Data Processing Agreement

Last updated: December 24, 2025

Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Do.dev, Inc. ("send.dev," "we," "us," or "Processor") and you ("Customer" or "Controller") for the use of our email delivery services.

This DPA reflects our commitment to processing personal data in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, and transmission.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
  • "Sub-processor" means any third party engaged by send.dev to process Personal Data on behalf of the Customer.
  • "Controller" means the entity that determines the purposes and means of Processing Personal Data.
  • "Processor" means the entity that processes Personal Data on behalf of the Controller.

2. Scope and Roles

When you use send.dev to send emails on behalf of your users or customers:

  • You (Customer) act as the Data Controller, determining why and how Personal Data is processed.
  • send.dev acts as the Data Processor, processing Personal Data only as instructed by you.

This DPA applies to all Personal Data processed by send.dev in connection with providing our Services.

3. Types of Personal Data Processed

In the course of providing our email delivery services, we may process:

  • Email addresses (sender and recipient)
  • Names and other identifiers included in emails
  • Email content and metadata
  • IP addresses and device information
  • Delivery and engagement data (opens, clicks)

4. Processing Instructions

send.dev will:

  • Process Personal Data only on your documented instructions
  • Process data only for the purpose of providing the Services
  • Not process data for any other purpose without your consent
  • Inform you if we believe an instruction violates applicable law

5. Security Measures

We implement appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and authentication (role-based access, MFA)
  • Regular security assessments and penetration testing
  • Incident detection and response procedures
  • Employee training on data protection
  • Physical security at data center facilities
  • Business continuity and disaster recovery plans

6. Sub-processors

We use the following categories of sub-processors to provide our Services:

  • Cloud Infrastructure: Amazon Web Services (AWS) - data hosting and processing
  • Email Delivery: Email service providers for message transmission
  • Payment Processing: Stripe - payment and billing data
  • Analytics: Service providers for usage analytics

We will notify you of any changes to sub-processors and provide you the opportunity to object. A current list of sub-processors is available upon request at privacy@send.dev.

7. Data Subject Rights

We will assist you in responding to Data Subject requests, including:

  • Access: Providing copies of Personal Data
  • Rectification: Correcting inaccurate data
  • Erasure: Deleting Personal Data ("right to be forgotten")
  • Portability: Exporting data in a structured format
  • Restriction: Limiting processing activities
  • Objection: Stopping certain processing activities

We will respond to your requests within 30 days or as required by applicable law.

8. Data Retention and Deletion

We retain Personal Data only as long as necessary for the purposes described:

  • Email content: Up to 30 days for delivery and troubleshooting
  • Delivery logs: According to your subscription plan (7 days to 1 year)
  • Account data: Duration of the business relationship plus legal retention periods

Upon termination of your account or upon request, we will delete or return all Personal Data within 90 days, except where retention is required by law.

9. International Data Transfers

Personal Data may be transferred to and processed in the United States. We ensure appropriate safeguards for international transfers through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all sub-processors
  • Technical and organizational security measures

10. Data Breach Notification

In the event of a Personal Data breach that affects your data, we will:

  • Notify you without undue delay and within 72 hours of becoming aware
  • Provide details of the breach, affected data, and likely consequences
  • Describe measures taken or proposed to address the breach
  • Assist you in meeting your notification obligations to authorities and Data Subjects

11. Audit Rights

You have the right to audit our compliance with this DPA. We will:

  • Make available information necessary to demonstrate compliance
  • Allow and contribute to audits conducted by you or an auditor you appoint
  • Provide copies of relevant certifications and audit reports upon request

Audits should be conducted with reasonable notice and during normal business hours.

12. Confidentiality

We ensure that personnel authorized to process Personal Data:

  • Are bound by confidentiality obligations
  • Receive appropriate training on data protection
  • Process data only as necessary for their duties

13. Your Obligations

As the Data Controller, you are responsible for:

  • Ensuring you have a lawful basis to process and share Personal Data with us
  • Obtaining necessary consents from Data Subjects
  • Providing required privacy notices to Data Subjects
  • Ensuring the accuracy of Personal Data provided to us
  • Responding to Data Subject requests (with our assistance)

14. Term and Termination

This DPA remains in effect for the duration of your use of our Services. Upon termination:

  • We will cease processing Personal Data except as required by law
  • We will delete or return all Personal Data within 90 days
  • We will provide certification of deletion upon request

15. Governing Law

This DPA is governed by the laws specified in our Terms of Service. For EU Data Subjects, GDPR and applicable member state laws apply to the processing of their Personal Data.

16. Contact Information

For questions about this DPA or to exercise your rights, contact us:

Request a Signed DPA

Enterprise customers requiring a signed Data Processing Agreement can request one by contacting our legal team. We'll provide a customized agreement that meets your organization's requirements.

Request Signed DPA