Trust Center / Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Agreement between you ("Customer", the Controller) and Sendie ("Sendie", the Processor) and governs Sendie's processing of Customer Personal Data under the GDPR and UK GDPR.

Standard terms apply automatically to every paid account. Enterprise customers can request a countersigned copy and the EU Standard Contractual Clauses, signed for their entity, from our team.

1. Roles and scope

1.1 Sendie as Processor. For Customer Data: recipient lists, campaign content, contact records the Customer uploads or creates, SMTP credentials, and message metadata. Sendie processes these solely on the Customer's documented instructions.

1.2 Sendie as independent Controller. For Sendie's own prospect database and platform telemetry. These are governed by Sendie's Privacy Policy and are outside the scope of this DPA.

2. Processing details (Annex 1)

3. Sendie's obligations

4. Subprocessors

4.1 Customer grants general authorization for the subprocessors listed at sendie.ai/subprocessors.

4.2 Sendie gives at least 30 days' notice of additions or replacements (via that page, and by email for Enterprise customers with a DPA on file). Customer may object on reasonable data-protection grounds; unresolved objections permit termination of the affected services on a pro-rata basis.

5. Security (Annex 2: Technical and Organizational Measures)

6. Breach notification

Sendie notifies the Customer without undue delay, and within 72 hours of confirming a Personal Data Breach affecting Customer Personal Data, with the known details and remediation steps.

7. Audits

Sendie provides this DPA, the subprocessor list, its security documentation, and answers to one reasonable security questionnaire per year. On-site audits take place only where required by law, at Customer cost, no more than once per year, with 30 days' notice.

8. International transfers

Transfers outside the EEA or UK rely on the EU Standard Contractual Clauses (Module 2: Controller to Processor), incorporated by reference, together with the UK Addendum where applicable.

9. Liability

Aggregate liability under this DPA is subject to the limitations in the Agreement and is capped at the fees paid in the 12 months preceding the claim.

Annex 3: Approved subprocessors

See sendie.ai/subprocessors (incorporated by reference).

← Back to the Trust Center

Last updated: June 2026