Draft — pending legal review. This document has not yet been reviewed by counsel and may change before Irisend is generally available.
Data Processing Agreement (DPA)
Effective date: 2026-09-25
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Irisend, registered at [to be completed: COMPANY_ADDRESS] (KVK [to be completed: KVK_NUMBER]) ("Processor", "Irisend", "we"), and the Customer identified in the applicable Irisend account ("Controller", "Customer"), and applies whenever Irisend processes Personal Data on Customer's behalf in connection with the Service (in particular, recipient/message data — "Customer Content" — as defined in the Terms of Service).
This DPA is designed to satisfy Article 28 GDPR / UK GDPR and, where applicable, the "service provider" contractual requirements of the CCPA/CPRA (Cal. Civ. Code § 1798.140(ag), § 1798.100 et seq.). Capitalized terms not defined here have the meaning given in the Terms of Service or in GDPR Art. 4.
1. Roles of the Parties
1.1. For Customer Content that constitutes Personal Data of Customer's own end users, recipients, or contacts, Customer is the Controller (or "Business" under CCPA/CPRA) and Irisend is the Processor (or "Service Provider"/"Contractor" under CCPA/CPRA). Irisend processes such Personal Data only for the purpose of providing the Service.
1.2. For account, billing, and dashboard-usage data about Customer and its authorized users, Irisend acts as an independent Controller, as described in the Irisend Privacy Policy; that processing is outside the scope of this DPA.
1.3. Where local law designates equivalent roles (e.g., "data fiduciary/processor" or similar), those roles are deemed to map to Controller/Processor as used here.
2. Subject Matter, Duration, Nature and Purpose of Processing
2.1. Subject matter: provision of the Irisend email API, SMTP relay, dashboard, and related sending/analytics functionality.
2.2. Duration: for the term of the Terms of Service, plus any post-termination retention/export period described in Section 9.
2.3. Nature and purpose: transmission, temporary storage, and delivery of email messages; delivery-event tracking (opens, clicks, bounces, complaints, unsubscribes); storage of recipient contact data and templates that Customer configures in the Service; and technical processing (e.g., abuse/spam filtering, deliverability monitoring) reasonably necessary to operate the Service.
2.4. Categories of Personal Data: recipient/contact identifiers (email address, name if provided), message content and metadata (subject, headers, body, attachments as configured by Customer), engagement/event data (delivery, open, click, bounce, complaint, unsubscribe timestamps and status), and any additional fields Customer chooses to include in message templates or contact records (e.g., custom merge fields).
2.5. Categories of Data Subjects: Customer's contacts, customers, subscribers, and other individuals to whom Customer sends email via the Service.
3. Processor Obligations (GDPR Art. 28(3))
Irisend shall:
(a) Process only on documented instructions. Process Personal Data only on Customer's documented instructions, including regarding international transfers, as set out in this DPA and the Terms of Service, unless required otherwise by EU or Member State law binding on Irisend — in which case Irisend will inform Customer of that legal requirement before processing, unless prohibited from doing so on important grounds of public interest.
(b) Confidentiality. Ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
(c) Security. Implement appropriate technical and organizational measures as required by Art. 32 GDPR, as detailed in Annex II (Technical and Organizational Measures) and the Security page.
(d) Sub-processors. Comply with Section 5 (Sub-processing) below.
(e) Assistance with data subject rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects exercising rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection). Where Irisend receives a data subject request directly regarding Customer Content, Irisend will, without undue delay, redirect the data subject to Customer and notify Customer, and will not itself respond substantively except on Customer's instruction.
(f) Assistance with Controller compliance. Assist Customer, taking into account the nature of processing and information available to Irisend, in ensuring compliance with Customer's obligations under Art. 32 (security), 33–34 (breach notification), and 35–36 (DPIAs and prior consultation) GDPR.
(g) Deletion or return. At Customer's choice, delete or return all Personal Data to Customer after the end of the provision of Services relating to processing, and delete existing copies, except to the extent EU/Member State/other applicable law requires continued storage — see Section 9.
(h) Audits and information. Make available to Customer all information reasonably necessary to demonstrate compliance with this Section 3, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to Section 8 (Audits) below. Irisend will promptly inform Customer if, in its opinion, an instruction infringes GDPR or other applicable data protection law.
4. Controller (Customer) Obligations
4.1. Customer warrants that: (a) it has, and will maintain, a valid legal basis under applicable law (e.g., consent, existing-customer soft opt-in, legitimate interest, or contractual necessity) for all Personal Data it submits to the Service and for all Messages it sends, including compliance with GDPR/ePrivacy, CAN-SPAM, CASL, the Australian Spam Act 2003, the Dutch Telecommunicatiewet, and equivalent laws in the jurisdictions of its recipients; (b) its instructions to Irisend comply with applicable law; and (c) it has provided any required notices to data subjects (e.g., privacy notice, identification of Irisend or its role, where required).
4.2. Customer is solely responsible for the accuracy, quality, and legality of Personal Data it submits and the means by which it acquired it.
5. Sub-processing
5.1. Customer grants Irisend general written authorization to engage sub-processors to support the Service, provided Irisend: (a) maintains an up-to-date list of sub-processors at Subprocessors; (b) imposes data protection obligations on each sub-processor that are no less protective than those in this DPA (Art. 28(4)); and (c) remains fully liable to Customer for the performance of each sub-processor's obligations.
5.2. Irisend will give Customer at least 14 days' advance notice of the addition or replacement of a sub-processor via the mechanism described on the Subprocessors page. Customer may object on reasonable data-protection grounds within that window by emailing legal@irisend.dev; if the parties cannot resolve the objection, Customer's exclusive remedy is to terminate the affected Service.
5.3. Current sub-processors, their processing locations, and transfer mechanisms are listed at Subprocessors, including at minimum: Amazon Web Services, Inc. (Amazon SES — email sending; AWS infrastructure — hosting), OVH SAS (application hosting), Cloudflare, Inc. (DNS/CDN/security), and Stripe, Inc. (billing, processes only Customer's own billing data, not Customer Content).
6. International Data Transfers
6.1. Irisend primarily processes Customer Content within [to be completed: AWS_REGION] / [to be completed: OVH_DATACENTER_LOCATION] (EU-based infrastructure). Where Personal Data is transferred outside the EEA/UK (e.g., to a sub-processor's US-based entity for account administration, billing, or support), the transfer is governed by:
- the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), Module Two (Controller-to-Processor) as between Customer and Irisend, and Module Three (Processor-to-Processor) as between Irisend and its sub-processors, incorporated by reference and completed as set out in Annex I–III below, satisfying both Art. 46 GDPR (transfer safeguard) and Art. 28(7) GDPR (processing-agreement content); and/or
- the UK International Data Transfer Addendum to the EU SCCs, for transfers subject to UK GDPR; and/or
- the sub-processor's own certification under the EU-U.S. Data Privacy Framework (and UK extension), where applicable and current.
6.2. Irisend will apply supplementary technical and organizational measures (e.g., encryption in transit and at rest, access minimization) to address risks associated with third-country government access, consistent with Schrems II / EDPB recommendations.
7. Security Measures
Irisend implements the technical and organizational measures described in Annex II and the Security page, including encryption in transit and at rest, access controls and logging, network protections (Cloudflare WAF/DDoS mitigation), least-privilege access to production systems, and a documented incident-response process.
8. Personal Data Breach Notification
8.1. Irisend will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Content, to enable Customer to meet its own notification obligations (e.g., the 72-hour window under Art. 33 GDPR).
8.2. The notification will describe, to the extent then known: the nature of the breach; categories and approximate number of data subjects and records affected; likely consequences; and measures taken or proposed to address the breach and mitigate its effects. Irisend will provide further information as it becomes available and will cooperate with Customer's investigation.
9. Audits
9.1. On reasonable prior written notice (at least 30 days, no more than once per 12 months absent a Personal Data Breach or regulatory requirement), Customer may request evidence of Irisend's compliance with this DPA, which Irisend will provide via: (a) a written summary of technical and organizational measures; (b) responses to a reasonable security questionnaire; and/or (c) where Irisend holds a relevant third-party audit report or certification (e.g., SOC 2), a copy under NDA, in lieu of an on-site audit.
9.2. If the above is insufficient to satisfy a binding regulatory or contractual audit requirement, Customer may conduct an on-site or remote audit during business hours, with reasonable advance notice, at Customer's expense, subject to confidentiality and without disrupting Irisend's operations or other customers' data.
10. Deletion / Return of Data
10.1. Upon termination of the Service, Customer may export Customer Content for 30 days. After that period (or earlier at Customer's request), Irisend will delete or anonymize Customer Content, except copies retained: (a) in encrypted backups until the routine backup-rotation cycle overwrites them (no longer than 90 days); or (b) as required by applicable law (e.g., financial/tax records).
11. CCPA/CPRA Terms (Where Applicable)
Where Irisend processes Personal Information (as defined under CCPA/CPRA) as a Service Provider on Customer's behalf, Irisend certifies it will not: (a) sell or share such Personal Information; (b) retain, use, or disclose it for any purpose other than providing the Service specified in the Terms of Service, including not combining it with Personal Information received from other sources except as permitted by CCPA/CPRA; or (c) retain, use, or disclose it outside the direct business relationship between Irisend and Customer. Irisend will notify Customer if it determines it can no longer meet its CCPA/CPRA obligations.
12. Liability
Liability arising out of this DPA is subject to the limitations of liability set out in the Terms of Service, except where such limitation is not permitted under applicable data protection law.
13. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses incorporated under Section 6, the Standard Contractual Clauses prevail.
14. Term
This DPA takes effect on the date Customer accepts the Terms of Service (or, for existing Customers, on 2026-09-25) and remains in effect until the Terms of Service terminate and all Personal Data has been deleted or returned per Section 10.
Annex I — Description of Processing
A. List of Parties
- Data exporter: Customer, as identified in its Irisend account (name, address, contact per account registration).
- Data importer: Irisend, [to be completed: COMPANY_ADDRESS], legal@irisend.dev. Activities: provision of the Irisend email API/SMTP/dashboard Service. Role: Processor.
B. Description of Transfer
- Categories of data subjects: Customer's contacts, subscribers, and recipients.
- Categories of Personal Data: email address, name (if provided), message content/headers, delivery/engagement event data, custom fields configured by Customer.
- Sensitive data: none processed by design; Customer must not submit special-category data (Art. 9 GDPR) via message content or contact fields unless it has independently assessed and secured an appropriate legal basis, and notified Irisend.
- Frequency of transfer: continuous, for as long as the Service is used.
- Nature of processing: transmission, temporary storage, delivery, event logging.
- Purpose: provision of the Service as instructed by Customer.
- Duration: for the term of the Terms of Service plus the retention/deletion periods in Section 10.
C. Competent Supervisory Authority: the supervisory authority of the EU Member State in which Customer is established, or, if Customer is not established in the EU, the Autoriteit Persoonsgegevens (Netherlands).
Annex II — Technical and Organizational Measures
See the Security page for the current, detailed description, summarized here: TLS 1.2+ encryption in transit; encryption at rest for databases and backups; hashed/salted credential storage; least-privilege, logged access to production systems; MFA for administrative access where supported; network protection via Cloudflare (WAF, DDoS mitigation); regular dependency/vulnerability monitoring; code review prior to production deployment; encrypted, regularly tested backups; documented incident-response process; sub-processor due diligence and contractual flow-down of equivalent obligations.
Annex III — List of Sub-processors
See Subprocessors for the current, authoritative list (currently: Amazon Web Services, Inc.; OVH SAS; Cloudflare, Inc.; Stripe, Inc.).
This document is a draft template and does not constitute legal advice. It is intended to reflect GDPR Art. 28 and the 2021 EU SCC modular structure, but must be reviewed by a qualified data protection lawyer before being offered to customers as a binding DPA. See research/legal.md for review recommendations before publishing.