Data Processing Agreement (DPA)
Our formal agreement outlining our legal obligations as a Data Processor under GDPR, CCPA, and international data protection laws.
Last updated: September 1, 2026
This Data Processing Agreement ("DPA") is a supplement to the Terms of Service and applies where eMailBase processes personal data on behalf of customers in the provision of the SaaS Email Marketing & Automation platform. The DPA should be read in conjunction with the Privacy Policy.
In the event of a conflict between this DPA and the Terms of Service regarding data protection, the provisions of the DPA shall prevail.
1. Definitions and Scope
1.1. Definitions
The terms in this DPA have the meaning set out in the GDPR (EU Regulation 2016/679) and other applicable data protection laws:
- Data Controller: The customer — the party that determines the purposes and means of processing Subscriber Data.
- Data Processor: eMailBase — data processor on behalf of the Controller to provide services.
- Personal Data: Any information relating to an identified or identifiable individual.
- Subscriber Data: Personal data about email recipients that the Controller uploads to or processes through eMailBase.
- Sub-processor: Third party authorized by eMailBase to process part of Subscriber Data.
- Data Breach: Security breach resulting in destruction, loss, alteration, unauthorized disclosure or access of Personal Data.
1.2. Scope
This DPA applies when:
- Customers use eMailBase to process subscribers' personal data;
- Personal data of data subjects located in the European Union (EEA), the United Kingdom or areas with equivalent data protection laws;
- Applicable data protection legislation requires a data processing agreement between the controller and the processor.
2. Roles of the Parties
- Customer (Controller): Determines the purposes of collection, email content, intended recipients, and lawful basis for processing Subscriber Data. The customer is responsible for ensuring a valid lawful basis, such as consent or legitimate interests, for collecting and using data on the platform.
- eMailBase (Processor): Process Subscriber Data in accordance with the Controller's lawful instructions, to the extent necessary to provide the services in accordance with the Terms of Service. eMailBase does not use Subscriber Data for purposes other than providing services.
3. Scope and Purpose of Processing
3.1. Processing Activities
Processing may include:
- Store and organize Subscriber Data in the workspace;
- Segment, tag, and manage recipient lists;
- Transmit recipient data to sending provider (BYO) according to campaign configuration;
- Execute automation flows based on events and conditions;
- Capture interaction data (opens, clicks, unsubscribes, bounce emails);
- Data enrichment via SocialEnrich when customers activate;
- Report generation, analysis and technical support.
3.2. Categories of Personal Data
- Contact information: email address, full name, phone number;
- Demographic information: title, company, geographical location;
- Customer-defined custom fields;
- Interaction data: open, click, unsubscribe history;
- Technical data: Access IP, user agent (when related to email interaction).
3.3. Categories of Data Subjects
Subscribers, email recipients, leads, and other individuals whose data the Controller uploads to or processes through the platform.
4. Controller Instructions
- eMailBase processes Subscriber Data only in accordance with the written instructions (including instructions through the platform interface) of the Controller, unless otherwise required by EU or national law.
- If eMailBase becomes aware that the Controller's instructions may violate the GDPR or applicable data protection laws, eMailBase will immediately notify the Controller (unless notification is prohibited by law).
- eMailBase ensures that employees with access to Subscriber Data have committed to confidentiality or are under a legal obligation of confidentiality.
5. Technical and Organizational Measures
eMailBase takes appropriate technical and organizational measures to protect Subscriber Data, including:
- Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (disk encryption, separately encrypted API keys).
- Access control: Decentralization according to the principle of least privilege, multi-factor authentication for internal administration systems.
- Data isolation: Workspace data is logically isolated between customers.
- Backup & Restore:Regular backups with recovery in case of failure.
- Monitoring: Monitor access logs, anomaly detection and automatic security alerts.
- Training: Employees are trained in data protection and information security.
6. Sub-processors
6.1. General Authorization
The Controller grants eMailBase general written authorization to engage sub-processors in support of the Services. Current sub-processor categories include:
- Cloud infrastructure provider: Stores and processes data on the server.
- Payment provider: Processes payment transactions.
- Analytics provider: Aggregated analysis of service usage.
Note: An email delivery provider (such as Amazon SES, SendGrid, Mailgun, or Gmail) connected by the customer under the BYO model is not an eMailBase sub-processor. The customer has a direct relationship with that sending provider and is responsible for complying with its terms.
6.2. Change Notification Process
- eMailBase will notify the Controller before adding or replacing a sub-processor, at least 30 days before the change takes effect.
- If the Controller objects to a new sub-processor, the parties will work in good faith to resolve the concern. If no agreement is reached, the Controller may terminate the affected Service.
6.3. Responsibility
eMailBase remains responsible for its sub-processors' performance within the scope of the Services and requires them to observe data-protection obligations that are no less protective than those in this DPA.
7. International Data Transfers
- eMailBase may process Subscriber Data in data centers in multiple geographies.
- When data is transferred outside the EEA or an area with equivalent data protection regulations, eMailBase applies the Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914).
- Additional technical protection measures (end-to-end encryption, pseudonymization) are applied where necessary according to EDPB (European Data Protection Board) recommendations.
- The Controller may request a signed copy of the SCC by contacting hi@emailbase.net.
8. Assistance with Data Subject Rights
eMailBase supports the Controller in fulfilling its obligations regarding data subject rights:
- Access rights: Provide data export tools for Controllers to respond to access requests.
- Edit rights: Controllers can edit Subscriber Data directly in the workspace.
- Right to deletion: The controller can delete specific contacts or the entire list. eMailBase deletes data from the system within a reasonable time after receiving the request.
- Right to data portability: The controller can export data in CSV format or via API.
- Right to Restrict & Object: The Controller may suspend processing by deactivating the relevant campaign or automation.
If eMailBase receives a request directly from a data subject, eMailBase will forward the request to the Controller (unless a direct response is required by law) within a reasonable time.
9. Personal Data Breach Notification
- eMailBase will notify the Controller no later than 72 hours after detecting a data incident affecting Subscriber Data.
- The notice will include (to the extent information is available):
- The nature of the problem and the type of data affected;
- Estimated number of data subjects affected;
- Possible consequences;
- Measures have been and are being implemented to overcome and minimize impacts.
- eMailBase cooperates with the Controller in investigating, remediating and notifying supervisory authorities/data subjects when required by law.
10. Data Protection Impact Assessment (DPIA)
eMailBase supports the Controller in carrying out a Data Protection Impact Assessment (DPIA) when processing activities are likely to create a high risk to the rights and freedoms of data subjects, by:
- Providing information about processing activities, security measures, and sub-processors;
- Coordinate within reasonable scope to support risk assessment;
- Supporting consultations with data protection supervisory authorities when necessary (in accordance with Article 36 GDPR).
11. Audits and Compliance Evidence
- eMailBase provides the Controller with necessary information to demonstrate compliance with obligations under GDPR Article 28.
- The Controller (or authorized third party auditor) has the right to perform audits, including on-site inspections, provided that:
- Reasonable advance notice (minimum 30 days);
- Do not cause undue disruption to eMailBase operations;
- The auditor is subject to an appropriate duty of confidentiality;
- No more than one audit in any 12-month period, unless a Personal Data Breach occurs or a supervisory authority requests otherwise.
- eMailBase may provide compliance reports, security certifications (when available) as an alternative to on-site audits if the Controller agrees.
12. Termination and Data Deletion
- When the service ends or at the request of the Controller, eMailBase will:
- Support the Controller in exporting all Subscriber Data in a structured format such as CSV or via API;
- Delete or anonymize Subscriber data for a period of 90 days after service ends, unless longer retention is required by law;
- Provide written confirmation of deletion at the Controller's request.
- The controller should complete the data export before terminating the account. eMailBase is not responsible for data not exported before the deletion deadline.
- The confidentiality obligations in this DPA continue after the end of the service until the data is completely erased.
Contact
To discuss a DPA, request a copy of an SCC, a compliance report or submit a data related request:
- Email: hi@emailbase.net
- Subject: Specify "DPA" or "Data Processing Request"