Data Processing Agreement
Last updated:
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Mailtr.co ("Mailtr", "we", "us") and the customer ("you") and applies whenever we process personal data on your behalf in providing the Service. Where this DPA conflicts with the Terms of Service on the subject of data protection, this DPA prevails.
1. Definitions
Terms such as "personal data", "processing", "data controller", "data processor", "data subject", "sub-processor", and "personal data breach" have the meanings given to them in the applicable data protection law — including the EU General Data Protection Regulation ("GDPR") and the India Digital Personal Data Protection Act 2023 ("DPDP Act"). "Customer Personal Data" means personal data contained in the content, contacts, and recipient lists you submit to or generate through the Service.
2. Roles of the Parties
For Customer Personal Data, you are the data controller (or, where you act on another party's behalf, the processor) and Mailtr is the data processor. You determine the purposes and means of processing; we process only to provide the Service and on your instructions. Each party is responsible for complying with the obligations that apply to it in its role.
For data about your own account, billing, and use of the Service, Mailtr acts as a controller; that processing is described in our Privacy Policy and is outside the scope of this DPA.
3. Scope and Details of Processing
The subject matter, nature, and purpose of the processing is the provision of the Service — the sending, delivery, tracking (where you enable it), and management of email you send to your recipients. The duration is the term of your use of the Service. These details are set out in Annex I below.
4. Processing on Your Instructions
We process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to us — in which case we will inform you of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. Your instructions are given through your use and configuration of the Service and through this DPA and the Terms of Service. We will inform you if, in our opinion, an instruction infringes applicable data protection law.
5. Confidentiality
We ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and process it only as necessary to provide the Service.
6. Security Measures
We implement appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art and the risks of the processing. These measures are described in Annex II and are reviewed and updated as the Service evolves.
7. Sub-processors
You provide general authorisation for us to engage sub-processors to process Customer Personal Data in providing the Service. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for a sub-processor's performance of those obligations.
Our current sub-processors are:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Contabo GmbH | Cloud hosting — application servers, database, object storage, and mail server | India (data centre); Germany (company) |
| Razorpay Software Private Limited | Payment processing for paid subscriptions | India |
| Google LLC (Gemini API) | AI-assisted email content features | United States |
| 2Factor (Adiptae Solutions Pvt. Ltd.) | SMS and one-time-passcode delivery | India |
Outbound email delivery and object storage run on Mailtr's own infrastructure and are not delegated to a third party. We will give at least 14 days' notice before adding or replacing a sub-processor, during which you may object on reasonable data-protection grounds; if we cannot address your objection, you may terminate the affected part of the Service.
8. Assistance with Data Subject Requests
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects to exercise their rights of access, rectification, erasure, restriction, portability, and objection. Where a data subject contacts us directly about Customer Personal Data, we will refer them to you rather than respond on your behalf, unless legally required to do otherwise.
9. Assistance with Compliance
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations relating to security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with supervisory authorities.
10. Personal Data Breach Notification
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide you with the information reasonably available to us to help you meet your own notification obligations to authorities and data subjects. Our notification is not an acknowledgement of fault or liability.
11. International Transfers
We are based in India and, as set out in Annex I and the sub-processor table above, Customer Personal Data is currently processed in India. India has not received an adequacy decision from the European Commission. Where you are established in the European Economic Area or the United Kingdom, or are otherwise subject to transfer restrictions, our processing of Customer Personal Data therefore constitutes a restricted transfer.
For such transfers, the European Commission's Standard Contractual Clauses (Module Two: controller to processor), together with the UK International Data Transfer Addendum where applicable, are incorporated into and form part of this DPA, with the Annexes below completing their appendices. We maintain supplementary measures appropriate to the transfer and can provide information about the legal framework applicable to government access to data in India on request.
We are introducing a European data-residency option for customers who require Customer Personal Data to remain in the European Economic Area. When available for your account, the applicable processing location will be reflected in your account and in the sub-processor table above.
12. Deletion and Return
On termination of the Service, and at your choice, we delete or return all Customer Personal Data and delete existing copies, unless we are required by law to retain some of it. Data in routine backups is overwritten on our standard backup cycle. Addresses retained on suppression or unsubscribe lists are kept for the sole purpose of honouring an opt-out, as permitted and required by law.
13. Audit and Compliance
We make available to you the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and no more than once a year (unless required by a supervisory authority or following a personal data breach), allow for and contribute to audits conducted by you or an auditor you mandate. To minimise disruption, we may satisfy an audit request by providing relevant certifications, reports, or a written response to your questionnaire where these reasonably address your request.
14. Liability and Term
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Personal Data on your behalf.
15. Annex I — Details of Processing
- Categories of data subjects: your contacts and the recipients of email you send through the Service.
- Categories of personal data: recipient email addresses and names, other contact fields you add, message content you create, and engagement data (such as opens and clicks) where you enable tracking.
- Special categories of data: not intended to be processed; you should not submit special-category data unless you have ensured an appropriate lawful basis and safeguards.
- Nature and purpose: hosting, sending, delivery, tracking (where enabled), suppression, and management of your email.
- Duration: the term of your use of the Service, then deletion or return in accordance with Section 12.
16. Annex II — Technical and Organisational Measures
- Encryption of data in transit, and of data at rest where supported.
- Hashing of account passwords and secure storage of credentials.
- Access controls and least-privilege access to production systems and data.
- Audit logging of significant account and administrative activity.
- Network protections, including rate limiting and abuse detection on sending.
- Regular backups and documented restoration procedures.
- Contractual data-protection obligations imposed on all sub-processors.
17. Contact
Questions about this DPA, or requests for a countersigned copy, should be sent to grievance@mailtr.co.