Data Processing Agreement

Last updated: 1 July 2026 — Version 1.0

If you use EmailConsul to process personal data of individuals located in the European Union, European Economic Area (EU/EEA), or the United Kingdom (UK), our Data Processing Agreement (DPA) governs how we handle that data as your Data Processor.

The DPA incorporates the EU Standard Contractual Clauses (SCCs) (European Commission Decision 2021/914, Module 2: Controller-to-Processor) as the lawful mechanism for transferring personal data from the EU/EEA to our servers in the United States.

UK customers: A UK International Data Transfer Addendum (UK IDTA) is currently in preparation and will be incorporated into the DPA once finalised. UK customers wishing to discuss interim transfer arrangements should contact [email protected].

The DPA is required under Article 28 of the GDPR. Acceptance of our Terms of Service alone does not substitute for a signed DPA.

Do I need to sign the DPA?

You need to sign the DPA if any of the following apply:

  • ✓ You are established in the EU/EEA or UK, or your customers or end users are located there.

  • ✓ You upload email lists, contact data, or other data sets that include personal data of EU/EEA or UK individuals.

  • ✓ You use EmailConsul to monitor, process, or analyse email activity involving EU/EEA or UK data subjects.

  • ✓ Your legal or compliance team requires a signed Data Processing Agreement with all third-party processors.

If you are not sure whether you need a DPA, contact us at [email protected] and we will advise.

What the DPA covers

The DPA sets out:

  • Processing scope — the categories of personal data EmailConsul processes on your behalf, the purposes of processing, and the types of data subjects involved.

  • Your instructions — EmailConsul processes your data only on your documented instructions, and will notify you if an instruction appears to violate applicable law.

  • Security measures — the technical and organisational measures (TOMs) we apply to protect your data, consistent with GDPR Art. 32.

  • Sub-processors — the third-party providers we use to deliver the service, your right to object to new sub-processors, and how we keep the list current.

  • Data subject rights — how we assist you in responding to access, deletion, portability, and other GDPR rights requests from your data subjects.

  • Data breach notification — our obligation to notify you without undue delay (and within 72 hours where feasible) of any personal data breach affecting your data.

  • Retention and deletion — how long we keep your data, and the procedures for returning or securely deleting it at the end of the contract.

  • EU Standard Contractual Clauses — Module 2 SCCs (Controller to Processor) under European Commission Decision 2021/914, governing transfers from the EU/EEA to our US-based services.

Download the DPA

The current version of the DPA, including all Annexes and the EU SCCs, is available as a PDF:

Download DPA (PDF)

Version 1.0 | Effective 1 July 2026 | Includes EU SCCs (Decision 2021/914)

How to execute the DPA

Choose the method that works for your organisation:

  • Option A — Accepted via Terms of Service

    If you subscribed to EmailConsul on or after 1 July 2026, our Terms of Service incorporate the DPA by reference. By accepting the Terms of Service, the authorised representative of your organisation concluded the DPA on its behalf. No separate action is required.

    A timestamped record of your Terms of Service acceptance, which includes acceptance of the DPA, is retained in our systems. To request a copy, contact [email protected].

  • Option B — Signed copy by email

    Enterprise customers or those whose procurement process requires a countersigned document may follow these steps:

    1. Download the DPA PDF using the link above.

    2. Sign on the signature page (wet signature or DocuSign/equivalent).

    3. Email the signed DPA to [email protected] with the subject line: [DPA] [Your Company Name].

    4. We will countersign and return a fully executed copy.

Sub-processor list

The current list of sub-processors used by EmailConsul, including their name, role, and processing location, is published at emailconsul.com/legal/sub-processors. We will notify you of any intended additions or replacements in accordance with the DPA.

Frequently asked questions

Is online acceptance legally valid?

Yes. For the EU SCCs under Decision 2021/914, electronic acceptance by an authorised representative is sufficient. We recommend Option B (countersigned PDF) if your internal procurement policy requires it.

Which SCC module applies?

Module 2 (Controller to Processor). You are the Data Controller; EmailConsul is the Data Processor.

Does the DPA cover UK transfers?

The DPA applies to UK customers under the UK GDPR (as retained in UK law). A UK International Data Transfer Addendum (UK IDTA) is currently in preparation and will be incorporated into the DPA once finalised. In the meantime, UK customers wishing to discuss interim transfer arrangements should contact [email protected].

What if I subscribed before 1 July 2026?

This is EmailConsul's first DPA. Customers who subscribed before 1 July 2026 did not have a DPA in place. If you process personal data of EU/EEA or UK individuals, please accept the updated Terms of Service to incorporate the DPA, or contact [email protected] to request a countersigned copy under Option B.

I am a US customer with no EU/EEA or UK data subjects. Do I need a DPA?

No. If you do not process personal data of EU/EEA or UK individuals through our services, a DPA is not required. If your situation changes, please execute the DPA before processing such data.

Contact

For DPA and data protection enquiries: [email protected].

EU/EEA data subjects may also contact our EU representative: Admonto BV, Hannie Schaftstraat 62, 2033PJ Haarlem, Netherlands — [email protected].