Data Processing Addendum

Last updated: 2026-04-30

This DPA forms part of the Splitsoft Terms of Service and applies whenever the Customer (Controller) submits Personal Data to the Service for Splitsoft (Processor) to process on the Customer's behalf. Capitalized terms have the meaning given in the Terms or in Article 4 GDPR.

1. Roles and scope

The Customer is the Controller (or the Processor on behalf of a third-party Controller, in which case Customer warrants it has the authority to engage Splitsoft as a Sub-Processor). Splitsoft is the Processor. The subject matter of processing is the transmission of email messages on the Controller's instructions; the duration is the term of the Terms; the nature and purpose of processing is the operation of an email-sending platform; the categories of Data Subjects are the Controller's recipients, list members, and contacts; the categories of Personal Data include email address, name, free-text merge fields, message content, and engagement metadata.

2. Processor obligations

  1. Documented instructions. Splitsoft processes Personal Data only on the Controller's documented instructions, including those embodied in the Terms, the API/SMTP submission of Messages, and explicit written instructions. If Splitsoft believes an instruction violates GDPR or other applicable law, it will inform the Controller.
  2. Confidentiality. All personnel with access to Personal Data are bound by written confidentiality obligations.
  3. Security (Art. 32). Splitsoft maintains the technical and organizational measures described on the security page and in Annex II below, including encryption at rest, TLS 1.2+ in transit, role-based access, audit logging, and tested backups.
  4. Sub-processing. Splitsoft engages the Sub-Processors listed in Annex III and gives the Controller at least 30 days' notice of additions or replacements, during which the Controller may object on reasonable data-protection grounds and, failing resolution, terminate the affected Service component.
  5. Data Subject requests. Splitsoft will, taking into account the nature of processing, assist the Controller by appropriate technical and organizational measures to fulfill Data Subject requests under Articles 15–22 GDPR. The data export and erasure endpoints described in the Privacy Policy are the primary mechanism.
  6. Breach notification. Splitsoft will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data Breach affecting the Controller's data, providing the information required by Art. 33(3) to the extent then known.
  7. DPIA assistance. Splitsoft will provide the Controller with information reasonably necessary to conduct a Data Protection Impact Assessment under Art. 35.
  8. Return / deletion on termination. On termination of the Terms, Splitsoft will, at the Controller's written election made within 30 days of termination, either return Personal Data to the Controller in a machine-readable format or delete it from production systems within 30 days, with backup purge completing within the further 35-day backup retention window.
  9. Audit rights. Once per 12-month period (more often after a Breach or where required by a supervisory authority), Splitsoft will make available to the Controller information necessary to demonstrate compliance with this DPA, including the most recent third-party audit reports when available, and will permit reasonable on-site or remote audits during business hours on at least 30 days' written notice, subject to confidentiality and to not unreasonably interfering with Splitsoft's operations.

3. International transfers

Where the Controller's data originates in the EEA, UK, or Switzerland and Splitsoft's processing involves transfer to a country not subject to an adequacy decision, the parties incorporate by reference the European Commission Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted on 4 June 2021 (and the UK International Data Transfer Addendum / Swiss FDPIC adaptation as applicable), with the following selections:

[REVIEW: confirm SCC Module election if Customer is itself a Processor (Module 3), and add UK IDTA executed copy.]

4. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms. Nothing in this DPA limits a Data Subject's rights against either party under GDPR Art. 79–82.


Annex I — Description of processing

Annex II — Technical and organizational measures

Annex III — Authorized Sub-Processors

Sub-ProcessorPurposeRegion
Vultr Holdings, LLCCompute, block storage, BYOIP custodyUSA (default), EU on request from M9
Stripe, Inc.Payment processing, invoicingUSA
Cloudflare, Inc.DNS, edge TLS for marketing site, DDoS protectionGlobal anycast
S3-compatible backup providerEncrypted off-site backupsRegion-matched

To execute this DPA, please request a counter-signed PDF at legal@splitsoft.com. Until executed, the version published on this page applies between the parties as of the Effective Date of the Terms.