Data Processing Addendum
This DPA forms part of the Splitsoft Terms of Service and applies whenever the Customer (Controller) submits Personal Data to the Service for Splitsoft (Processor) to process on the Customer's behalf. Capitalized terms have the meaning given in the Terms or in Article 4 GDPR.
1. Roles and scope
The Customer is the Controller (or the Processor on behalf of a third-party Controller, in which case Customer warrants it has the authority to engage Splitsoft as a Sub-Processor). Splitsoft is the Processor. The subject matter of processing is the transmission of email messages on the Controller's instructions; the duration is the term of the Terms; the nature and purpose of processing is the operation of an email-sending platform; the categories of Data Subjects are the Controller's recipients, list members, and contacts; the categories of Personal Data include email address, name, free-text merge fields, message content, and engagement metadata.
2. Processor obligations
- Documented instructions. Splitsoft processes Personal Data only on the Controller's documented instructions, including those embodied in the Terms, the API/SMTP submission of Messages, and explicit written instructions. If Splitsoft believes an instruction violates GDPR or other applicable law, it will inform the Controller.
- Confidentiality. All personnel with access to Personal Data are bound by written confidentiality obligations.
- Security (Art. 32). Splitsoft maintains the technical and organizational measures described on the security page and in Annex II below, including encryption at rest, TLS 1.2+ in transit, role-based access, audit logging, and tested backups.
- Sub-processing. Splitsoft engages the Sub-Processors listed in Annex III and gives the Controller at least 30 days' notice of additions or replacements, during which the Controller may object on reasonable data-protection grounds and, failing resolution, terminate the affected Service component.
- Data Subject requests. Splitsoft will, taking into account the nature of processing, assist the Controller by appropriate technical and organizational measures to fulfill Data Subject requests under Articles 15–22 GDPR. The data export and erasure endpoints described in the Privacy Policy are the primary mechanism.
- Breach notification. Splitsoft will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data Breach affecting the Controller's data, providing the information required by Art. 33(3) to the extent then known.
- DPIA assistance. Splitsoft will provide the Controller with information reasonably necessary to conduct a Data Protection Impact Assessment under Art. 35.
- Return / deletion on termination. On termination of the Terms, Splitsoft will, at the Controller's written election made within 30 days of termination, either return Personal Data to the Controller in a machine-readable format or delete it from production systems within 30 days, with backup purge completing within the further 35-day backup retention window.
- Audit rights. Once per 12-month period (more often after a Breach or where required by a supervisory authority), Splitsoft will make available to the Controller information necessary to demonstrate compliance with this DPA, including the most recent third-party audit reports when available, and will permit reasonable on-site or remote audits during business hours on at least 30 days' written notice, subject to confidentiality and to not unreasonably interfering with Splitsoft's operations.
3. International transfers
Where the Controller's data originates in the EEA, UK, or Switzerland and Splitsoft's processing involves transfer to a country not subject to an adequacy decision, the parties incorporate by reference the European Commission Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted on 4 June 2021 (and the UK International Data Transfer Addendum / Swiss FDPIC adaptation as applicable), with the following selections:
- Clause 7 (docking) — applies.
- Clause 9 — Option 2 (general written authorization), with 30-day notice as in Section 2.4 above.
- Clause 11 — independent dispute resolution body — not selected.
- Clause 17 — Governing law: Ireland.
- Clause 18 — Forum: Ireland.
- Annexes I, II, III — populated below.
[REVIEW: confirm SCC Module election if Customer is itself a Processor (Module 3), and add UK IDTA executed copy.]
4. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms. Nothing in this DPA limits a Data Subject's rights against either party under GDPR Art. 79–82.
Annex I — Description of processing
- Categories of Data Subjects: Controller's email recipients, list subscribers, customers, prospects, and employees.
- Categories of Personal Data: email address; optional name; merge-field content (which the Controller controls); message subject and body, which may incidentally include other personal data depending on Controller's content; IP address and user agent of recipients who open tracked email; timestamps of opens and clicks.
- Sensitive categories: Splitsoft does not solicit or require special-category data and the Controller agrees not to upload it. Any incidental special-category data in message content is processed under the same security controls as ordinary content.
- Frequency: continuous, transactional and batched.
- Duration: the term of the Terms, plus retention periods set out in the Privacy Policy.
Annex II — Technical and organizational measures
- Encryption at rest: volume-level LUKS encryption on all Postgres and MariaDB data volumes; encrypted backups with keys held in production region.
- Encryption in transit: TLS 1.2+ for all admin-panel, API, and management traffic; opportunistic STARTTLS for outbound SMTP, with MTA-STS supported for recipient domains that publish a policy; DKIM signing of all outbound mail.
- Access control: single administrative account per deployment; per-Customer scoped Postal credentials; SSH access to production hosts limited to Splitsoft engineering with hardware-key 2FA; no shared accounts.
- Logging and monitoring: admin audit log (2-year retention), authentication log, deliverability telemetry; alerting on bounce/complaint anomalies.
- Backup and recovery: daily encrypted off-site backups of Postgres and MariaDB; quarterly restore drills.
- Vulnerability management: automated dependency scanning, OS patching cadence aligned to upstream advisories, coordinated disclosure via security@splitsoft.com.
- Personnel: background-checked engineering staff bound by confidentiality obligations; documented onboarding/offboarding access review.
- Incident response: documented IR runbook; on-call rotation; 72-hour breach notification commitment.
Annex III — Authorized Sub-Processors
| Sub-Processor | Purpose | Region |
|---|---|---|
| Vultr Holdings, LLC | Compute, block storage, BYOIP custody | USA (default), EU on request from M9 |
| Stripe, Inc. | Payment processing, invoicing | USA |
| Cloudflare, Inc. | DNS, edge TLS for marketing site, DDoS protection | Global anycast |
| S3-compatible backup provider | Encrypted off-site backups | Region-matched |
To execute this DPA, please request a counter-signed PDF at legal@splitsoft.com. Until executed, the version published on this page applies between the parties as of the Effective Date of the Terms.