This Data Processing Agreement ("DPA") forms part of the agreement between Sourceit Technologies Inc ("Mailivery", "we", "Processor") and the customer identified in that agreement ("you", "Controller") for the provision of the Mailivery services (the "Agreement"). It applies where we process personal data on your behalf.
1.1 "Data Protection Law" means Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), as applicable.
1.2 "Personal Data", "processing", "controller", "processor", "data subject" and "Personal Data Breach" have the meanings given in the GDPR. Where the CCPA applies, "Personal Data" includes "personal information" as defined there.
1.3 "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
1.4 "Sub-processor" means a processor engaged by us to process Personal Data on your behalf.
2.1 You are the controller and we are the processor in respect of Personal Data processed to provide the Services. Where you are yourself a processor acting for a third party, you confirm you have authority to enter into this DPA and to give the instructions you give under it.
2.2 We act as an independent controller in respect of account administration, billing, security, and the operation of the warm-up network. That processing is governed by our Privacy Policy and is outside this DPA.
2.3 The details of the processing are set out in Annex I. This DPA is effective for the term of the Agreement and survives until we have deleted or returned the Personal Data under clause 9.
3.1 You are responsible for the lawfulness of the Personal Data you provide to the Services and of the instructions you give us, including having a valid legal basis for the processing, providing any notices and obtaining any consents required by Data Protection Law.
3.2 You will not submit to the Services, or instruct us to process, special categories of Personal Data (Article 9 GDPR), data relating to criminal convictions, or data relating to children, except where such data is incidentally contained in mailbox content.
3.3 You will not give us any instruction that would cause us to breach Data Protection Law.
4.1 We shall:
4.2 We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law.
5.1 You give us general authorisation to engage Sub-processors in the following categories: cloud infrastructure providers, for hosting and data storage; mailbox and mail transmission providers, for the seed mailboxes we operate as part of the warm-up network; analytics and monitoring providers; payment processors; and customer support providers.
5.2 The categories and locations of our current Sub-processors are set out in Annex III. The identity of the Sub-processors within each category is available on request to accounts@mailivery.io.
5.3 We will give you at least 30 days' notice, by email to the address on your account, before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected Services without penalty.
5.4 We impose data protection obligations on each Sub-processor no less protective than those in this DPA, and we remain liable to you for their performance.
5.5 Where the Services connect to mailboxes you designate, using credentials you supply, the providers of those mailboxes act under your own arrangements with them and are not our Sub-processors. You acknowledge that messages sent through the Services are transmitted to recipient mail servers whose location and operator are determined by the recipient.
6.1 We are established in the United States and process and store Personal Data in the United States. We do not currently offer processing or storage restricted to the European Economic Area.
6.2 Where you transfer Personal Data subject to the GDPR to us, the SCCs apply and are incorporated into this DPA by reference, as follows:
6.3 For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
6.4 If this DPA conflicts with the SCCs, the SCCs prevail. We are not currently certified under the EU-US Data Privacy Framework; if we become certified, the SCCs will continue to apply in addition.
6.5 California. Where the CCPA applies, we act as your service provider. We will not sell or share Personal Data, will not retain, use or disclose it for any purpose other than the business purposes set out in the Agreement and this DPA, and will not combine it with Personal Data we receive from other sources except as the CCPA permits. We will tell you if we can no longer meet our obligations under the CCPA.
7.1 If we receive a request directly from a data subject relating to Personal Data we process for you, we will not respond substantively but will forward it to you promptly.
7.2 We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data we process on your behalf, and will provide the information reasonably required for you to meet your own notification obligations. Where information is not all available at once, we may provide it in phases.
7.3 We will take reasonable steps to contain and remediate the breach and will cooperate with you in your response.
8.1 We will make available the information reasonably necessary to demonstrate compliance with this DPA, including certifications, audit reports and completed security questionnaires where we have them.
8.2 Where that is not sufficient, you may request an audit no more than once in any twelve-month period, on at least thirty days' written notice, during business hours, subject to confidentiality and conducted so as to minimise disruption. A further audit may be requested following a Personal Data Breach or where a supervisory authority requires it. You bear your own costs and reimburse our reasonable costs of participating.
9.1 We retain Personal Data for the term of the Agreement. After termination or expiry, we delete or irreversibly anonymise it within 24 months, except where we are required by law to retain it, in which case we continue to protect it under this DPA for as long as we hold it.
9.2 You may ask us in writing at any time after termination to return the Personal Data in a commonly used format or to delete it earlier, and we will do so within 30 days of your request.
10.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. Nothing here limits liability that cannot be limited by law, including liability to data subjects under the SCCs.
10.2 In the event of conflict, the order of precedence is: the SCCs, then this DPA, then the Agreement.
10.3 This DPA is governed by the law of Illinois, United States, whose courts have exclusive jurisdiction, except that clause 6 and the SCCs are governed as set out in clause 6.2.
11.1 This DPA, including the SCCs, is incorporated into the Agreement and is deemed executed by both parties when you accept the Agreement or use the Services. No separate signature is required. A countersigned copy is available on request to accounts@mailivery.io.
11.2 We may update this DPA to reflect changes in Data Protection Law, the Services, or our Sub-processors. We will give you at least 30 days' notice of material changes by email to the address on your account. The version in force is the one published at https://mailivery.io/legal/dpa.
12.1 Data protection enquiries should be sent to accounts@mailivery.io. Our registered office is 2206 N Main Street, Suite 183, Wheaton, Illinois 60187, United States.
Data exporter: The Controller identified in the Agreement (the account holder). Role: controller (Module Two) or processor (Module Three).
Data importer: Sourceit Technologies Inc, 2206 N Main Street, Suite 183, Wheaton, Illinois 60187, United States. Role: processor. Contact: accounts@mailivery.io
Data subjects: The Controller's personnel and authorised users; owners and recipients of mailboxes connected to the Services; individuals whose email addresses are submitted for verification.
Categories of personal data: Name; business email address; mailbox credentials and access tokens; the content, headers and metadata of messages sent and received through connected mailboxes; IP address; product usage data.
Special category data: None requested or required. Any such data present in mailbox content is incidental.
Frequency: Continuous, for the term of the Agreement.
Nature and purpose: Automated sending, receipt, classification and analysis of email to establish and maintain sender reputation and to measure inbox placement.
Retention: As set out in clause 9.
The supervisory authority of the EU member state in which the data exporter is established, or where the exporter is not established in the EU, that of the member state in which its Article 27 representative is appointed.
We engage Sub-processors in the categories below, all located in the United States. The identity of the current Sub-processors within each category is available on request to accounts@mailivery.io. Changes are notified under clause 5.3.