Data Processing Addendum
Last updated: 2026-05-02
This Data Processing Addendum ("DPA") forms part of the Splitsoft Terms of Service and applies whenever the Customer ("Controller") submits personal data to the Service for Splitsoft ("Processor") to process on the Controller's behalf. Capitalized terms have the meaning given in the Terms or in Article 4 GDPR.
1. Roles and scope
The Customer is the Controller (or a Processor acting on behalf of a third-party Controller, in which case Customer warrants it has the authority to engage Splitsoft as a Sub-Processor). Splitsoft is the Processor.
- Subject matter — transmission of email messages on the Controller's instructions.
- Duration — the term of the Terms.
- Nature and purpose — operation of an email-sending platform.
- Data subjects — the Controller's recipients, list members, and contacts.
- Categories of personal data — email address, name, free-text merge fields, message content, and engagement metadata.
2. Processor obligations
- Documented instructions. Splitsoft processes personal data only on the Controller's documented instructions, including those embodied in the Terms and the API/SMTP submission of messages.
- Confidentiality. All personnel with access to personal data are bound by written confidentiality obligations.
- Security (Art. 32). Splitsoft maintains the technical and organizational measures described in Annex II below.
- Sub-processing. Splitsoft engages the Sub-Processors listed in Annex III and gives the Controller at least 30 days' notice of additions or replacements, during which the Controller may object on reasonable data-protection grounds.
- Data subject requests. Splitsoft will assist the Controller by appropriate technical and organizational measures, including the
/api/data-exportand/api/data-eraseendpoints exposed by the admin panel. - Breach notification. Splitsoft will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal-data breach affecting the Controller's data.
- Return or deletion on termination. On termination of the Terms, Splitsoft will, at the Controller's election made within 30 days, either return personal data in a machine-readable format or delete it from production systems within 30 days, with backup purge completing within the further 35-day backup retention window.
- Audit rights. Once per 12-month period (more often after a breach or where required by a supervisory authority), Splitsoft will make available information necessary to demonstrate compliance with this DPA.
3. International transfers
Where the Controller's data originates in the EEA, UK, or Switzerland and processing involves transfer to a country not subject to an adequacy decision, the parties incorporate by reference the European Commission Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted on 4 June 2021, with the UK International Data Transfer Addendum and the Swiss FDPIC adaptation as applicable.
4. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms. Nothing in this DPA limits a data subject's rights against either party under GDPR Articles 79–82.
Annex I — Description of processing
- Categories of data subjects: Controller's email recipients, list subscribers, customers, prospects, and employees.
- Categories of personal data: email address; optional name; merge-field content controlled by the Controller; message subject and body, which may incidentally include other personal data; IP address and user-agent of recipients who open tracked email; timestamps of opens and clicks.
- Sensitive categories: Splitsoft does not solicit or require special-category data. The Controller agrees not to upload it.
- Frequency: continuous, transactional and batched.
- Duration: the term of the Terms, plus retention periods set out in the Privacy Policy.
Annex II — Technical and organizational measures
- Encryption at rest — volume-level encryption on all Postgres and MariaDB data volumes; encrypted off-site backups.
- Encryption in transit — TLS 1.2+ for all admin-panel, API, and management traffic; opportunistic STARTTLS for outbound SMTP with MTA-STS; DKIM signing of all outbound mail.
- Access control — single administrative account per deployment; per-customer scoped Postal credentials; SSH access limited to Splitsoft engineering with hardware-key 2FA; no shared accounts.
- Logging and monitoring — admin audit log (2-year retention), authentication log, deliverability telemetry; alerting on bounce and complaint anomalies.
- Backup and recovery — daily encrypted off-site backups; quarterly restore drills.
- Vulnerability management — automated dependency scanning, OS patching aligned to upstream advisories, coordinated disclosure via security@splitsoft.com.
- Incident response — documented runbook; on-call rotation; 72-hour breach-notification commitment.
Annex III — Authorized sub-processors
As of 2026-05-02 the following sub-processors are engaged:
| Sub-processor | Purpose | Region |
|---|---|---|
| Vultr Holdings, LLC | Compute, block storage, BYOIP custody | US, EU |
| Stripe, Inc. | Payment processing and invoicing | US |
| Cloudflare, Inc. | DNS, edge TLS for marketing site, DDoS protection | US / global anycast |
| Backblaze, Inc. (B2) | Encrypted off-site backups of Postgres and MariaDB | US |
To execute this DPA, request a counter-signed PDF at legal@splitsoft.com. Until executed, the version published on this page applies between the parties as of the Effective Date of the Terms.