Data Processing Addendum (DPA)

Maillog.nl — part of Woodst B.V.

Annex to the Terms of Service of Maillog.nl

This Data Processing Addendum forms an inseparable part of the main agreement (Terms of Service) between the Customer (hereinafter: “Controller”) and Woodst B.V., trading under the name Maillog.nl (hereinafter: “Processor”).

1. Purposes of the processing

1.1. The Processor undertakes, under the conditions of this Data Processing Addendum, to process personal data on behalf of the Controller.

1.2. The processing takes place exclusively in the context of the execution of the main agreement, namely providing an email API and SMTP infrastructure, routing and delivering electronic messages, and generating related telemetry and analytical data (such as open-, click- and bounce-tracking).

1.3. The Processor will not process the personal data for any other purpose, unless with express, prior written consent of the Controller or where a legal obligation requires it.

2. Nature of the personal data and data subjects

2.1. The Controller determines which personal data is sent via the systems of the Processor. This usually includes:

  • Identification data (email addresses, names, IP addresses).
  • Content data (the body and any attachments of the email messages).
  • Metadata (timestamps, user agents, routing information).

2.2. The categories of data subjects concern the end users, customers, or relations of the Controller to whom the messages are sent.

2.3. The Controller guarantees that the processing of this personal data is lawful, that a valid legal basis exists (such as consent or performance of a contract), and that the processing does not conflict with the GDPR.

3. Security

3.1. The Processor will endeavour to take appropriate technical and organisational measures to secure the personal data against loss or any form of unlawful processing (such as unauthorised access, impairment, modification or disclosure of the personal data).

3.2. These measures include at least:

  • Encryption in transit (TLS) for all API traffic and, where supported by receiving parties, SMTP traffic (Opportunistic TLS).
  • Physical and logical access control on the servers and databases of the Processor, hosted within the European Union (Paris, France).
  • Pseudonymisation and encryption of stored passwords and API keys.

3.3. The Processor does not warrant that the security will be effective under all circumstances, but guarantees that the level of security, given the state of the art and the costs of implementation, is appropriate to the risks of the processing and the nature of the data to be protected.

4. Data breach notification

4.1. In the event of a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to transmitted, stored or otherwise processed personal data (a “Data Breach”), the Processor will inform the Controller thereof without undue delay, and at the latest within 36 hours after discovery.

4.2. The Processor will provide the Controller with all reasonably available information required to make a notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the data subject(s).

4.3. It is the exclusive responsibility of the Controller to assess whether the data breach must be reported to the supervisory authority.

5. Engagement of Subprocessors

5.1. The Controller hereby grants the Processor general authorisation to engage subprocessors (such as cloud hosting providers) in the processing of personal data.

5.2. The Processor will inform the Controller via its website (e.g. via a dedicated Subprocessors page) of intended changes regarding the addition or replacement of subprocessors.

5.3. The Controller has the right to make a reasoned objection to a new subprocessor within 14 days of publication. If the parties cannot reach a solution, the Controller is entitled to terminate the agreement.

5.4. The Processor imposes contractually on subprocessors at least the same obligations regarding data protection as those included in this agreement.

6. Rights of Data Subjects

6.1. If a data subject submits a request to exercise their statutory rights (access, rectification, erasure, data portability) to the Processor, the Processor will forward this request immediately to the Controller.

6.2. The Processor will, insofar as reasonably possible given the nature of the processing, provide technical assistance to the Controller in fulfilling its duty to respond to such requests, for example via the provided management dashboards.

7. Transfer outside the EEA

7.1. The Processor will primarily process personal data on servers located within the European Economic Area (EEA).

7.2. If personal data is transferred to a country outside the EEA, the Processor will guarantee that this only happens where there is an appropriate level of protection (as determined by the European Commission, through the use of Standard Contractual Clauses (SCC), or the EU-US Data Privacy Framework).

8. Retention periods and deletion

8.1. After termination of the main agreement or after the end of the retention period applicable within the subscription, the Processor will permanently and irrevocably delete all personal data (including email logs and the content of the messages) from the active systems.

8.2. Backups in which this data may still be present are kept securely for a limited period and overwritten according to regular rotation schedules. The personal data in these backups is no longer actively processed.

9. Audits

9.1. The Controller has the right, at most once per calendar year and only in the event of a reasonable and substantiated suspicion of a shortcoming, to have an audit performed by an independent expert third party.

9.2. The audit will be limited to verifying compliance with the provisions of this Data Processing Addendum. The costs of this audit, including the internal costs the Processor must incur to cooperate with the audit, are entirely for the account of the Controller.

10. Liability

10.1. The liability of the parties with regard to the obligations agreed in this Data Processing Addendum is governed exclusively by the liability provisions as agreed in the Terms of Service.

10.2. The Controller indemnifies the Processor against all claims of third parties, including the Autoriteit Persoonsgegevens and data subjects, arising from non-compliance with the GDPR by the Controller (for example due to the absence of consent from the email recipient or the sending of unencrypted special categories of personal data via email).

Contact

[email protected]