Data Processing Addendum
Last updated: 2026. This DPA forms part of the Terms of Service between you (“Controller”) and RabbitMail (“Processor”) and applies where we process personal data on your behalf.
1. Roles
For lead data, recipient email addresses, message content, and replies you upload or generate, you are the Controller and RabbitMail is the Processor. You are responsible for having a lawful basis to process that data and to contact your recipients.
2. Scope and instructions
We process personal data only to provide the Service and on your documented instructions (including via the product configuration), unless required by law.
3. Confidentiality & security
- Personnel with access are bound by confidentiality.
- We maintain technical and organizational measures appropriate to the risk, including encryption of secrets, access control, and workspace isolation.
4. Sub-processors
You authorize us to engage sub-processors (hosting, mailbox/email providers, DNS, payments, AI providers) under written terms with equivalent obligations. We will make the list available and notify you of material changes.
5. Data subject requests
We will assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
6. Breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data.
7. Deletion & return
On termination we will delete or return customer personal data per your instruction, subject to backups and legal retention.
8. International transfers
Where personal data is transferred across borders, the parties rely on an appropriate transfer mechanism such as the Standard Contractual Clauses, incorporated by reference.
9. Contact
To execute a signed DPA or ask questions: contact us.