This addendum forms part of the terms of service between you (the controller) and Posthaste (the processor). It applies whenever we process personal data on your behalf. Where it conflicts with the terms of service, this addendum takes precedence for that processing.
1. Scope of the processing
- Subject matter
- Delivery of transactional email you submit, and recording what happened to it.
- Duration
- For as long as your account is open, plus the retention periods in section 8.
- Nature and purpose
- Receiving, storing, signing and transmitting messages; parsing bounce and complaint reports; maintaining a suppression list and a delivery record.
- Types of personal data
- Recipient email addresses, sender addresses, subject lines, message content you choose to include, and the responses receiving servers give.
- Categories of data subject
- Your users, customers and anyone else you send transactional mail to.
You decide what goes into a message. Please do not put special category data — health, biometric, political or similar — into transactional email that does not need it; email is not a confidential channel end to end, however well we handle our part.
2. Our obligations
- We process personal data only on your documented instructions. Using the API is an instruction; so is a written request to us.
- If we believe an instruction breaches data protection law, we will tell you.
- Everyone with access is bound by confidentiality obligations.
- We do not use your recipients’ data for our own purposes, and we do not use message content to train anything.
3. Security
We implement appropriate technical and organisational measures, including tenant isolation enforced by database row-level security, encryption of signing keys at rest, hashing of API secrets, TLS in transit, and an append-only, hash-linked delivery record. These are described in detail on the security page, which forms part of this addendum by reference.
4. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, with what each processes and where, is at posthastemail.dev/legal/subprocessors.
We will give at least 30 days’ notice by email before adding or replacing one. If you reasonably object on data protection grounds, tell us within that period and we will work to find an alternative; if we cannot, you may terminate the affected service and receive a refund of prepaid fees for the unused period.
Each sub-processor is bound by terms no less protective than these, and we remain liable for their performance.
5. International transfers
Our processing takes place in the European Union. Where a sub-processor transfers data outside the UK or EEA, that transfer relies on an adequacy decision or on standard contractual clauses, as noted per provider on the sub-processors page.
6. Assisting you
We will help you, so far as is reasonable and taking account of the nature of the processing, with:
- responding to requests from data subjects — the API exposes the delivery records and suppression entries relating to any address;
- data protection impact assessments and prior consultations; and
- demonstrating compliance with your own obligations.
If a data subject contacts us directly about data we hold on your behalf, we will not respond substantively; we will pass it to you promptly.
7. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe what we know, what we are doing, and what we recommend you do — and we will keep sending updates as it develops rather than waiting until we have a complete picture.
8. Deletion and return
On termination you may export your delivery records through the API for 30 days. After that we delete personal data processed on your behalf within 90 days, except where we are required to retain it by law.
One deliberate exception: suppression entries are retained. Deleting them would mean sending again to addresses that bounced or complained, which harms the very people the record exists to protect. Entries are held as a hash of the address, not the address itself, wherever the design allows.
9. Audit
We will make available the information reasonably needed to demonstrate compliance with this addendum, and will contribute to audits carried out by you or an auditor you appoint, on reasonable notice, no more than once a year unless a supervisory authority requires otherwise or there has been a breach.
We are not currently SOC 2 or ISO 27001 certified and do not offer a certification report in place of an audit. When that changes, this section will change with it.
10. Signing this
Accepting the terms of service accepts this addendum, and no signature is needed. If your procurement process requires a countersigned copy, email [email protected] and we will sign one.