Data Processing Agreement
Pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679
This is the agreement every EmailConnect customer gets, word for word. Your own copy, with your organisation's details and the date filled in, is a PDF you download from your account settings, on every plan including Free. You do not need to sign it or send it back.
Parties
Data Processor:
EmailConnect by XADI
Registration/VAT: KvK 91939267 (Amsterdam) / NL004926305B88
Address: Parnassia 108A, 2224 DD Katwijk (ZH), The Netherlands
Data Protection Officer: Xander Groesbeek
Email: support@emailconnect.eu
Data Controller:
The customer: organisation name, VAT number, address and contact, filled in from the account when the agreement is generated.
In this Agreement, the Data Controller is referred to as "Controller" and EmailConnect by XADI as "Processor". Together referred to as the "Parties".
1. Purpose and Scope
This Data Processing Agreement ("DPA") governs the processing of personal data by the Processor on behalf of the Controller in connection with the emailconnect.eu email-to-webhook forwarding service.
In plain terms: You (the Controller) use emailconnect.eu to receive emails at custom or system-provided addresses and have their contents delivered as structured JSON payloads to your webhook endpoints. We (the Processor) handle this email data on your behalf, according to your instructions and this agreement.
2. Description of Processing
Nature and purpose:
Receiving, parsing, and forwarding incoming email messages to Controller-configured HTTP webhook endpoints. Temporary storage of email data for delivery retry and configurable retention periods.
Categories of data subjects:
Individuals who send emails to addresses managed by the Controller through emailconnect.eu (e.g., customers, contacts, or other third parties).
Types of personal data:
- Email metadata: sender address, recipient address, subject line, timestamps, message headers
- Email content: message body (text and/or HTML), attachments
- Technical data: IP addresses of sending mail servers, DKIM/SPF/DMARC verification results
Retention:
Email data is retained only for the duration necessary to ensure delivery (retry window) and for the Controller-configured retention period. After expiration, data is automatically and permanently deleted. By default, Free-plan accounts apply a 1-hour retention window; higher-tier plans can configure their own retention period and may delete payloads on demand via the API (for example, immediately after a successful webhook delivery). Attachments offloaded to managed object storage are retained for the same period as the email they belong to; on a custom Controller-provided S3 connection, the Controller controls attachment retention independently.
Special categories of data:
The Controller is responsible for the lawfulness of the content it routes through the service. The Controller must not route special categories of personal data (Article 9 GDPR) without its own valid legal basis. Such use cases require enabling Data Residency Mode, in which no email content — only routing metadata — is stored by the Processor, and a custom Controller-provided S3 connection is a prerequisite.
2a. Data Residency Mode Addendum
This section is included only in agreements for accounts that have Data Residency Mode enabled.
The Controller has enabled Data Residency Mode. This materially changes the scope of data processed and stored by the Processor:
Reduced storage scope:
Email content (body text, HTML, attachments, and non-routing headers) is NOT stored in the Processor's central database. Content is processed in memory and delivered to the Controller's webhook endpoint, and if configured, stored in the Controller's own S3-compatible storage.
Metadata retained by the Processor:
- Message ID, recipient email address, subject line
- Delivery timestamps and status
- Attachment summary (filename, content type, size — not the attachment content itself)
- Spam classification score and email classification type
Transfer of responsibility:
The Controller assumes full responsibility for the storage, retention, protection, and lawful processing of email content delivered to the Controller's endpoints and S3 storage. The Processor's obligations under this DPA apply only to the routing metadata it retains.
Operational limitations:
- Manual retry, replay, and payload preview in the dashboard are unavailable (content is not stored by the Processor)
3. Processor Obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller, including with regard to transfers to third countries.
- Immediately inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other applicable Union or Member State data protection provisions.
- Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 4).
- Respect the conditions for engaging sub-processors (see Section 5).
- Assist the Controller in responding to requests for exercising data subject rights (see Section 6).
- Assist the Controller in ensuring compliance with obligations related to security, breach notification, and data protection impact assessments.
- At the choice of the Controller, delete or return all personal data after the end of the provision of services (see Section 8).
- Make available to the Controller all information necessary to demonstrate compliance with this Article, and allow for and contribute to audits and inspections.
Audits and inspections:
The Processor maintains audit logs of actions performed on the platform. Controllers on the Platform plan have direct, self-service access to these logs through the dashboard. Controllers on other plans may request the audit information necessary to demonstrate compliance with this DPA. Such requests are subject to reasonable prior written notice, a limit of one audit per twelve-month period (absent a substantiated cause such as a personal data breach), the Controller bearing the Processor's reasonable costs, and a written confidentiality undertaking. Audits are satisfied through the provision of documentation, audit logs, and available certifications; on-site inspection of the Processor's infrastructure is not provided, given the security-sensitive nature of the hosting environment.
4. Technical and Organizational Measures
The Processor implements the following measures to protect personal data:
- EU-only processing: All personal data that the Processor processes and stores on the Controller's behalf under this Agreement resides exclusively within the European Union — Hetzner (Germany) for compute, the PostgreSQL database, and the self-hosted mail server (Postfix), and Scaleway (France) for outbound platform transactional email and optional managed S3 storage of large attachments. Optional single sign-on (Section 5) authenticates directly with an independent identity provider and is not processing carried out by the Processor on the Controller's behalf.
- Encryption in transit: All data transfers use TLS 1.2 or higher. Webhook deliveries are made over HTTPS only.
- Access controls: Role-based access with multi-factor authentication for administrative access. API keys are scoped with fine-grained permissions.
- Automated data lifecycle: Configurable retention periods with automatic, permanent deletion upon expiry. No manual intervention required.
- Audit logging: All data processing activities are logged for compliance verification.
- Infrastructure isolation: Dedicated compute instances, no shared-tenancy platforms for core data processing.
5. Sub-processors
The Controller provides general authorization for the Processor to engage the following sub-processors. The Processor will inform the Controller of any intended changes to this list at least 30 days in advance, giving the Controller the opportunity to object. Where the Controller objects on reasonable data-protection grounds, the Controller may terminate the affected service.
Where the Processor engages a sub-processor, it does so by way of a written contract imposing the same data protection obligations as set out in this DPA. The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.
| Sub-processor | Location | Purpose | Data processed |
|---|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Application hosting, compute, PostgreSQL database, self-hosted mail server (Postfix) | All Controller personal data in transit and at rest |
| Scaleway SAS | France (EU) | Outbound platform transactional email (e.g. magic links, subscription notices); optional managed S3 object storage for large attachments | Account email address (transactional email); large inbound attachments at rest (managed S3). Email bodies and metadata remain in Hetzner (PostgreSQL); the parsed body holds only a link to the stored attachment. |
The following third-party services are used but act as independent data controllers. No personal data is shared with them by the Processor; where data is involved, the data subject provides it directly to the service:
- Mollie B.V. (Netherlands, EU) — Payment processing. Users are redirected to Mollie with only an anonymous reference ID and amount. The user provides their own payment details directly to Mollie.
- Plausible Insights OÜ (EU) — Privacy-friendly web analytics. Anonymized, cookieless usage data only. No personal data collected.
- GitHub Inc. / Microsoft (USA*) — Optional SSO login. Used only when an operator chooses GitHub SSO; the operator authenticates directly with GitHub.
- Google LLC (USA*) — Optional SSO login. Used only when an operator chooses Google SSO; the operator authenticates directly with Google.
* GitHub and Google SSO involve a transfer of personal data to the USA, solely at the Controller's own discretion where its operators choose SSO. These transfers are covered under the EU-US Data Privacy Framework (GitHub/Microsoft and Google LLC being certified participants), with EU Standard Contractual Clauses as a fallback mechanism, and under each provider's own DPA.
6. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligation to respond to data subject requests under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection).
Self-service capabilities: The Controller can export all of its data at any time via the compliance tools at app.emailconnect.eu/settings/compliancy. The Controller can delete its account and all associated data at any time via app.emailconnect.eu/settings/profile.
7. Breach Notification
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. This notification shall:
- Describe the nature of the breach, including categories and approximate number of data subjects and records concerned.
- Describe the likely consequences of the breach.
- Describe the measures taken or proposed to address the breach, including measures to mitigate possible adverse effects.
Breach notifications will be sent to the Controller's registered email address and displayed as a system notification in the dashboard.
8. Duration and Termination
This DPA is effective for the duration of the Controller's use of the emailconnect.eu service. Upon termination, at the Controller's choice, the Processor will return or delete all personal data:
- Return: the Controller may export all of its data prior to account deletion using the self-service export tools at app.emailconnect.eu/settings/compliancy.
- Deletion: account deletion can be initiated at app.emailconnect.eu/settings/profile, after which all personal data is permanently deleted within 30 days.
- Anonymized financial transaction records may be retained as required by applicable tax and accounting laws.
- Data in encrypted backups expires automatically within 7 days of the backup rotation cycle.
9. Governing Law
This DPA is governed by and construed in accordance with the laws of the Netherlands. It supplements, and is subject to, the EmailConnect Terms of Service. In the event of a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails.
Terms of Service: emailconnect.eu/terms-of-service
Signatures
Signed for the Processor by Xander Groesbeek / Founder, digitally executed on the date your copy is generated.
You do not need to share a signed copy with us. This DPA is effective upon your continued use of the service.
Related
- Sub-processors: the current list, with what each one handles
- About the DPA: what it covers and how to download your copy
- Data retention
- Security and responsible disclosure