Data Processing Addendum
Last updated: July 25, 2026
This Data Processing Addendum ("DPA") forms part of the Terms and Conditions between sendrules ("sendrules", "we", "Processor") and the customer that accepted those Terms ("Customer", "Controller"). It applies whenever sendrules processes Personal Data on behalf of the Customer under the Service. Terms not defined here have the meaning given in the UK GDPR and the EU GDPR (together, the "Data Protection Laws").
1. Scope and roles
Under this DPA the Customer is the Controller of Personal Data submitted to the Service by the Customer, its end users, or its recipients (the "Customer Personal Data"). sendrules acts as the Processor and processes Customer Personal Data solely to provide the Service, and only on the Customer's documented instructions — this DPA, the Terms, and the Customer's use of the product configuration are those instructions.
2. Categories of data and data subjects
Customer Personal Data typically includes the email addresses, message content, headers, and metadata that the Customer sends through sendrules; addresses and message metadata received into managed inboxes; and contact details harvested by autoresponder parsers configured by the Customer. Data subjects include the Customer's end users, the recipients of the Customer's messages, and the senders of messages received into the Customer's managed inboxes.
3. Duration
sendrules processes Customer Personal Data for the duration of the Terms and for the retention windows configured by the Customer in Settings → Data retention. After the applicable window expires — or on termination — sendrules deletes or returns the data as described in section 8.
4. Sub-processors
The Customer authorises sendrules to engage sub-processors (for example, cloud hosting and the upstream email providers the Customer attaches to their Grids and Rules). sendrules maintains a list of sub-processors and provides at least 30 days' notice of intended changes so the Customer can object.
5. Security measures
sendrules implements appropriate technical and organisational measures for Customer Personal Data, including: encryption in transit (TLS on SMTP submission and REST); AES-256-GCM at rest for stored SMTP credentials; role-based access control with a full audit trail; IP allow-listing on SMTP AUTH where the Customer configures it; HMAC-signed outbound webhooks; segregated tenant data with tenant-scoped queries; and least-privilege operational access to production systems.
6. Personal Data breach
sendrules will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, together with the information reasonably required for the Customer to meet its own notification obligations.
7. Data subject rights
sendrules provides tools (Activity, exports, delete endpoints, suppression list controls) that allow the Customer to fulfil data subject requests. Where sendrules receives a data subject request directly, we forward it to the Customer and do not respond on the Customer's behalf.
8. Return or deletion
On written request, and in any case within a reasonable period after termination, sendrules deletes or returns Customer Personal Data. Suppression lists, allow-lists, QC-failed lists, parser-extracted contacts and the permanent cross-tenant hard-bounce ledger persist for the purposes described in the Terms and the product documentation; the Customer may export or delete each of those from the app.
9. Audits
sendrules provides the information reasonably necessary to demonstrate compliance with this DPA and permits and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, subject to reasonable confidentiality and scheduling.
10. International transfers
Where sendrules transfers Customer Personal Data outside the UK or the EEA, we do so under an approved transfer mechanism (the Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable) and with the supplementary measures required by applicable guidance.
11. Contact
Questions about this DPA, or requests to enter a signed copy, should be sent through our Contact page.