Last updated: 2026-06-28
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Controller") and Climails (the "Processor") and governs the processing of personal data that Climails carries out on your behalf under applicable data protection laws. Where it conflicts with the Terms on data protection, this DPA prevails.
Definitions
"Applicable data protection laws" means the data protection and privacy laws that apply to the processing under this DPA. "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in those laws. "Customer Personal Data" means personal data within Customer Data that Climails processes on your behalf.
Roles and instructions
You are the controller and Climails is the processor of Customer Personal Data. You determine the purposes and means of processing and are responsible for the lawfulness of the data and instructions you provide.
Climails processes Customer Personal Data only on your documented instructions, including those given through the Service, unless required to act by law, in which case we will inform you where legally permitted. We will tell you if, in our opinion, an instruction infringes data protection law.
Details of processing
Subject matter: provision of the Climails Service. Duration: the term of your account plus any retention period in the Privacy Policy. Nature and purpose: hosting, sending, measuring and supporting the messages and campaigns you create across email and the channels in your plan.
Categories of data subjects: your contacts, recipients, leads and any individuals whose data you upload. Categories of personal data: identifiers and contact details (such as name, email address, phone number and messaging identifiers), custom fields you define, consent and suppression records, and engagement and delivery metadata. You must not upload special-category data unless you have a lawful basis and have informed us.
Confidentiality
We ensure that personnel authorised to process Customer Personal Data are bound by confidentiality and trained on their data protection obligations, and we limit access to those who need it to provide the Service.
Security
Taking into account the state of the art and the risks of processing, we implement appropriate technical and organisational measures, including encryption in transit and at rest, KMS-protected secrets, access controls, least-privilege administration, audit logging, network isolation, backup, and regular testing and review of our measures.
Sub-processors
You give general authorisation for Climails to engage sub-processors to provide the Service. Each sub-processor is bound by data protection obligations no less protective than this DPA, and Climails remains responsible for their performance.
We maintain a list of sub-processors and give notice before adding or replacing one. You may object on reasonable data protection grounds within 30 days; if we cannot resolve your objection, you may terminate the affected part of the Service.
Data subject requests
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. If a data subject contacts us directly about Customer Personal Data, we refer them to you.
Assistance
We assist you, taking into account the nature of processing and the information available to us, in ensuring compliance with your obligations on security, breach notification, data protection impact assessments and prior consultation with authorities.
Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to us to help you meet your own notification obligations.
International transfers
Where processing involves a cross-border transfer of Customer Personal Data, the parties rely on the transfer safeguards required by applicable data protection laws, such as standard contractual clauses or another lawful transfer mechanism. Data-residency options may be available on higher tiers.
Audits
We make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, by you or an auditor you mandate. To avoid disrupting the Service, audits take place on reasonable notice, no more than once a year unless required by a regulator or following a breach, subject to confidentiality, and we may satisfy audit rights by providing third-party reports and certifications where available.
Return or deletion
On termination of the Service, we delete or return Customer Personal Data at your choice and delete existing copies, except where storage is required by law. Residual copies in encrypted backups are deleted in the ordinary backup cycle.
Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA forms part of and is governed by the Terms.
Start sending in minutes
Create a free account, connect your domain and reach your audience across every channel — no credit card needed.
Free plan forever · No credit card required · Set up in minutes