Legal

Data Processing Addendum

Learn how AutoSend processes personal data on your behalf, including our sub-processors, security measures, and international transfer safeguards.

Last updated at : Aug 27, 2026

This Data Processing Addendum, together with its Annexes and the Standard Contractual Clauses incorporated by reference (the "DPA"), forms part of the Terms and Conditions or other written agreement between Peerlist Inc., a Delaware corporation operating the AutoSend email platform ("AutoSend", "we", "us"), and the customer identified in that agreement ("Customer", "you") governing Customer's use of that platform (the "Agreement").

Peerlist Inc. operates products other than AutoSend. This DPA applies only to Customer's use of the Services as defined below, and does not apply to, vary, or supplement the terms governing any other product or service operated by Peerlist Inc. or its Affiliates. References to "AutoSend" in this DPA mean Peerlist Inc. acting in its capacity as the operator of the Services.

This DPA becomes binding on both parties on the date Customer accepts the Agreement, or on the date Customer executes this DPA separately, whichever is earlier. No signature is required for this DPA to take effect. The Execution section below explains how to obtain a countersigned copy.

Capitalised terms not defined here have the meaning given in the Agreement.

Definitions

  • "Account Data" means personal data relating to AutoSend's commercial relationship with Customer, including the names, email addresses, job titles, and login credentials of the individuals Customer authorises to access its account, and billing and payment records associated with that account.
  • "Affiliate" means any entity that controls, is controlled by, or is under common control with a party, where control means ownership of more than fifty percent of the voting interests of that entity.
  • "Customer Personal Data" means personal data contained in Customer Data that AutoSend processes on Customer's behalf under the Agreement.
  • "Data Protection Laws" means all laws and regulations applicable to a party's processing of personal data under this DPA, including: (a) Regulation (EU) 2016/679 (the "EU GDPR"); (b) the EU GDPR as incorporated into the law of England and Wales, Scotland, and Northern Ireland by section 3 of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018 (the "UK GDPR"); (c) the Swiss Federal Act on Data Protection of 25 September 2020 (the "FADP"); (d) the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA") and other US state privacy laws; and (e) any successor or replacement legislation. References to the "GDPR" mean the EU GDPR and the UK GDPR together.
  • "EU SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
  • "Restricted Transfer" means a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that is not the subject of an adequacy decision under the applicable Data Protection Laws.
  • "Sub-processor" means any third party engaged by AutoSend to process Customer Personal Data in connection with the provision of the Services, including AutoSend's Affiliates.
  • "Services" means the AutoSend email sending, receiving, automation, and analytics platform and any related services provided under the Agreement.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022.
  • "Usage Data" means data generated by AutoSend through the operation of the Services, including delivery and engagement logs, diagnostic and performance telemetry, and data used to detect and prevent abuse of the platform.

The terms "controller", "processor", "data subject", "personal data", "personal data breach", "processing", and "supervisory authority" have the meanings given in the GDPR.

Scope and Roles of the Parties

This DPA applies to AutoSend's processing of Customer Personal Data in the course of providing the Services.

As between the parties, Customer is the controller of Customer Personal Data, or where Customer is itself acting as a processor for a third party, Customer is a processor and AutoSend is a sub-processor. AutoSend processes Customer Personal Data solely as a processor on Customer's behalf.

AutoSend is an independent controller in respect of Account Data and Usage Data. The AutoSend as Controller section below sets out how AutoSend processes that data.

Annex I sets out the subject matter, duration, nature, and purpose of the processing, the types of personal data processed, and the categories of data subjects, as required by Article 28(3) of the GDPR.

Customer Obligations

Customer is responsible for the accuracy, quality, and lawfulness of Customer Personal Data, for the means by which it obtained that data, and for the instructions it gives AutoSend regarding its processing.

Customer warrants that it has a valid legal basis under Data Protection Laws for the processing it instructs AutoSend to perform, that it has provided any notices and obtained any consents required from data subjects, and that its instructions will not cause AutoSend to breach Data Protection Laws.

Customer will not submit to the Services any special categories of personal data within the meaning of Article 9 of the GDPR, data relating to criminal convictions or offences, government identification numbers, financial account credentials, or protected health information, unless the parties have agreed in writing to additional safeguards for that data. AutoSend is not a HIPAA business associate and the Services are not designed for the processing of regulated health data.

AutoSend's Processing Obligations

Documented instructions. AutoSend will process Customer Personal Data only on Customer's documented instructions, including with regard to transfers of personal data to a third country or an international organisation. The Agreement, this DPA, and the configuration and API calls Customer makes through the Services together constitute Customer's complete documented instructions. AutoSend will not process Customer Personal Data for any other purpose.

Legally required processing. Where AutoSend is required by Union, Member State, or other applicable law to process Customer Personal Data other than on Customer's instructions, AutoSend will inform Customer of that legal requirement before processing, unless the law in question prohibits such disclosure on important grounds of public interest.

Unlawful instructions. AutoSend will immediately inform Customer if, in AutoSend's opinion, an instruction from Customer infringes the GDPR or any other Data Protection Law. AutoSend may suspend performance of the instruction until Customer confirms, withdraws, or amends it.

No sale of data. AutoSend will not sell, rent, license, or otherwise make available Customer Personal Data to any third party, and will not use Customer Personal Data to build or improve independent products or services other than the Services provided to Customer.

Confidentiality

AutoSend will ensure that every person it authorises to process Customer Personal Data, whether an employee, contractor, or officer, is bound by a written confidentiality undertaking that survives the end of their engagement, or is under an appropriate statutory obligation of confidentiality.

AutoSend will limit access to Customer Personal Data to those personnel who require access to perform AutoSend's obligations under the Agreement, and will apply the principle of least privilege to that access.

AutoSend personnel with access to Customer Personal Data receive data protection and security training on onboarding and at regular intervals thereafter.

Security

Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of data subjects, AutoSend will implement and maintain the technical and organisational measures set out in Annex II in order to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR.

AutoSend may update the measures in Annex II from time to time, provided that no update materially reduces the overall level of security of the Services.

Customer is responsible for the security of its own systems, for safeguarding its API keys and account credentials, and for configuring the access controls available within the Services appropriately for its use case.

Sub-processors

General authorisation. Customer gives AutoSend general written authorisation to engage Sub-processors to process Customer Personal Data in connection with the Services, in accordance with Article 28(2) of the GDPR.

Current list. AutoSend maintains a current list of its Sub-processors at autosend.com/legal/subprocessors, including the identity of each Sub-processor, its location, and the processing it performs.

Notice of changes. AutoSend will give Customer at least thirty (30) days' prior notice of the addition or replacement of any Sub-processor. Notice will be given by email to the administrative address associated with Customer's account, and the change will be reflected on the page referred to above. Customer is responsible for keeping a monitored address on file.

Objection. Customer may object to a proposed Sub-processor on reasonable data protection grounds by giving written notice within thirty (30) days of AutoSend's notice. The parties will discuss the objection in good faith. If AutoSend is unable to offer a commercially reasonable alternative within thirty (30) days of the objection, Customer may terminate the affected Services on written notice without penalty and will not receive a refund of any prepaid fees for the terminated portion of the subscription term.

Flow down. AutoSend will enter into a written agreement with each Sub-processor imposing data protection obligations that are no less protective than those imposed on AutoSend under this DPA.

Liability. AutoSend remains fully liable to Customer for the performance of each Sub-processor's data protection obligations.

Data Subject Rights

Taking into account the nature of the processing, AutoSend will assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.

The Services include self-service functionality allowing Customer to access, export, correct, suppress, and delete recipient records, including contact data and associated engagement history. Customer will use that functionality to respond to data subject requests in the first instance.

If AutoSend receives a request directly from a data subject relating to Customer Personal Data, AutoSend will not respond to the substance of the request other than to acknowledge it and direct the data subject to Customer, and will notify Customer without undue delay unless prohibited by law.

Where Customer cannot satisfy a data subject request using the functionality of the Services, AutoSend will provide reasonable additional assistance. AutoSend may charge a reasonable fee for assistance that is disproportionate to the nature of the request, and will notify Customer of any such fee before incurring it.

Personal Data Breaches, Impact Assessments, and Consultation

Breach notification. AutoSend will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.

The notification will include, to the extent known at the time and supplemented as further information becomes available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information.

AutoSend will provide Customer with reasonable cooperation and assistance necessary for Customer to meet its own obligations under Articles 33 and 34 of the GDPR, taking into account the nature of the processing and the information available to AutoSend.

AutoSend's notification of a breach is not an acknowledgement of fault or liability.

Impact assessments. Taking into account the nature of the processing and the information available to it, AutoSend will provide Customer with reasonable assistance with data protection impact assessments under Article 35 of the GDPR and with prior consultation of a supervisory authority under Article 36, to the extent that the assessment or consultation relates to AutoSend's processing and Customer does not otherwise have access to the necessary information.

Deletion and Return of Data

On termination or expiry of the Agreement or where there is no active subscription, AutoSend will, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless retention is required by applicable law.

Customer may export its data through the Services at any time during the term and for 60 days after termination. Customer must notify AutoSend in writing within that period if it requires return of the data in another form.

Absent an election by Customer, AutoSend will delete Customer Personal Data from its production systems within 60 days of termination. Residual copies held in encrypted backups will be deleted in the ordinary course of AutoSend's backup rotation, within 90 days of termination, and will remain subject to this DPA until deleted.

AutoSend may retain Customer Personal Data to the extent required by applicable law, and may retain suppression list entries, being email addresses that have unsubscribed, hard bounced, or registered a spam complaint, indefinitely, for the sole purpose of preventing further email being sent to those addresses. This retention is necessary to comply with obligations under anti-spam law and is limited to the address and the suppression reason.

AutoSend will provide written certification of deletion on Customer's request.

AutoSend as Controller

AutoSend processes Account Data and Usage Data as an independent controller, not as a joint controller with Customer, for the following purposes: managing the customer relationship and providing support; billing, accounting, tax, and audit; verifying identity and preventing fraud; detecting, investigating, and preventing abuse of the platform, spam, and security incidents; maintaining, securing, and improving the reliability and deliverability of the Services; producing aggregated and de-identified statistics; and complying with legal obligations.

AutoSend's processing as a controller is described in the AutoSend Privacy Policy.

AutoSend will not use the content of Customer's emails or the contact details of Customer's recipients for its own marketing purposes.

Audits and Information

AutoSend will make available to Customer all information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the GDPR and this DPA.

Documentation first. Customer will exercise its audit rights in the first instance by requesting AutoSend's then-current security documentation, which may include a penetration test summary, AutoSend's information security policies, completed security questionnaires, and any third-party audit report or certification AutoSend then holds. AutoSend will respond within thirty (30) days of a written request, no more than once in any twelve-month period, and will provide the documentation under the confidentiality terms of the Agreement. The parties agree that this documentation is ordinarily sufficient to demonstrate AutoSend's compliance with Article 28 of the GDPR and Clause 8.9 of the EU SCCs.

Further audit. Where Customer can demonstrate, by reference to specific and documented deficiencies, that the materials provided under Documentation first are insufficient to demonstrate AutoSend's compliance, or following a personal data breach affecting Customer Personal Data, or where a supervisory authority with jurisdiction over Customer directs an audit, Customer may conduct or mandate an independent auditor to conduct an audit of AutoSend's processing, subject to the following:

  • Customer gives at least thirty (30) days' prior written notice specifying the scope, the deficiencies relied on, and the identity and qualifications of any mandated auditor.
  • The audit is conducted remotely, by written enquiry, document review, and video conference, unless the parties agree in writing that a specific matter cannot reasonably be assessed remotely.
  • The audit is limited to systems, records, and personnel relevant to the processing of Customer Personal Data, and does not extend to AutoSend's source code, commercial information, information relating to other customers, or any information the disclosure of which would compromise the security of the Services or breach an obligation owed to a third party.
  • The audit is conducted by no more than two (2) representatives, over no more than three (3) business days, during AutoSend's business hours, and in a manner that does not unreasonably disrupt AutoSend's operations.
  • Any mandated auditor is independent, is not a competitor of AutoSend, and executes a confidentiality undertaking in favour of AutoSend before receiving any information.
  • Audits under this section take place no more than once in any twelve-month period, except where directed by a supervisory authority or following a personal data breach affecting Customer Personal Data.
  • AutoSend may satisfy an audit request under this section by arranging for an independent third-party auditor of AutoSend's selection to conduct the audit against the scope Customer has specified, and providing Customer with the resulting report.

Costs. Customer bears its own costs of a further audit, the costs of any mandated auditor, and AutoSend's reasonable costs of preparing for and participating in the audit, charged at AutoSend's then-current professional services rates. AutoSend will provide a good faith estimate of those costs before the audit begins and will not proceed until Customer confirms in writing. This does not apply where the audit identifies material non-compliance by AutoSend, in which case AutoSend bears its own costs and will remediate at its expense.

AutoSend will contribute to audits and inspections conducted by Customer or an auditor mandated by Customer as required by Article 28(3)(h) of the GDPR.

Nothing in this section limits the rights of a supervisory authority, or of a controller on whose behalf Customer acts, to the extent those rights cannot be limited by contract.

International Transfers

Customer acknowledges that AutoSend's processing operations take place primarily in the United States and that transfer of Customer Personal Data to the United States is necessary for the provision of the Services.

Where a Restricted Transfer occurs, the parties agree that the transfer is made subject to the EU SCCs, which are incorporated into this DPA by reference and completed as follows:

  • Modules. Module Two (controller to processor) applies where Customer is a controller. Module Three (processor to processor) applies where Customer is a processor acting on behalf of a third-party controller.
  • Clause 7 (docking clause): does not apply.
  • Clause 9 (sub-processors): Option 2, general written authorisation, applies. The notice period is the period stated in the Sub-processors section of this DPA.
  • Clause 11 (redress): the optional independent dispute resolution language does not apply.
  • Clause 13 and Annex I.C: the competent supervisory authority is the authority identified in Annex I.
  • Clause 17 (governing law): Option 1 applies. The EU SCCs are governed by the law of Ireland.
  • Clause 18(b) (forum): disputes will be resolved before the courts of Ireland.
  • Annexes: Annex I of this DPA populates Annex I of the EU SCCs. Annex II of this DPA populates Annex II of the EU SCCs. Annex III of this DPA, together with the list at autosend.com/legal/subprocessors, populates Annex III of the EU SCCs.

United Kingdom. For Restricted Transfers from the United Kingdom, the EU SCCs apply as amended by the UK Addendum, which is incorporated by reference. In Table 4 of the UK Addendum, neither party may end the Addendum as set out in Section 19 of it. The information required by Tables 1 to 3 is taken from this DPA and its Annexes.

Switzerland. For Restricted Transfers from Switzerland, the EU SCCs apply with the following modifications: references to the GDPR are read as references to the FADP where the FADP applies; the competent supervisory authority is the Federal Data Protection and Information Commissioner in respect of transfers governed by the FADP; the clauses also protect the data of legal entities to the extent required by the FADP; and data subjects in Switzerland may enforce their rights in Switzerland.

Government access requests. AutoSend has not, as at the date of this DPA, received any request from a public authority for access to Customer Personal Data. If AutoSend receives such a request, it will, unless legally prohibited: notify Customer without undue delay; seek to redirect the requesting authority to Customer; challenge any request that is unlawful or overbroad; and disclose only the minimum amount of data lawfully required. AutoSend will not voluntarily disclose Customer Personal Data to any public authority.

Alternative mechanisms. If the transfer mechanism relied on under this section ceases to be valid, or a supervisory authority requires transfers under it to be suspended, the parties will cooperate in good faith to put in place an alternative lawful transfer mechanism without undue delay.

United States State Privacy Laws

For the purposes of the CCPA and comparable US state privacy laws, AutoSend acts as a "service provider" or "processor" in respect of Customer Personal Data, and Customer acts as a "business" or "controller".

AutoSend will not: sell or share Customer Personal Data as those terms are defined in the CCPA; retain, use, or disclose Customer Personal Data for any purpose other than performing the Services specified in the Agreement, or as otherwise permitted by the CCPA; retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or combine Customer Personal Data with personal information received from another source, except as permitted by the CCPA.

AutoSend certifies that it understands and will comply with these restrictions.

AutoSend will notify Customer if it determines that it can no longer meet its obligations under applicable US state privacy laws, and Customer may on notice take reasonable steps to stop and remediate unauthorised use of personal information.

General

Order of precedence. In the event of conflict, the order of precedence is: (1) the EU SCCs and the UK Addendum, where applicable; (2) this DPA; (3) the Agreement; (4) the AutoSend Privacy Policy.

Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable law, including a data subject's rights under the EU SCCs.

Term. This DPA takes effect on the effective date and continues until AutoSend ceases to process Customer Personal Data. The Confidentiality, Deletion and Return of Data, Audits and Information, and General sections survive termination.

Changes. AutoSend may update this DPA where necessary to reflect changes in Data Protection Laws, changes to the Services, or the adoption of new transfer mechanisms, provided that no update materially reduces Customer's protections. AutoSend will give at least thirty (30) days' notice of any material change.

Governing law. Except as provided in International Transfers, this DPA is governed by the law stated in the Agreement.

Contact. Data protection enquiries may be sent to [email protected].

Execution

This DPA is binding on Customer and AutoSend on acceptance of the Agreement, in accordance with Article 28(9) of the GDPR, which permits a processing contract to be concluded in electronic form. No signature is required and the absence of one does not affect the validity or enforceability of this DPA.

Where Customer's procurement or compliance process requires a countersigned copy, Customer may request one at [email protected]. AutoSend will return an executed PDF of this DPA, on identical terms, naming Customer's legal entity.

Annex I: Details of Processing

A. List of Parties

Data exporter (controller or processor)

  • Name: Customer, as identified in the Agreement.
  • Address and contact: as recorded in Customer's AutoSend account.
  • Activities relevant to the transfer: use of the AutoSend platform to send, receive, and analyse email.
  • Role: controller, or processor where Customer processes on behalf of a third-party controller.
  • Signature and date: execution of the Agreement constitutes execution of the EU SCCs by both parties.

Data importer (processor)

  • Name: Peerlist Inc., operating AutoSend.
  • Address: 8 The Green St, Dover, Delaware 19901.
  • Contact: [email protected].
  • Activities relevant to the transfer: provision of the AutoSend email sending, receiving, automation, and analytics platform.
  • Role: processor, or sub-processor where Customer is a processor.
  • Signature and date: execution of the Agreement constitutes execution of the EU SCCs by both parties.

B. Description of the Processing

Subject matter. AutoSend's provision of the Services to Customer under the Agreement.

Duration. For the term of the Agreement, plus the retention periods set out in the Deletion and Return of Data section of this DPA.

Nature of the processing. Collection, receipt, storage, transmission, retrieval, analysis, organisation, erasure, and destruction of personal data, carried out in order to send, receive, queue, route, deliver, log, and report on email messages, to maintain contact lists and suppression lists, and to run automations and campaigns configured by Customer.

Purpose. To enable Customer to deliver transactional and marketing email to its recipients and to provide Customer with delivery, engagement, and deliverability reporting.

Categories of data subjects.

  • Recipients of email sent by Customer through the Services, being Customer's own users, customers, subscribers, or contacts.
  • Senders of email received by Customer through AutoSend's inbound processing, where enabled.
  • Individuals whose personal data Customer includes in the content of a message, in contact metadata, or in custom fields.
  • Where Customer is a processor, the data subjects of Customer's own controller clients.

Categories of personal data.

  • Contact identifiers: email address, name, and any other contact fields Customer chooses to store.
  • Message data: subject line, message body, headers, attachments, and any personal data Customer includes in them.
  • Custom attributes and segmentation data uploaded or synced by Customer.
  • Delivery and engagement data: timestamps, delivery status, bounce and complaint records, and, where Customer enables tracking, open and click events with associated IP address, approximate location derived from IP, user agent, device, and email client.
  • Subscription status, including opt-in records and suppression status.

Special category data. The Services are not intended for the processing of special categories of personal data. Customer is contractually prohibited from submitting such data under the Customer Obligations section without a prior written agreement setting out additional safeguards.

Frequency of transfer. Continuous, for the duration of the Agreement.

Retention. As set out in the Deletion and Return of Data section of this DPA, and as follows:

Message content, being the subject, body, attachments, and merge data of each message, together with the per-message delivery record, is available to Customer through the Services for the data retention period applicable to Customer's plan, as published at autosend.com/pricing. Content is deleted at the end of that period.

Delivery and engagement metadata, being the recipient address, timestamps, delivery status, bounce and complaint codes, and, where Customer enables tracking, open and click events, is retained for up to 180 days from the date of send and is then deleted or irreversibly aggregated. Retention beyond the plan period is limited to what is necessary for deliverability and sender reputation management, abuse and fraud prevention, billing reconciliation, and responding to complaints from mailbox providers and supervisory authorities, and this data is not accessible to Customer through the Services after the plan period ends.

Contact records are retained until deleted by Customer or until termination. Suppression list entries are retained as described in that section.

Sub-processor processing. Sub-processors process personal data for the subject matter, nature, and duration described above, limited to the specific function each performs as described at autosend.com/legal/subprocessors.

C. Competent Supervisory Authority

Where the EU SCCs apply, the competent supervisory authority is determined under Clause 13 of the EU SCCs, being the supervisory authority of the Member State in which the data exporter is established, or where the data exporter is not established in the EEA, the supervisory authority of the Member State in which the data exporter's Article 27 representative is established, or in which the data subjects whose data is transferred are located.

Where the UK Addendum applies, the competent authority is the Information Commissioner's Office. Where the FADP applies, the competent authority is the Federal Data Protection and Information Commissioner.

Annex II: Technical and Organisational Measures

Governance

AutoSend maintains a documented information security programme, reviewed at least annually, covering access control, secure development, incident response, vendor management, and business continuity. A named member of the leadership team is accountable for information security. Personnel receive security and data protection training at onboarding and annually thereafter, and are subject to written confidentiality obligations.

Access Control

  • Access to production systems and to Customer Personal Data is restricted to personnel with a defined operational need, granted on a least-privilege basis and reviewed at least quarterly.
  • Access to production infrastructure requires multi-factor authentication.
  • Administrative access is individually attributed. Shared accounts are not used for administrative access to production.
  • Access is revoked promptly on change of role or termination of engagement.
  • Customer-facing authentication supports two-factor authentication. API access is authenticated with scoped API keys that Customer can rotate and revoke.
  • Customer data is logically segregated per account, and application-layer authorisation checks enforce tenant isolation on every request.

Encryption

  • All data in transit between Customer and the Services is encrypted using TLS 1.2 or above.
  • Data at rest, including databases and backups, is encrypted using AES-256 or equivalent.
  • Secrets, API keys, and credentials are stored encrypted and are not written to application logs.
  • Passwords are stored using a modern memory-hard hashing algorithm with per-user salting.

Pseudonymisation and Minimisation

AutoSend collects only the data necessary to provide the Services. Engagement tracking is configurable by Customer and can be disabled. Aggregated statistics used for service improvement are de-identified.

Infrastructure and Physical Security

Production infrastructure is hosted with third-party cloud providers operating data centres that maintain recognised security certifications, including SOC 2 Type II and ISO 27001. AutoSend personnel have no physical access to those facilities. AutoSend does not operate its own data centres.

Resilience and Availability

  • Production data is backed up on a daily schedule, with backups encrypted and retained for 90 days.
  • Restore procedures are tested at least annually.
  • The platform is architected across multiple availability zones to avoid single points of failure.
  • Service availability is published at status.autosend.com.

Secure Development

  • Code changes are peer reviewed before merge.
  • Automated dependency scanning and static analysis run in the build pipeline.
  • Development, staging, and production environments are separated. Production Customer Personal Data is not used in development or test environments.

Logging and Monitoring

Access to production systems and to Customer Personal Data is logged. Logs are retained for 30 days and are protected against unauthorized modification. Automated alerting is in place for anomalous authentication activity, error rate deviations, and abuse signals.

Incident Response

AutoSend maintains a documented incident response plan defining severity levels, escalation paths, containment and remediation steps, customer notification, and post-incident review. The plan is reviewed at least annually. Notification obligations are set out in the Personal Data Breaches, Impact Assessments, and Consultation section of this DPA.

Vendor Management

Sub-processors are assessed for security and data protection posture before engagement and reviewed periodically. Each is bound by a written agreement imposing obligations no less protective than those in this DPA.

Deletion

Customer can delete contact records and associated data through the application and the API. Deletion propagates to production systems immediately and to backups within the backup rotation period described in the Deletion and Return of Data section.

Annex III: Sub-processors

The current list of Sub-processors, including each Sub-processor's name, function, and country of processing, is maintained at autosend.com/legal/subprocessors. That list forms part of this DPA and populates Annex III of the EU SCCs. Changes are notified in accordance with the Sub-processors section above.

Still wondering?

See what your favorite LLM has to say about us, then make an informed decision.