This Data Processing Agreement ("DPA") forms part of the Agreement between you ("Customer", the Controller) and Sendie ("Sendie", the Processor) and governs Sendie's processing of Customer Personal Data under the GDPR and UK GDPR.
1.1 Sendie as Processor. For Customer Data: recipient lists, campaign content, contact records the Customer uploads or creates, SMTP credentials, and message metadata. Sendie processes these solely on the Customer's documented instructions.
1.2 Sendie as independent Controller. For Sendie's own prospect database and platform telemetry. These are governed by Sendie's Privacy Policy and are outside the scope of this DPA.
4.1 Customer grants general authorization for the subprocessors listed at sendie.ai/subprocessors.
4.2 Sendie gives at least 30 days' notice of additions or replacements (via that page, and by email for Enterprise customers with a DPA on file). Customer may object on reasonable data-protection grounds; unresolved objections permit termination of the affected services on a pro-rata basis.
Sendie notifies the Customer without undue delay, and within 72 hours of confirming a Personal Data Breach affecting Customer Personal Data, with the known details and remediation steps.
Sendie provides this DPA, the subprocessor list, its security documentation, and answers to one reasonable security questionnaire per year. On-site audits take place only where required by law, at Customer cost, no more than once per year, with 30 days' notice.
Transfers outside the EEA or UK rely on the EU Standard Contractual Clauses (Module 2: Controller to Processor), incorporated by reference, together with the UK Addendum where applicable.
Aggregate liability under this DPA is subject to the limitations in the Agreement and is capped at the fees paid in the 12 months preceding the claim.
See sendie.ai/subprocessors (incorporated by reference).
← Back to the Trust CenterLast updated: June 2026