Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Agreement between you ("Customer", the Controller) and SENDIE AI LTD, a company registered in England (No. 17307184, registered office: 66 Paul Street, London, England, EC2A 4NA) ("Sendie", the Processor), and governs Sendie's processing of Customer Personal Data under the GDPR and UK GDPR.
Standard terms apply automatically to every paid account. Enterprise customers can request a countersigned copy and the EU Standard Contractual Clauses, signed for their entity, from
our team.
1. Roles and scope
1.1 Sendie as Processor. For Customer Data: recipient and contact lists, contact records the Customer uploads or creates, message and campaign content, call recordings, transcripts and summaries, conversations across voice and messaging channels, booking, reservation and transaction records, SMTP and connected-account credentials, and related metadata. Sendie processes these solely on the Customer's documented instructions.
1.2 Sendie as independent Controller. For Sendie's own prospect database and platform telemetry. These are governed by Sendie's Privacy Policy and are outside the scope of this DPA.
2. Processing details (Annex 1)
- Subject matter: delivery of the Sendie AI customer-engagement platform (voice, messaging, pages, payments, Contacts and outreach).
- Duration: the term of the Agreement plus 30 days (deletion grace window).
- Nature and purpose: storing, organizing and personalizing Customer Data; answering calls and messages; taking bookings, reservations and payments; and sending outreach, on Customer instruction.
- Data categories: business and personal contact data (name, email, employer, title, phone number, channel identifiers such as chat IDs and social handles), message, call and conversation content (including recordings, transcripts and summaries), booking, reservation and transaction records, and engagement metadata.
- Data subjects: the Customer's prospects, callers, message senders, customers and team members.
3. Sendie's obligations
- Process only on documented instructions, and flag any instruction believed to be unlawful.
- Ensure personnel are bound by confidentiality.
- Maintain the technical and organizational measures in Annex 2.
- Assist with data-subject requests (access, deletion, portability) within 10 business days.
- Assist with DPIAs and supervisory-authority consultations as reasonably required.
- Delete or return Customer Personal Data on termination (30-day grace, then permanent deletion).
4. Subprocessors
4.1 Customer grants general authorization for the subprocessors listed at sendie.ai/subprocessors.
4.2 Sendie gives at least 30 days' notice of additions or replacements (via that page, and by email for Enterprise customers with a DPA on file). Customer may object on reasonable data-protection grounds; unresolved objections permit termination of the affected services on a pro-rata basis.
5. Security (Annex 2: Technical and Organizational Measures)
- Encryption in transit (TLS 1.2+) for all traffic.
- SMTP and integration credentials encrypted at rest.
- Two-factor authentication available on all accounts.
- Role-restricted admin access and an immutable audit log of sensitive actions.
- Daily encrypted offsite backups (RPO under 24 hours) with a tested restore procedure.
- Account deletion via a two-step, email-confirmed flow with a 30-day grace window, then permanent erasure.
- Vulnerability management: dependency patching and security review on authentication and billing changes.
6. Breach notification
Sendie notifies the Customer without undue delay, and within 72 hours of confirming a Personal Data Breach affecting Customer Personal Data, with the known details and remediation steps.
7. Audits
Sendie provides this DPA, the subprocessor list, its security documentation, and answers to one reasonable security questionnaire per year. On-site audits take place only where required by law, at Customer cost, no more than once per year, with 30 days' notice.
8. International transfers
Transfers outside the EEA or UK rely on the EU Standard Contractual Clauses (Module 2: Controller to Processor), incorporated by reference, together with the UK Addendum where applicable.
9. Liability
Aggregate liability under this DPA is subject to the limitations in the Agreement and is capped at the fees paid in the 12 months preceding the claim.
Annex 3: Approved subprocessors
See sendie.ai/subprocessors (incorporated by reference).
← Back to the Trust Center
Last updated: August 26, 2026