Data Processing Addendum
Last Updated: June 23, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and ProperSend ("ProperSend", "we", "us") and applies to the extent that we process Personal Data on the Customer's behalf in providing the Service. Capitalized terms not defined here have the meaning given in the Terms or in applicable Data Protection Laws.
1. Definitions
- Data Protection Laws means all laws applicable to the processing of Personal Data under the Service, including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act, as amended ("CCPA").
- Controller, Processor, Data Subject, Personal Data, and processing have the meanings given under GDPR; Business and Service Provider have the meanings given under CCPA.
2. Roles of the parties
As between the parties, the Customer is the Controller (or Business) and ProperSend is the Processor (or Service Provider) with respect to Customer Personal Data processed through the Service. The Customer determines the purposes and means of processing.
3. Scope and purpose of processing
We process Personal Data only to provide, maintain, secure, and support the Service in accordance with the Customer's documented instructions (including configuration choices within the Service and the Terms). The subject matter is the operation of the email marketing platform; the duration is the term of the agreement; the data subjects are the Customer's contacts and users; and the data types are those the Customer chooses to store (e.g., names, email addresses, custom fields, and engagement data).
4. Bring Your Own Server (BYOS) note
Email delivery and list verification are performed by third-party providers that the Customer connects and controls directly (for example Amazon SES, SendGrid, Mailgun, or a verification API). Those providers act as the Customer's own processors under agreements between the Customer and each provider; they are not our sub-processors. The Customer is responsible for entering into appropriate data processing terms with them.
5. Customer instructions and compliance
The Customer warrants that it has a lawful basis and all necessary consents and notices to collect and process the Personal Data it uploads, and to instruct us to process it. We will inform the Customer if, in our opinion, an instruction infringes Data Protection Laws.
6. Confidentiality
We ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality and process Personal Data only as necessary to provide the Service.
7. Security
We implement appropriate technical and organizational measures designed to protect Personal Data, including encryption in transit, access controls and least-privilege administration, network and host hardening, logging, and regular security maintenance. Security measures may evolve; we will not materially decrease the overall protection during the term.
8. Sub-processors
The Customer authorizes us to engage sub-processors to support the Service (for example, infrastructure and hosting providers). We impose data protection obligations on our sub-processors that are no less protective than those in this DPA and remain responsible for their performance. We will provide a means to learn of, and reasonable notice of, changes to our sub-processors so the Customer can object on reasonable data-protection grounds.
9. Assistance with data subject rights
Taking into account the nature of the processing, we provide tools within the Service (such as search, edit, export, and delete) that enable the Customer to respond to Data Subject requests to access, correct, delete, restrict, or port their Personal Data, and we will provide reasonable assistance where the Customer cannot do so through those tools.
10. Personal data breach
We will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data and provide information reasonably available to us to assist the Customer in meeting its notification obligations.
11. International transfers
Where processing involves a transfer of Personal Data outside the EEA, UK, or other restricted region, such transfers are made on the basis of an appropriate transfer mechanism (such as the EU Standard Contractual Clauses and the UK Addendum) where required by Data Protection Laws.
12. Return or deletion
On termination of the Service, the Customer may export its data within the period stated in the Terms. After that period, we will delete or anonymize Customer Personal Data in the ordinary course, except where retention is required by law.
13. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality, scope, and frequency limits.
14. CCPA
With respect to Personal Data subject to the CCPA, we act as a Service Provider. We do not sell or share such Personal Data and do not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA.
15. Contact
To request a signed copy of this DPA or to raise a data-protection matter, contact legalpropersend.com. See also our Privacy Policy.