Draft — to be reviewed by counsel before publication
Data processing agreement
Draft processor terms for Article 28 of Regulation (EU) 2016/679. Counsel reviews before either party signs. This file is not a signed agreement.
Controller: the customer.
Processor: MB Tobuli, company code [Company code], [Registered address], VAT [VAT number], [Contact email].
Subject matter and duration
The processor sends transactional email for the controller and records the result. Processing lasts for the service contract. At the end, the processor deletes or returns personal data as set out below.
Nature and purpose
The processor receives the message from the controller's API call, stores it, and hands the live message to the email provider in eu-central-1. The processor records delivery, permanent bounce, and complaint events, and suppresses the affected address so it is not mailed again. Test-mode messages are stored and are not handed to the email provider.
Types of personal data
- Sender and recipient addresses, subject, HTML, text, and tags.
- Delivery metadata: status, event type, event time, provider message id, bounce diagnostic, complaint data, and clicked link when the provider sends those fields.
- Suppression address and reason.
- Webhook URL and signing secret, where the controller configures a webhook.
- Tenant name and API key metadata. The key secret is not stored in clear text. The stored value is a hash.
The processor does not ask for special-category data. If the controller puts such data in a message body, the controller documents that choice. To confirm by counsel whether the processor must refuse those bodies.
Categories of data subjects
Recipients and senders of the controller's messages. The controller's own operators, to the extent their addresses appear as senders. Organization members, including their email addresses, are stored for the account. Dashboard sign-in exists.
Documented instructions
The processor processes personal data only on the controller's documented instructions. The instructions are these. Accept the API call. Send live mail. Apply provider events. Suppress on a permanent bounce and on a complaint. Deliver webhooks the controller configured.
A later written instruction from the controller controls where it conflicts. The processor tells the controller if an instruction appears to breach Regulation (EU) 2016/679. That notice duty is to confirm by counsel.
The processor does not sell message data. The processor does not use message bodies to train a model.
People and security
The processor limits access to people who operate the service and binds them to confidentiality. The contractual location for the email service is eu-central-1 only. The processor does not move message content, recipient addresses, or event payloads outside that Region.
That limit also covers observability and the send-admission cache. Those systems do not receive message content, recipient addresses, or event payloads. See Subprocessors.
Terraform in this repository defines production compute, the production database, and the Valkey cache in eu-central-1. Counsel does not treat this draft as evidence that those resources are already applied in a live account. To confirm at launch.
Article 32 measures that exist in the repository today: private object-storage settings on the unused raw-MIME bucket, TLS to the email provider through the AWS API, hashed API keys, SNS signature checks before an event is stored, and tenant row-level security enabled and forced on tenant tables. A full measure list is to confirm by counsel.
Subprocessors
The processor uses the subprocessors in Subprocessors. Each subprocessor must carry the same data-protection obligations that this agreement sets for the processor. That includes confidentiality, security, and the duty to follow documented instructions. The Cloudflare entry includes the dashboard sign-in bot check when that check is configured. Cloudflare then receives the challenge token and the signals in the Turnstile Privacy Addendum (accessed 2026-10-07): client IP address, TLS fingerprint, User-Agent, site key, and the site key's origin. Cloudflare is the processor for providing the check and the controller for improving detection. The addendum does not name a cookie. Cloudflare does not receive message content.
Article 28(4) of Regulation (EU) 2016/679 requires that flow-down. Counsel confirms the sentence before signature.
Counsel confirms the notice period and the objection right before publication. General written authorization for that list is a draft choice. To confirm by counsel. The processor updates the list before a new subprocessor processes personal data.
Data subject rights
The processor assists the controller with access, correction, deletion, export, and objection requests, taking into account the nature of the processing. The controller's own tool is the API where it already supports the action (for example, deleting a suppression). A dashboard organization owner can export the tenant’s retained data through GET /organizations/{tenant_id}/export and request deletion through DELETE /organizations/{tenant_id}. The processor handles other requests sent to [Contact email]. Counsel reviews these procedures before publication.
Assistance and breaches
The processor assists the controller with security, breach notice, and impact assessment duties that fall on the controller, to the extent the processor's role allows. The processor notifies the controller without undue delay after becoming aware of a personal-data breach. A fixed hour count is to confirm by counsel. Do not copy the controller's supervisory-authority deadline into this clause until counsel does.
Deletion or return
At the end of the service, the processor deletes or returns personal data at the controller's choice, and deletes remaining copies unless the law requires retention. An owner can stream a JSON export of organization data, members, pending invitations, domains and DNS records, API key metadata, webhook configuration, tenant suppressions, and retained messages with bodies and events. Pending invitations omit tokens and hashes. The export excludes accepted and revoked invitations, secrets and internal retry bookkeeping. See ADR-0024 (docs/adr/0024-account-export-and-deletion.md). An account-deletion request immediately revokes API keys, disables webhooks, and rejects new sends, new invitations, invitation acceptance and member changes. Unused invitations can still be revoked. The request cancels that organization's queued team-invite notifications that are not yet delivered. Restoring the organization does not recreate those notifications. The owner can restore the organization within thirty days; revoked keys remain revoked. After that window, cron removes the tenant’s database rows and provider tenant and unused identities. Failed purges retry, so thirty days is the earliest purge time rather than a completion guarantee. Shared user identities and global suppressions remain where they serve other controllers. A user referenced by another organization's accepted invitation remains. Counsel confirms the window, exclusions and treatment of remaining copies before publication.
While the contract runs, cron drops daily partitions of messages, events, webhook deliveries, and webhook delivery attempts after the retention period. The default period is 30 days. The minimum is 4 days. That drop is not a response to one controller's deletion request. It removes the same UTC day for every tenant. The public summary is Data retention.
Suppression rows can protect other controllers. Deleting a global suppression on one controller's request may be refused where the address hard-bounced or complained for another controller. To confirm by counsel.
Audits
The processor provides the information the controller needs to show compliance. An audit is by written request to [Contact email], on reasonable notice, and limited to this processing. A third-party audit right, the notice period, and any confidentiality terms are to confirm by counsel.
International transfers
Email-service processing stays in eu-central-1. Message content, recipient addresses, and event payloads stay in that Region. The processor does not rely on a transfer tool for that processing while this limit holds.
A subprocessor in another EU country is still inside the EEA. That fact does not allow it to take message content out of eu-central-1. A subprocessor outside the EEA needs a transfer tool before it processes personal data. The tool is to confirm by counsel before that processing starts.
Stripe is a separate controller or processor for billing when billing is enabled. Billing is not enabled. Stripe's transfer mechanism is to confirm by counsel. The Stripe data-transfer addendum, page dated 2025-11-18, describes the Data Privacy Framework and standard contractual clauses toward Stripe, LLC. Counsel confirms whether that is the tool that applies. Do not state that the addendum is signed.
Controller duties of the processor
If the processor decides purposes or means for a given processing activity, it is a controller for that activity. Counsel reviews any such activity before it starts. None is intended for message content.