Legal

Data processing addendum

Where you are the controller of your recipients' data and we are your processor, these are the terms that govern it.

Last updated

Draft, pending legal review. Posthaste is in private testing and these terms have not yet been reviewed by a solicitor. They describe how we actually intend to operate, but they are not a substitute for the reviewed version that will replace them before general availability. Questions in the meantime: get in touch.

This addendum forms part of the terms of service between you (the controller) and Posthaste (the processor). It applies whenever we process personal data on your behalf. Where it conflicts with the terms of service, this addendum takes precedence for that processing.

1. Scope of the processing

Subject matter
Delivery of transactional email you submit, and recording what happened to it.
Duration
For as long as your account is open, plus the retention periods in section 8.
Nature and purpose
Receiving, storing, signing and transmitting messages; parsing bounce and complaint reports; maintaining a suppression list and a delivery record.
Types of personal data
Recipient email addresses, sender addresses, subject lines, message content you choose to include, and the responses receiving servers give.
Categories of data subject
Your users, customers and anyone else you send transactional mail to.

You decide what goes into a message. Please do not put special category data — health, biometric, political or similar — into transactional email that does not need it; email is not a confidential channel end to end, however well we handle our part.

2. Our obligations

3. Security

We implement appropriate technical and organisational measures, including tenant isolation enforced by database row-level security, encryption of signing keys at rest, hashing of API secrets, TLS in transit, and an append-only, hash-linked delivery record. These are described in detail on the security page, which forms part of this addendum by reference.

4. Sub-processors

You give general authorisation for us to engage sub-processors. The current list, with what each processes and where, is at posthastemail.dev/legal/subprocessors.

We will give at least 30 days’ notice by email before adding or replacing one. If you reasonably object on data protection grounds, tell us within that period and we will work to find an alternative; if we cannot, you may terminate the affected service and receive a refund of prepaid fees for the unused period.

Each sub-processor is bound by terms no less protective than these, and we remain liable for their performance.

5. International transfers

Our processing takes place in the European Union. Where a sub-processor transfers data outside the UK or EEA, that transfer relies on an adequacy decision or on standard contractual clauses, as noted per provider on the sub-processors page.

6. Assisting you

We will help you, so far as is reasonable and taking account of the nature of the processing, with:

If a data subject contacts us directly about data we hold on your behalf, we will not respond substantively; we will pass it to you promptly.

7. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe what we know, what we are doing, and what we recommend you do — and we will keep sending updates as it develops rather than waiting until we have a complete picture.

8. Deletion and return

On termination you may export your delivery records through the API for 30 days. After that we delete personal data processed on your behalf within 90 days, except where we are required to retain it by law.

One deliberate exception: suppression entries are retained. Deleting them would mean sending again to addresses that bounced or complained, which harms the very people the record exists to protect. Entries are held as a hash of the address, not the address itself, wherever the design allows.

9. Audit

We will make available the information reasonably needed to demonstrate compliance with this addendum, and will contribute to audits carried out by you or an auditor you appoint, on reasonable notice, no more than once a year unless a supervisory authority requires otherwise or there has been a breach.

We are not currently SOC 2 or ISO 27001 certified and do not offer a certification report in place of an audit. When that changes, this section will change with it.

10. Signing this

Accepting the terms of service accepts this addendum, and no signature is needed. If your procurement process requires a countersigned copy, email [email protected] and we will sign one.