Data Processing Agreement – Sidemail.io
This Data Processing Agreement (“DPA”) forms part of the agreement (the “Agreement”) governing use of the Sidemail.io service (“Sidemail”) between the customer identified in the applicable Account or order form (“Customer”) and Avantis Innovations LLC (“Company,” “we,” “us,” or “our”).
This DPA applies when the Company processes Customer Personal Data on behalf of Customer in connection with the Services. By accepting the Agreement or using the Services, Customer enters into this DPA on behalf of itself and, where applicable, its authorized Affiliates. Customer represents and warrants that it has authority to bind each such Affiliate and remains responsible for each Affiliate’s compliance with this DPA.
Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
Definitions
- “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.
- “Applicable Data Protection Law” means any privacy, data protection or data security law applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and applicable United States state privacy laws.
- “Customer Personal Data” means personal data, personal information or equivalent information contained in Customer Content that the Company processes on behalf of Customer to provide the Services. Customer Personal Data does not include information for which the Company determines the purposes and means of processing as an independent controller, such as Account, billing, support, security and service-usage information processed as described in our Privacy Policy.
- “Data Subject” means an identified or identifiable person to whom Customer Personal Data relates.
- “EEA” means the European Economic Area.
- “EU SCCs” means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
- “GDPR” means Regulation (EU) 2016/679.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data are not Personal Data Breaches.
- “Restricted Transfer” means a transfer of Customer Personal Data that requires an approved transfer mechanism under Applicable Data Protection Law.
- “Services” means the website, application, APIs, email infrastructure and related services that comprise Sidemail and are covered by the Agreement.
- “Subprocessor” means a third party engaged by the Company to process Customer Personal Data on behalf of Customer.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner and in force from March 21, 2022, as updated or replaced.
- The terms “controller,” “processor,” “processing,” “personal data,” “personal information,” “sale,” and “sharing” have the meanings given to them by Applicable Data Protection Law.
Scope and roles
- Customer appoints the Company to process Customer Personal Data as necessary to provide, secure, maintain and support the Services and as further described in Schedule 1.
- Customer is a controller of Customer Personal Data and the Company is its processor. Where Customer is itself a processor acting for another controller, the Company is Customer’s subprocessor. Each party will comply with the obligations applicable to its role under Applicable Data Protection Law.
- The Agreement, Customer’s use and configuration of the Services, and Customer’s documented support requests constitute Customer’s documented processing instructions. Additional instructions must be consistent with the Agreement and Applicable Data Protection Law and may be subject to reasonable fees where they require work beyond the standard Services.
- The Company may process Customer Personal Data where required by applicable law. Unless legally prohibited, the Company will inform Customer of that legal requirement before processing.
- The Company acts as an independent controller, rather than a processor under this DPA, when it determines the purposes and means of processing Account, billing, support, security, abuse-prevention or service-usage information. Such processing is governed by our Privacy Policy and Applicable Data Protection Law.
Customer obligations
-
Customer represents, warrants and agrees that:
- it will comply with Applicable Data Protection Law and the Agreement;
- it has provided all required privacy notices and obtained all rights, permissions, consents and lawful bases necessary for the Company to process Customer Personal Data under the Agreement;
- its instructions and use of the Services are lawful and will not cause the Company to violate Applicable Data Protection Law;
- it is responsible for the accuracy, quality, legality and minimization of Customer Personal Data;
- it is responsible for responding to Data Subjects and regulators regarding its processing, except for assistance the Company is expressly required to provide under this DPA;
- if it acts as a processor, its controller has authorized Customer to appoint the Company and its Subprocessors; and
- it will not provide special-category or sensitive personal data, protected health information, payment-card data, government identification numbers, precise biometric data, or personal data relating to children unless the Services expressly support that processing and the Company has agreed to it in writing.
-
Customer is responsible for securely configuring and using the Services, protecting Account credentials and API keys, and implementing appropriate security for systems and applications that connect to the Services.
-
The Company is not responsible for determining whether Customer’s instructions comply with law. The Company will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing until Customer modifies or confirms the instruction.
Company processing obligations
-
The Company will:
- process Customer Personal Data only on documented instructions from Customer, including as necessary to provide, secure and support the Services, unless otherwise required by law;
- ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
- implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as described in Schedule 2;
- taking into account the nature of the processing, assist Customer through appropriate technical and organizational measures, insofar as reasonably possible, with responding to requests to exercise Data Subject rights;
- taking into account the nature of processing and information available to the Company, provide reasonable assistance with Customer’s obligations concerning security, breach notifications, data protection impact assessments and prior consultation with supervisory authorities;
- maintain information required by Applicable Data Protection Law regarding its processing under this DPA;
- notify Customer if the Company can no longer comply with material obligations under this DPA or Applicable Data Protection Law; and
- on termination or expiration, delete or return Customer Personal Data as described in the section titled Return and deletion.
-
Assistance that requires material work beyond standard Service functionality may be charged at the Company’s then-current professional-services rates, unless the assistance is required because the Company breached this DPA.
Subprocessors
- Customer grants the Company general written authorization to engage Subprocessors to process Customer Personal Data.
- The Company’s then-current Subprocessor list is incorporated into this DPA by reference and will be provided to Customer upon written request to [email protected]. The list will identify each Subprocessor’s legal name, processing function and principal processing location.
- The Company will provide at least 15 days’ prior notice by email or another reasonable electronic method before a new or replacement Subprocessor begins processing Customer Personal Data, except where an urgent replacement is reasonably necessary to maintain security, availability or legal compliance. In that case, the Company will provide notice as soon as reasonably practicable.
- Customer may object to a new Subprocessor by providing a detailed written objection based on reasonable data-protection grounds before the Subprocessor begins processing. The parties will work in good faith to resolve the objection. If they cannot resolve it, the Company may modify or discontinue the affected feature, or Customer may stop using and terminate the affected portion of the Services. Any termination and refund rights are governed by the Agreement.
- The Company will enter into a written agreement with each Subprocessor imposing data-protection obligations that provide at least the level of protection required by Applicable Data Protection Law for the processing performed by that Subprocessor.
- The Company remains responsible for its Subprocessors’ performance of their data-protection obligations to the extent required by Applicable Data Protection Law.
Personal Data Breaches
-
The Company will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
-
To the extent reasonably available, the notice will describe:
- the nature of the Personal Data Breach;
- the categories of affected Data Subjects and Customer Personal Data;
- the likely consequences;
- measures taken or proposed to address and mitigate the Personal Data Breach; and
- a contact from whom further information may be obtained.
The Company may provide information in phases as it becomes available. A notification is not an admission of fault or liability.
-
The Company will take reasonable steps to contain, investigate and mitigate the Personal Data Breach and will reasonably cooperate with Customer’s legally required response.
-
Customer is responsible for determining whether notice to Data Subjects, regulators or other parties is required and for the content and delivery of such notices. The Company may notify regulators, law enforcement, affected parties or others without Customer’s approval where the Company is legally required to do so or reasonably determines that notification is necessary to protect Sidemail, the Company, its customers or others.
-
Each party will bear its own Personal Data Breach response costs, except to the extent otherwise required by Applicable Data Protection Law or allocated under the Agreement. The Company’s liability relating to a Personal Data Breach is subject to the limitations and exclusions in the Agreement.
Data Subject and regulatory requests
- If the Company receives a request from a Data Subject concerning Customer Personal Data, the Company will, where legally permitted, direct the Data Subject to Customer and will not independently respond except on Customer’s documented instructions or as required by law.
- Customer will use the functionality available in the Services to respond to requests where reasonably possible. If Customer cannot respond using the Services, the Company will provide reasonable assistance considering the nature of the processing.
- If the Company receives a legally binding request from a governmental or law-enforcement authority for Customer Personal Data, the Company will notify Customer before disclosure unless prohibited by law. Where appropriate and legally permitted, the Company will reasonably challenge requests it considers unlawful or disproportionate.
Audits and compliance information
-
On reasonable request, the Company will make available information reasonably necessary to demonstrate compliance with this DPA. The Company may satisfy this obligation by providing security documentation, certifications, independent audit reports, summaries, questionnaires or other relevant materials.
-
If the information provided is insufficient for Customer to meet a legal audit obligation, Customer may conduct one additional audit in any 12-month period, subject to the following:
- Customer must provide at least 30 days’ written notice;
- the audit must occur during normal business hours and avoid unreasonable disruption;
- the audit must be conducted remotely unless an on-site inspection is legally required;
- the auditor must be independent, qualified, not a competitor of the Company, and bound by confidentiality;
- the audit must be limited to systems, records and personnel relevant to Customer Personal Data;
- the audit must not compromise security or expose data belonging to another customer or third party;
- Customer may not perform penetration testing, vulnerability scanning or access source code without the Company’s prior written approval; and
- Customer will bear its audit costs and reimburse the Company’s reasonable costs, unless the audit identifies a material breach of this DPA by the Company.
-
The frequency and notice limits above do not apply where a competent regulator requires a different audit or where Customer reasonably believes, based on documented evidence, that the Company has materially breached this DPA.
-
Audit materials and findings are the Company’s confidential information and may be disclosed only to Customer’s professional advisers and regulators with a need to know, subject to confidentiality obligations or legal duties.
International data transfers
-
Customer authorizes the Company and its Subprocessors to process Customer Personal Data in the United States and other countries where the Company or its Subprocessors operate, subject to this DPA and Applicable Data Protection Law.
-
Where a Restricted Transfer may lawfully rely on an adequacy decision, approved certification or another valid transfer mechanism, the parties may rely on that mechanism.
-
EEA transfers. Where Customer Personal Data protected by the GDPR is transferred to the Company in a country not recognized as providing an adequate level of protection, the EU SCCs are incorporated into this DPA by reference and completed as follows:
- Module Two applies where Customer is a controller and the Company is a processor;
- Module Three applies where Customer is a processor and the Company is a subprocessor;
- Clause 7, the optional docking clause, does not apply;
- under Clause 9(a), Option 2, general written authorization applies, with the notice period stated in the Subprocessors section;
- the optional language in Clause 11 does not apply;
- under Clause 17, the EU SCCs are governed by the laws of Ireland;
- under Clause 18, disputes under the EU SCCs will be resolved by the courts of Ireland;
- Annex I is completed by Schedule 1 and the contact information in the Agreement;
- the competent supervisory authority is determined under Clause 13 of the EU SCCs;
- Annex II is completed by Schedule 2; and
- Annex III is completed by the Company’s then-current Subprocessor list incorporated by reference under the Subprocessors section.
-
United Kingdom transfers. For Restricted Transfers subject to United Kingdom data protection law, the UK Addendum is incorporated into this DPA and completed as follows:
- the Start Date in Table 1 is the date Customer accepts this DPA, and the remaining party and contact information in Table 1 is completed using the Agreement and Schedule 1;
- Table 2 is completed using the modules and selections stated for the EU SCCs above, and “Yes” applies to the question whether personal data received from the Importer may be combined with personal data collected by the Exporter;
- Table 3 is completed using Schedules 1 and 2 and the Company’s then-current Subprocessor list made available to Customer upon request;
- for Table 4, the Company as the Importer may end the UK Addendum as permitted by Section 19; and
- Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, applies.
-
Swiss transfers. For Restricted Transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with the following adaptations:
- references to the GDPR include the Swiss Federal Act on Data Protection where applicable;
- references to “EU,” “Union” and “Member State” include Switzerland where necessary to give effect to the EU SCCs;
- the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
- Data Subjects located in Switzerland may enforce their rights in Switzerland; and
- the governing-law and forum provisions of the EU SCCs apply without preventing rights granted by Swiss law.
-
The parties will provide information reasonably necessary to support transfer-impact assessments required by Applicable Data Protection Law. Customer remains responsible for determining whether its use of the Services and transfer instructions are lawful.
-
The EU SCCs and UK Addendum will prevail over conflicting provisions of this DPA solely with respect to the applicable Restricted Transfer. Nothing in this DPA modifies the EU SCCs or UK Addendum contrary to their terms.
United States privacy laws
-
Customer discloses Customer Personal Data to the Company only for the limited and specified business purposes described in Schedule 1. To the extent the Company processes Customer Personal Data subject to a United States state privacy law that recognizes processors, service providers or contractors, the Company will act as Customer’s processor, service provider or contractor, as applicable.
-
The Company will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data outside the direct business relationship with Customer or for purposes other than the limited and specified business purposes described in Schedule 1, except as permitted by Applicable Data Protection Law;
- combine Customer Personal Data with personal information received from another person or collected from the Company’s own interaction with a consumer, except as permitted by Applicable Data Protection Law; or
- use Customer Personal Data for targeted advertising or its own independent commercial purposes.
-
The Company will comply with the applicable obligations imposed on service providers, contractors or processors under Applicable Data Protection Law, provide the same level of privacy protection required by that law, and notify Customer if the Company determines that it can no longer meet those obligations.
-
Customer may take reasonable and appropriate steps to help ensure that the Company uses Customer Personal Data consistently with Customer’s obligations under Applicable Data Protection Law and may require the Company to stop and remediate unauthorized use, subject to the audit procedures in this DPA.
-
Each party certifies that it understands and will comply with the restrictions applicable to it under this section.
Return and deletion
- During the term, Customer may access, export or delete Customer Personal Data using available Service functionality.
- Following termination or expiration of the Services, at Customer’s choice, the Company will return or delete Customer Personal Data, unless Applicable Data Protection Law requires storage. If Customer chooses return, the Company will, after completing the return, delete all remaining existing copies in accordance with its standard retention and deletion practices, subject to paragraph 3 below and except to the extent Applicable Data Protection Law requires storage. Customer must request return before termination or before deletion under those practices. Return will be provided through available Service functionality or another reasonable method selected by the Company; custom export or migration assistance may be subject to reasonable fees. If Customer does not timely request return, Customer instructs the Company to delete Customer Personal Data in accordance with those practices.
- Customer Personal Data may remain in encrypted or access-restricted backups until overwritten through ordinary backup cycles. During that period, the Company will not actively process the data except for security, disaster recovery or legal-compliance purposes.
- The Company has no obligation to retain Customer Personal Data after deletion under its standard retention practices or to provide custom export formats or migration services unless agreed in writing.
Liability
- This DPA does not create separate or additional liability beyond the Agreement. To the fullest extent permitted by law, the Company’s aggregate liability arising out of or relating to this DPA is subject to the exclusions, limitations and liability cap in the Terms of Service or other applicable Agreement. Customer’s liability and indemnification obligations remain governed by the Agreement, including any liabilities expressly excluded from that cap.
- Customer’s indemnification obligations under the Agreement apply to claims arising from Customer Personal Data, Customer’s instructions, Customer’s breach of this DPA, or Customer’s violation of Applicable Data Protection Law.
- Nothing in this section limits liability to a Data Subject or supervisory authority to the extent such limitation is prohibited by Applicable Data Protection Law or the applicable transfer clauses. As between Customer and the Company, liability remains allocated under the Agreement to the fullest extent permitted by law.
Miscellaneous
- If there is a conflict between this DPA and the Agreement, this DPA controls only with respect to the processing of Customer Personal Data. The Agreement controls in all other respects. The applicable EU SCCs or UK Addendum control over both documents solely for a Restricted Transfer.
- Except where the applicable transfer clauses require otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the Agreement.
- The Company may update this DPA where reasonably necessary to comply with changes in Applicable Data Protection Law, regulatory guidance or the Services. The Company will provide reasonable notice of material changes and will not materially reduce the overall protection of Customer Personal Data during a current paid subscription term unless required by law.
- If any provision is unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in effect.
- Provisions that by their nature should survive termination will survive, including confidentiality, audits, international-transfer provisions, deletion obligations, liability and miscellaneous provisions.
- This DPA may be accepted electronically and does not require a separate signature. On reasonable request, the parties may execute a signature page or order form incorporating this DPA.
Schedule 1 – Details of processing
Parties
Data exporter: Customer and each authorized Affiliate on whose behalf Customer accepts this DPA and that transfers Customer Personal Data to the Company. Each data exporter’s address and contact details are those associated with its Account or applicable order form. The data exporter acts as controller under Module Two or processor under Module Three of the EU SCCs. Its activities relevant to the transfer are described under Subject matter and purposes below. Customer is responsible for keeping the data exporter information complete and accurate and will provide additional details reasonably requested by the Company.
Data importer: Avantis Innovations LLC, 75 East 3rd Street, Sheridan, WY 82801, United States. Data-protection contact: [email protected]. The Company acts as processor under Module Two or subprocessor under Module Three of the EU SCCs. Its activities relevant to the transfer are described under Subject matter and purposes below.
The parties are deemed to have entered into and signed the applicable EU SCCs and UK Addendum on the date Customer accepts this DPA.
Subject matter and purposes
The Company processes Customer Personal Data to provide, secure, maintain and support email sending and receiving, contact management, templates, automations, email validation, delivery and engagement analytics, domain management, APIs, webhooks, technical support, abuse prevention and related Service functionality selected or instructed by Customer.
Nature of processing
Processing may include collecting, receiving, recording, organizing, structuring, hosting, storing, retrieving, consulting, using, adapting as technically necessary, transmitting, routing, disclosing to authorized recipients and Subprocessors, restricting, deleting and destroying Customer Personal Data.
Duration and frequency
Processing occurs on a continuous or intermittent basis, depending on Customer’s use of the Services, for the term of the Agreement and the retention period described in this DPA.
Categories of Data Subjects
Data Subjects may include:
- Customer’s customers, prospective customers, subscribers, contacts and end users;
- recipients, senders and other participants in email communications;
- Customer’s personnel, contractors, representatives and Account users; and
- individuals whose information Customer submits through custom fields, message content, attachments, inbound email or integrations.
Categories of Customer Personal Data
Customer Personal Data may include:
- names, email addresses, contact identifiers and other contact details;
- subscription status, consent records, opt-in and opt-out dates, IP addresses, time zones, groups, tags, notes and custom properties;
- sender, recipient, reply-to, CC and BCC information;
- email subject lines, bodies, templates, attachments and inbound-email content;
- domain, routing, authentication and message-header information;
- delivery, bounce, complaint, suppression, opening, clicking and engagement events;
- device, browser, network and approximate-location information where collected through Customer-enabled functionality; and
- any other personal data Customer submits to the Services.
Sensitive data
The Services are not intended for special-category or sensitive personal data. Customer must not submit such data unless the Services expressly support it and the Company has agreed in writing. Where permitted, Customer must apply appropriate safeguards and provide lawful instructions.
Schedule 2 – Technical and organizational measures
The Company maintains technical and organizational measures appropriate to the nature of the Services, Customer Personal Data and reasonably foreseeable risks, including:
- Encryption: Customer Personal Data is encrypted at rest in production databases and object storage.
- Access controls: access to production systems and Customer Personal Data is limited to authorized employees whose job responsibilities require access and is protected through centralized authentication controls.
- Availability: The Company maintains regular backups designed to support the availability and recovery of the Services.
- Personnel confidentiality: The Company will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations or an appropriate legal duty of confidentiality.
- Data and vendor controls: The Company maintains controls supporting data retention and deletion and requires Subprocessors to undertake appropriate data-protection and confidentiality obligations.
The Company may update these measures from time to time, provided that updates do not materially reduce the overall security of the Services during a current paid subscription term.
This Data Processing Agreement is effective as of July 25, 2026.
Avantis Innovations LLC
75 East 3rd Street
Sheridan, WY 82801
United States