This Data Processing Addendum ("DPA") forms part of the Terms of Service between Seamailer Corp ("Seamailer", "Processor") and the customer that accepted them ("Customer", "Controller"). It applies when Seamailer processes Customer Personal Data on the Customer's behalf. It takes effect automatically when the Customer accepts the Terms. If this DPA and the Terms conflict on data protection, this DPA wins.
1. Definitions
- Data Protection Laws: all laws on personal data that apply to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act (CCPA) and other US state privacy laws, and the Nigeria Data Protection Act 2023 (NDPA).
- Customer Personal Data: personal data in Customer Content that Seamailer processes on the Customer's behalf, mainly Contact data.
- Subprocessor: a third party Seamailer engages to process Customer Personal Data.
- Security Incident: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- SCCs: the Standard Contractual Clauses approved by the European Commission in Decision 2021/914.
- Terms such as "controller", "processor", "data subject" and "processing" have the meanings given in the Data Protection Laws.
2. Roles and scope
2.1 The Customer is the controller (or, where it acts for another controller, a processor), and Seamailer is the processor (or subprocessor) of Customer Personal Data.
2.2 The details of the processing are in Annex I.
2.3 For the CCPA, Seamailer is a "service provider". Seamailer will not sell or share Customer Personal Data, or retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the Service.
3. Customer obligations
The Customer is responsible for:
- having a lawful basis, including any consent needed, for the Customer Personal Data it collects and gives to Seamailer;
- giving data subjects any required notices;
- making sure its instructions to Seamailer comply with Data Protection Laws.
4. Seamailer obligations
Seamailer will:
- process Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of the Service, unless the law requires otherwise (in which case Seamailer will tell the Customer first, unless the law forbids it);
- tell the Customer if it believes an instruction breaks Data Protection Laws;
- ensure that staff who access Customer Personal Data are bound by confidentiality;
- apply the security measures in Annex II;
- help the Customer, through the Service's features or otherwise, to respond to data subject requests; if Seamailer receives a request directly, it will refer the person to the Customer;
- give reasonable help with data protection impact assessments and consultations with regulators;
- not use Customer Personal Data for its own purposes, including its own marketing or training AI models.
5. Subprocessors
5.1 The Customer authorises Seamailer to use the Subprocessors in Annex III.
5.2 Seamailer will have a written contract with each Subprocessor that gives at least the same level of protection as this DPA, and remains responsible for its Subprocessors.
5.3 Seamailer will update Annex III and notify the Customer by email or in the app at least 30 days before a new Subprocessor starts processing Customer Personal Data.
5.4 The Customer may object on reasonable data protection grounds within that 30-day period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for it.
6. Security incidents
6.1 Seamailer will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a Security Incident affecting Customer Personal Data.
6.2 The notice will describe, as far as known, the nature of the incident, the data and data subjects affected, likely consequences, and the steps taken or proposed. Seamailer will update the Customer as more information becomes available.
6.3 Notifying the Customer is not an admission of fault.
7. International transfers
7.1 Seamailer and its Subprocessors process Customer Personal Data in the United States and other countries.
7.2 EEA. For transfers of personal data from the EEA to a country without an adequacy decision, the SCCs are incorporated into this DPA: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. For the SCCs: clause 7 (docking) applies; clause 9 option 2 (general authorisation) applies with the notice period in section 5.3; the optional language in clause 11 does not apply; clauses 17 and 18 are governed by, and disputes decided in, the courts of Ireland; and Annexes I to III of this DPA complete the SCC annexes.
7.3 United Kingdom. For transfers from the UK, the UK International Data Transfer Addendum to the SCCs applies, with the tables completed using this DPA.
7.4 Switzerland. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
7.5 Nigeria. For transfers of personal data subject to the NDPA, Seamailer will rely on a transfer basis allowed by the NDPA, including appropriate safeguards equivalent to this DPA.
8. Audits
8.1 On written request, and no more than once a year, Seamailer will provide information reasonably needed to show compliance with this DPA, such as security documentation and answers to a reasonable security questionnaire.
8.2 If that is not enough, or a regulator requires it, the Customer may carry out an audit, at its own cost, with at least 30 days' notice, during business hours, and under confidentiality, in a way that does not disrupt Seamailer's operations.
9. Return and deletion
9.1 The Customer can export Customer Personal Data using the Service at any time while its Account is active.
9.2 After the Account closes, Seamailer will delete Customer Personal Data within 6 months, except where the law requires it to keep some data. Deleted data is removed from backups on their normal cycle, within 90 days of deletion from active systems.
9.3 Seamailer may keep suppression data (addresses that unsubscribed, bounced or complained) where needed to prevent them being emailed again through the Service.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
11. Term
This DPA lasts as long as Seamailer processes Customer Personal Data for the Customer.
Annex I: Details of processing
| Item | Details |
|---|---|
| Data exporter | The Customer, as identified in its Seamailer Account |
| Data importer | Seamailer Corp, 233 Gilman Avenue, Cincinnati, OH 45219, US · support@seamailer.app |
| Subject matter | Providing the Seamailer email marketing Service |
| Duration | The term of the Terms of Service, plus the deletion period in section 9 |
| Nature of processing | Collection, storage, organisation, segmentation, analysis, transmission (sending email), and deletion |
| Purpose | To send the Customer's emails, manage its Contacts, forms and landing pages, provide reporting and AI features, and support the Customer |
| Data subjects | The Customer's Contacts (subscribers, leads, customers and prospects), and people who submit the Customer's forms |
| Categories of data | Email address, name, phone number, custom fields and tags set by the Customer, subscription status, email engagement (opens, clicks, bounces, complaints), IP address and device data from form sign-ups and email engagement |
| Special categories | None intended. The Customer must not upload special category data (such as health data) |
| Frequency | Continuous, for as long as the Service is used |
| Competent supervisory authority | The authority determined under clause 13 of the SCCs |
Annex II: Security measures
- Encryption: data encrypted in transit (TLS) and at rest on our cloud provider's storage.
- Access control: access limited to staff who need it, with individual accounts and least-privilege permissions; passwords stored as secure hashes.
- Infrastructure: hosted on Amazon Web Services, which maintains recognised security certifications.
- Monitoring: error tracking, logging and alerting for unusual activity.
- Application security: input validation, protection against common web attacks, rate limiting and bot protection.
- Backups: regular backups, with deleted data removed within 90 days.
- Incident response: a documented process for investigating and notifying Security Incidents.
- Staff: confidentiality obligations for everyone with access to Customer Personal Data.
Annex III: Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, file storage (S3) | United States |
| Anthropic, PBC | AI features | United States |
| Google LLC (Gemini) | AI features | United States |
| Cloudinary Ltd. | Image hosting | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
| Bugsnag (SmartBear Software) | Error monitoring | United States |
| Better Stack, Inc. | Logging | European Union / United States |
| tawk.to | Customer support chat | United States |
Paystack, Google Sign-In, PostHog, Amplitude and ipdata process data about Customers' own account use, not Customer Personal Data, and are listed in the Privacy Policy.