Data Processing Agreement
Last updated:
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (“Controller”) and [OPERATOR NAME, ADDRESS, ID] (“Processor”) and applies whenever the Processor processes personal data on behalf of the Controller through Frontmail.
1. Subject matter and duration
The Processor processes personal data to deliver email messages, store message history, manage contacts and suppression lists, and provide statistics, for as long as the Controller uses the Service.
2. Nature of processing
| Item | Description |
|---|---|
| Data subjects | recipients and senders of messages (e.g. website visitors submitting forms), contacts, team members |
| Data categories | email addresses, names and any other data the Controller includes in template parameters or attachments; delivery events (delivered, bounced, opened, clicked); IP address and user agent of form submissions |
| Special categories | not intended; the Controller must not send special category data unless adequately protected and agreed in writing |
| Processing operations | receiving, validating, rendering, storing, transmitting to the Controller’s email provider, logging, deleting |
3. Processor obligations
The Processor will:
- process personal data only on documented instructions of the Controller, including the configuration made in the dashboard and API;
- ensure that persons authorised to process data are bound by confidentiality;
- implement appropriate technical and organisational measures (Annex 1);
- assist the Controller with data subject requests, security, breach notification and data protection impact assessments;
- notify the Controller of a personal data breach without undue delay and in any case within [48] hours of becoming aware of it;
- delete or return all personal data at the end of the Service, unless storage is required by law;
- make available information necessary to demonstrate compliance and allow audits [audit procedure to be defined].
4. Sub-processors
The Controller gives general authorisation to engage the sub-processors listed below. The Processor will inform the Controller of intended changes at least [30] days in advance; the Controller may object on reasonable grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | hosting, storage, queueing, encryption keys | EU (Frankfurt) |
| Cloudflare, Inc. | DNS, bot protection (Turnstile) | global, SCCs |
| Google Cloud EMEA Ltd. | usage analytics (BigQuery) | [REGION TO CONFIRM] |
| Stripe Payments Europe, Ltd. | billing (Controller’s billing data only) | EU / US, SCCs |
The email providers connected by the Controller (for example Gmail, Mailgun or an SMTP server) are chosen and contracted by the Controller and are not sub-processors of the Processor.
5. International transfers
Transfers outside the EEA take place only under an adequacy decision or Standard Contractual Clauses with supplementary measures where required.
Annex 1 – Technical and organisational measures
- Encryption in transit (TLS 1.2+) and at rest; provider credentials encrypted with per-record data keys (AWS KMS envelope encryption).
- Least-privilege access, multi-factor authentication for staff, audit logging of sensitive actions.
- Separated production and development environments; backups with point-in-time recovery in production.
- Retention limits per plan; automatic deletion of expired message content.
- Rate limiting, bot protection and anomaly detection to prevent abuse.
[Signature block / click-through acceptance mechanism to be defined.]