and Annex B of this DPA; Annex III is the subprocessor list.
For UK transfers, the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0) applies to the Standard Contractual Clauses, with Tables 1 to 3 populated by this DPA and its annexes, and neither party able to terminate under Table 4. For Swiss transfers, references to the GDPR are read as references to the FADP and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
12. Return and deletion
You may export Customer Personal Data at any time while the account is active. On termination you have 30 days to export, after which we delete it from active systems within a further 30 days and from backups within 90 days, except where a law requires us to keep it. Anything retained stays subject to this DPA for as long as we hold it.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Law prohibits limiting it. Nothing in this DPA limits a data subject's rights under the Standard Contractual Clauses.
Annex A: description of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the SentientMail email marketing and transactional messaging platform. |
| Duration | The term of the Terms of Service, plus the retention periods in section 12. |
| Nature and purpose | Storing, organizing, segmenting, personalizing, rendering, transmitting, and reporting on messages the Controller sends to its own contacts. |
| Categories of data subject | The Controller's contacts, subscribers, customers, and prospects, and the Controller's own personnel who use the Service. |
| Categories of personal data | Contact identifiers (email address, name, subscriber key), any attributes the Controller chooses to upload into its data extensions, consent and subscription status, engagement events (sends, opens, clicks, bounces, complaints, unsubscribes), and message content authored by the Controller. |
| Special category data | Not intended. The Service is not designed for special category data under Article 9 or for criminal-offence data under Article 10, and the Controller should not upload it. If the Controller does, it warrants it has a lawful basis and an Article 9 condition, and remains solely responsible for that decision. |
| Frequency | Continuous, for the duration of the agreement. |
| Retention | As set out in section 12 and in the Privacy Policy. |
| Competent supervisory authority | Determined under Clause 13 of the Standard Contractual Clauses by reference to the Controller's establishment or representative in the EEA. |
Annex B: technical and organizational security measures
Access control
- Two-factor authentication available on all accounts, with idle-session timeouts.
- Role-based access control within a customer account.
- Least-privilege access for our personnel, reviewed periodically, granted only where needed to operate the Service or answer a support request.
Isolation
- Row-level security enforced in the database, so each customer's boundary is applied at the storage layer rather than by application code alone.
- Every record carries the account it belongs to, and queries are constrained to it by the database.
- Dedicated schema or database isolation available on Enterprise plans.
Encryption
- TLS for all data in transit, including to and from subprocessors.
- Encryption at rest for databases, backups, and object storage.
- Customer-supplied provider API keys encrypted separately at the application layer.
- Passwords stored only as salted hashes.
Resilience and recovery
- Managed database with automated backups and point-in-time recovery.
- Infrastructure defined as code so an environment can be rebuilt from source.
Monitoring and governance
- Audit records of security-relevant actions, capturing the actor and timestamp.
- Automated abuse monitoring on bounce and complaint rates, with automatic suspension on breach.
- Resource limits and rate limits protecting availability for all customers.
- Change review before production deployment.
Deletion
- Self-service export and deletion within the Service.
- Defined retention and purge schedules, including backup expiry.
