Data Processing Terms
Baseline data-processing commitments for customer data handled in connection with the Sendout service.
1. Roles
Where a customer determines the purposes and means of processing recipient data, the customer acts as controller (or equivalent role) and Sendout acts as processor/operator to the extent it processes that data to provide the service.
2. Customer instructions
Sendout processes customer data on documented instructions embodied in the customer’s use of the service, these terms, configuration choices, and support requests, except where processing is required by law or necessary to protect the service.
3. Confidentiality
Personnel and service providers with access to customer data should be subject to appropriate confidentiality obligations and access restrictions.
4. Security
Sendout maintains reasonable technical and organizational safeguards appropriate to the nature of the service, including access control, transport security, secret protection, operational logging, and abuse prevention.
5. Subprocessors
Sendout may engage subprocessors for infrastructure, delivery, security, DNS/CDN, authentication, billing, monitoring, and support functions. Current categories are described on the Subprocessors page.
6. Data subject requests
Where appropriate and technically feasible, Sendout will assist customers with requests relating to personal data processed on their behalf.
7. Deletion and return
Upon account termination or valid customer request, Sendout will delete or render inaccessible customer data in accordance with applicable retention, security, backup, fraud-prevention, and legal requirements.
8. International transfers
Where data is transferred internationally, the parties are responsible for using legally appropriate transfer mechanisms required by applicable law.
9. Audit information
Sendout may provide reasonable information about its security and processing practices. Any formal audit rights or bespoke data-processing terms require a separate written agreement.
