Data Processing Agreement

Last updated 10 September 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Sourceit Technologies Inc ("Mailivery", "we", "Processor") and the customer identified in that agreement ("you", "Controller") for the provision of the Mailivery services (the "Agreement"). It applies where we process personal data on your behalf.

1. Definitions

1.1 "Data Protection Law" means Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), as applicable.

1.2 "Personal Data", "processing", "controller", "processor", "data subject" and "Personal Data Breach" have the meanings given in the GDPR. Where the CCPA applies, "Personal Data" includes "personal information" as defined there.

1.3 "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.

1.4 "Sub-processor" means a processor engaged by us to process Personal Data on your behalf.

2. Roles and Scope

2.1 You are the controller and we are the processor in respect of Personal Data processed to provide the Services. Where you are yourself a processor acting for a third party, you confirm you have authority to enter into this DPA and to give the instructions you give under it.

2.2 We act as an independent controller in respect of account administration, billing, security, and the operation of the warm-up network. That processing is governed by our Privacy Policy and is outside this DPA.

2.3 The details of the processing are set out in Annex I. This DPA is effective for the term of the Agreement and survives until we have deleted or returned the Personal Data under clause 9.

3. Your Obligations

3.1 You are responsible for the lawfulness of the Personal Data you provide to the Services and of the instructions you give us, including having a valid legal basis for the processing, providing any notices and obtaining any consents required by Data Protection Law.

3.2 You will not submit to the Services, or instruct us to process, special categories of Personal Data (Article 9 GDPR), data relating to criminal convictions, or data relating to children, except where such data is incidentally contained in mailbox content.

3.3 You will not give us any instruction that would cause us to breach Data Protection Law.

4. Our Obligations

4.1 We shall:

  • process Personal Data only on your documented instructions, including those in the Agreement and this DPA, unless required otherwise by law, in which case we will tell you before processing unless the law prohibits it;
  • ensure that people authorised to process Personal Data are bound by confidentiality;
  • implement and maintain the measures set out in Annex II;
  • engage Sub-processors only in accordance with clause 5;
  • assist you, so far as reasonably possible and taking account of the nature of the processing, in responding to data subject requests and in meeting your obligations under Articles 32 to 36 of the GDPR;
  • delete or return Personal Data at the end of the Services, in accordance with clause 9; and
  • make available the information necessary to demonstrate compliance with this DPA, and contribute to audits in accordance with clause 8.

4.2 We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law.

5. Sub-processors and Mail Transmission

5.1 You give us general authorisation to engage Sub-processors in the following categories: cloud infrastructure providers, for hosting and data storage; mailbox and mail transmission providers, for the seed mailboxes we operate as part of the warm-up network; analytics and monitoring providers; payment processors; and customer support providers.

5.2 The categories and locations of our current Sub-processors are set out in Annex III. The identity of the Sub-processors within each category is available on request to accounts@mailivery.io.

5.3 We will give you at least 30 days' notice, by email to the address on your account, before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected Services without penalty.

5.4 We impose data protection obligations on each Sub-processor no less protective than those in this DPA, and we remain liable to you for their performance.

5.5 Where the Services connect to mailboxes you designate, using credentials you supply, the providers of those mailboxes act under your own arrangements with them and are not our Sub-processors. You acknowledge that messages sent through the Services are transmitted to recipient mail servers whose location and operator are determined by the recipient.

6. International Transfers

6.1 We are established in the United States and process and store Personal Data in the United States. We do not currently offer processing or storage restricted to the European Economic Area.

6.2 Where you transfer Personal Data subject to the GDPR to us, the SCCs apply and are incorporated into this DPA by reference, as follows:

  • Module Two applies where you are a controller, and Module Three where you are a processor;
  • the docking clause in Clause 7 applies;
  • Option 2 in Clause 9 (general written authorisation) applies, with the notice period in clause 5.3 above;
  • the SCCs are governed by the law of Ireland, whose courts have jurisdiction under Clause 18(b); and
  • Annexes I, II and III of this DPA serve as Annexes I, II and III of the SCCs.

6.3 For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

6.4 If this DPA conflicts with the SCCs, the SCCs prevail. We are not currently certified under the EU-US Data Privacy Framework; if we become certified, the SCCs will continue to apply in addition.

6.5 California. Where the CCPA applies, we act as your service provider. We will not sell or share Personal Data, will not retain, use or disclose it for any purpose other than the business purposes set out in the Agreement and this DPA, and will not combine it with Personal Data we receive from other sources except as the CCPA permits. We will tell you if we can no longer meet our obligations under the CCPA.

7. Data Subject Requests and Breach

7.1 If we receive a request directly from a data subject relating to Personal Data we process for you, we will not respond substantively but will forward it to you promptly.

7.2 We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data we process on your behalf, and will provide the information reasonably required for you to meet your own notification obligations. Where information is not all available at once, we may provide it in phases.

7.3 We will take reasonable steps to contain and remediate the breach and will cooperate with you in your response.

8. Audits

8.1 We will make available the information reasonably necessary to demonstrate compliance with this DPA, including certifications, audit reports and completed security questionnaires where we have them.

8.2 Where that is not sufficient, you may request an audit no more than once in any twelve-month period, on at least thirty days' written notice, during business hours, subject to confidentiality and conducted so as to minimise disruption. A further audit may be requested following a Personal Data Breach or where a supervisory authority requires it. You bear your own costs and reimburse our reasonable costs of participating.

9. Retention and Deletion

9.1 We retain Personal Data for the term of the Agreement. After termination or expiry, we delete or irreversibly anonymise it within 24 months, except where we are required by law to retain it, in which case we continue to protect it under this DPA for as long as we hold it.

9.2 You may ask us in writing at any time after termination to return the Personal Data in a commonly used format or to delete it earlier, and we will do so within 30 days of your request.

10. Liability, Precedence and Governing Law

10.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. Nothing here limits liability that cannot be limited by law, including liability to data subjects under the SCCs.

10.2 In the event of conflict, the order of precedence is: the SCCs, then this DPA, then the Agreement.

10.3 This DPA is governed by the law of Illinois, United States, whose courts have exclusive jurisdiction, except that clause 6 and the SCCs are governed as set out in clause 6.2.

11. Execution and Changes

11.1 This DPA, including the SCCs, is incorporated into the Agreement and is deemed executed by both parties when you accept the Agreement or use the Services. No separate signature is required. A countersigned copy is available on request to accounts@mailivery.io.

11.2 We may update this DPA to reflect changes in Data Protection Law, the Services, or our Sub-processors. We will give you at least 30 days' notice of material changes by email to the address on your account. The version in force is the one published at https://mailivery.io/legal/dpa.

12. Contact

12.1 Data protection enquiries should be sent to accounts@mailivery.io. Our registered office is 2206 N Main Street, Suite 183, Wheaton, Illinois 60187, United States.

Annex I: Description of Processing

Required by Annex I of the SCCs.

A. Parties

Data exporter: The Controller identified in the Agreement (the account holder). Role: controller (Module Two) or processor (Module Three).

Data importer: Sourceit Technologies Inc, 2206 N Main Street, Suite 183, Wheaton, Illinois 60187, United States. Role: processor. Contact: accounts@mailivery.io

B. Description of the Transfer

Data subjects: The Controller's personnel and authorised users; owners and recipients of mailboxes connected to the Services; individuals whose email addresses are submitted for verification.

Categories of personal data: Name; business email address; mailbox credentials and access tokens; the content, headers and metadata of messages sent and received through connected mailboxes; IP address; product usage data.

Special category data: None requested or required. Any such data present in mailbox content is incidental.

Frequency: Continuous, for the term of the Agreement.

Nature and purpose: Automated sending, receipt, classification and analysis of email to establish and maintain sender reputation and to measure inbox placement.

Retention: As set out in clause 9.

C. Competent Supervisory Authority

The supervisory authority of the EU member state in which the data exporter is established, or where the exporter is not established in the EU, that of the member state in which its Article 27 representative is appointed.

Annex II: Technical and Organisational Measures

Required by Annex II of the SCCs.

  • Encryption in transit: TLS 1.2 or higher for connections to the Services and to Sub-processor systems. Mail transmission uses TLS where the receiving server supports it.
  • Encryption at rest: AES-256 for primary data stores and backups. Mailbox credentials and access tokens are stored encrypted.
  • Access control: Role-based access on the principle of least privilege. Multi-factor authentication is required for administrative access to production systems. Access is reviewed periodically and removed on termination.
  • Network security: Segmented production environment with firewalling and restricted inbound access.
  • Logging: Access to production systems and to Personal Data is logged and retained.
  • Secure development: Code review before deployment; dependency vulnerability scanning; separation of development, staging and production environments.
  • Backup and recovery: Encrypted backups taken regularly, with documented restoration procedures.
  • Incident response: Documented procedure for detection, escalation, containment and notification, consistent with clause 7.2.
  • Personnel: Confidentiality obligations in employment and contractor terms.
  • Sub-processor assurance: Data protection terms imposed by contract on each Sub-processor, as required by clause 5.4.

Annex III: Sub-processors

Required by Annex III of the SCCs.

We engage Sub-processors in the categories below, all located in the United States. The identity of the current Sub-processors within each category is available on request to accounts@mailivery.io. Changes are notified under clause 5.3.

  • Cloud infrastructure: application hosting and data storage.
  • Mailbox and mail transmission: seed mailboxes operated by us in the warm-up network.
  • Analytics and monitoring: performance, security and service improvement.
  • Payment processing: billing and subscription management.
  • Support and communication: customer support.

© 2026 Sourceit Technologies Inc. All rights reserved.

Don't Land In Spam.
Make more sales.
Get Started Today For Free.