This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer", acting as data Controller) and Facturama Limited, trading as MailStruck (acting as data Processor), and governs the processing of personal data that you upload to or generate through the Service (the "Customer Personal Data"). It is designed to meet the requirements of Article 28 of the UK GDPR and the EU GDPR.
1. Roles and scope
The Customer is the Controller and MailStruck is the Processor of the Customer Personal Data. MailStruck will process Customer Personal Data only on your documented instructions (including as set out in the Terms and this DPA), for the sole purpose of providing the Service, and for the duration of your account.
- Subject matter: the provision of an email marketing and automation platform.
- Nature and purpose: storing contacts, sending campaigns and automations, and reporting on engagement.
- Categories of data subjects: your subscribers, contacts, and recipients.
- Categories of personal data: email addresses, names, company, and any custom fields you choose to upload, plus engagement metadata (opens, clicks, bounces, unsubscribes).
2. Processor obligations
- Process Customer Personal Data only on your documented instructions, unless required to do otherwise by law (in which case we will inform you, unless legally prohibited).
- Ensure that personnel authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational measures (see section 4).
- Assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your obligations regarding security, breach notification, and data protection impact assessments.
- At your choice, delete or return all Customer Personal Data after the end of the provision of the Service, and delete existing copies unless retention is required by law.
- Make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits (see section 6).
3. Sub-processors
You provide general authorization for MailStruck to engage sub-processors to provide the Service. A current list is available at our Sub-Processor List. We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain liable for their performance. We will give you reasonable notice of any intended changes to sub-processors so that you may object on reasonable data-protection grounds.
4. Security measures
MailStruck maintains appropriate technical and organizational measures to protect Customer Personal Data, including: encryption of data in transit (TLS) and at rest; access controls and least-privilege permissions; network and application-level safeguards; automated suppression of bounces and complaints; and regular patching and monitoring. See our Privacy Policy for further detail.
5. Personal data breach
MailStruck will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist you in meeting your notification obligations to supervisory authorities and data subjects.
6. Audits
Upon reasonable written request, and no more than once per year (unless required by a supervisory authority), MailStruck will make available information necessary to demonstrate compliance with this DPA. Audits must be conducted during business hours, with reasonable notice, and subject to confidentiality.
7. International transfers
Where processing involves a transfer of Customer Personal Data outside the UK or EEA, such transfers are made subject to appropriate safeguards, including the UK International Data Transfer Agreement (IDTA) / Addendum or the EU Standard Contractual Clauses (SCCs), which are incorporated into this DPA by reference.
8. Term and deletion
This DPA remains in effect for as long as MailStruck processes Customer Personal Data on your behalf. On termination, we will delete Customer Personal Data as described in our Privacy Policy, retaining only minimal suppression data (hashed email addresses) required to honor opt-outs, or as required by law.
To request a countersigned copy of this DPA, contact info@mailstruck.com.