Data Processing Agreement
Last updated: December 24, 2025
Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Do.dev, Inc. ("send.dev," "we," "us," or "Processor") and you ("Customer" or "Controller") for the use of our email delivery services.
This DPA reflects our commitment to processing personal data in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, and transmission.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
- "Sub-processor" means any third party engaged by send.dev to process Personal Data on behalf of the Customer.
- "Controller" means the entity that determines the purposes and means of Processing Personal Data.
- "Processor" means the entity that processes Personal Data on behalf of the Controller.
2. Scope and Roles
When you use send.dev to send emails on behalf of your users or customers:
- You (Customer) act as the Data Controller, determining why and how Personal Data is processed.
- send.dev acts as the Data Processor, processing Personal Data only as instructed by you.
This DPA applies to all Personal Data processed by send.dev in connection with providing our Services.
3. Types of Personal Data Processed
In the course of providing our email delivery services, we may process:
- Email addresses (sender and recipient)
- Names and other identifiers included in emails
- Email content and metadata
- IP addresses and device information
- Delivery and engagement data (opens, clicks)
4. Processing Instructions
send.dev will:
- Process Personal Data only on your documented instructions
- Process data only for the purpose of providing the Services
- Not process data for any other purpose without your consent
- Inform you if we believe an instruction violates applicable law
5. Security Measures
We implement appropriate technical and organizational measures to protect Personal Data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Access controls and authentication (role-based access, MFA)
- Regular security assessments and penetration testing
- Incident detection and response procedures
- Employee training on data protection
- Physical security at data center facilities
- Business continuity and disaster recovery plans
6. Sub-processors
We use the following categories of sub-processors to provide our Services:
- Cloud Infrastructure: Amazon Web Services (AWS) - data hosting and processing
- Email Delivery: Email service providers for message transmission
- Payment Processing: Stripe - payment and billing data
- Analytics: Service providers for usage analytics
We will notify you of any changes to sub-processors and provide you the opportunity to object. A current list of sub-processors is available upon request at privacy@send.dev.
7. Data Subject Rights
We will assist you in responding to Data Subject requests, including:
- Access: Providing copies of Personal Data
- Rectification: Correcting inaccurate data
- Erasure: Deleting Personal Data ("right to be forgotten")
- Portability: Exporting data in a structured format
- Restriction: Limiting processing activities
- Objection: Stopping certain processing activities
We will respond to your requests within 30 days or as required by applicable law.
8. Data Retention and Deletion
We retain Personal Data only as long as necessary for the purposes described:
- Email content: Up to 30 days for delivery and troubleshooting
- Delivery logs: According to your subscription plan (7 days to 1 year)
- Account data: Duration of the business relationship plus legal retention periods
Upon termination of your account or upon request, we will delete or return all Personal Data within 90 days, except where retention is required by law.
9. International Data Transfers
Personal Data may be transferred to and processed in the United States. We ensure appropriate safeguards for international transfers through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all sub-processors
- Technical and organizational security measures
10. Data Breach Notification
In the event of a Personal Data breach that affects your data, we will:
- Notify you without undue delay and within 72 hours of becoming aware
- Provide details of the breach, affected data, and likely consequences
- Describe measures taken or proposed to address the breach
- Assist you in meeting your notification obligations to authorities and Data Subjects
11. Audit Rights
You have the right to audit our compliance with this DPA. We will:
- Make available information necessary to demonstrate compliance
- Allow and contribute to audits conducted by you or an auditor you appoint
- Provide copies of relevant certifications and audit reports upon request
Audits should be conducted with reasonable notice and during normal business hours.
12. Confidentiality
We ensure that personnel authorized to process Personal Data:
- Are bound by confidentiality obligations
- Receive appropriate training on data protection
- Process data only as necessary for their duties
13. Your Obligations
As the Data Controller, you are responsible for:
- Ensuring you have a lawful basis to process and share Personal Data with us
- Obtaining necessary consents from Data Subjects
- Providing required privacy notices to Data Subjects
- Ensuring the accuracy of Personal Data provided to us
- Responding to Data Subject requests (with our assistance)
14. Term and Termination
This DPA remains in effect for the duration of your use of our Services. Upon termination:
- We will cease processing Personal Data except as required by law
- We will delete or return all Personal Data within 90 days
- We will provide certification of deletion upon request
15. Governing Law
This DPA is governed by the laws specified in our Terms of Service. For EU Data Subjects, GDPR and applicable member state laws apply to the processing of their Personal Data.
16. Contact Information
For questions about this DPA or to exercise your rights, contact us:
- Data Protection Officer: dpo@send.dev
- Privacy Inquiries: privacy@send.dev
- Legal Department: legal@send.dev
Request a Signed DPA
Enterprise customers requiring a signed Data Processing Agreement can request one by contacting our legal team. We'll provide a customized agreement that meets your organization's requirements.
Request Signed DPA