FutureMail

Legal

Data Processing Addendum

Effective

This DPA sets out how FutureMail processes personal data on behalf of its customers, as required by Article 28 of the GDPR and similar laws. It applies automatically to every customer that needs it as part of the Terms of Service; if your organization needs a countersigned copy, email support@futuremail.dev.

1.Scope and roles

This Data Processing Addendum ("DPA") applies when FutureMail processes personal data on a customer's behalf in providing the Service, and that processing is subject to the EU or UK General Data Protection Regulation, the Swiss Federal Act on Data Protection, or other data protection laws that require such terms ("Data Protection Laws").

The customer is the controller (or a processor acting for its own controller) and R&R Unicorns, LLC, doing business as FutureMail ("FutureMail") is the processor (or subprocessor) of the personal data contained in Customer Data, as defined in the Terms of Service ("Customer Personal Data"). This DPA forms part of the Terms and is incorporated into them automatically for every customer that needs it; no signature is required. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data.

2.Details of the processing

  • Subject matter and duration: providing the Service for the term of the customer's subscription, plus the post-termination periods described in the Terms.
  • Nature and purpose: receiving, storing, sending, indexing, searching and displaying email; delivery and engagement tracking when enabled; webhooks and API access; security and abuse prevention; support.
  • Categories of data subjects: the customer's team members, and people who send email to, or receive email from, the customer's domains, addresses and agents.
  • Categories of personal data: names, email addresses, message content and attachments, message headers and metadata, delivery events, and (when tracking is enabled) IP addresses, user agents and open/click times. Message content may contain any data a sender chooses to include; the customer should not use the Service to process special categories of data unless it has assessed that this is appropriate.

3.FutureMail's obligations

FutureMail will:

  • process Customer Personal Data only on the customer's documented instructions, which are the Terms, this DPA and the customer's use and configuration of the Service, unless required otherwise by law (in which case we will inform the customer unless the law prohibits it);
  • tell the customer if it believes an instruction infringes Data Protection Laws;
  • ensure that people authorized to process Customer Personal Data are bound by confidentiality;
  • implement the technical and organizational measures in the Annex;
  • assist the customer, taking into account the nature of the processing, with responding to data subjects' requests, and with security, breach notification, data protection impact assessments and prior consultations; and
  • make available the information needed to demonstrate compliance with this DPA, as described under Audits.

The customer is responsible for the lawfulness of its instructions and of the Customer Personal Data it provides, including having the notices and consents required for the email it sends and receives.

4.Subprocessors

The customer gives FutureMail general authorization to engage subprocessors. The current list is on our subprocessors page. FutureMail imposes data protection obligations on each subprocessor that are no less protective than this DPA and remains responsible for its subprocessors' performance. We will update the list at least 30 days before a new subprocessor starts processing Customer Personal Data (and notify customers who ask at support@futuremail.dev to receive notice by email). The customer may object on reasonable data protection grounds within that period; if we can't reasonably address the objection, the customer may cancel the affected Service and receive a refund of prepaid fees for the period after cancellation.

5.International transfers

FutureMail processes Customer Personal Data in the United States. To the extent a transfer of Customer Personal Data from the EEA, the UK or Switzerland to FutureMail is a restricted transfer, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs") are incorporated into this DPA by reference, as follows:

  • Module 2 (controller to processor) applies where the customer is a controller, and Module 3 (processor to processor) where the customer is a processor;
  • Clause 7 (docking clause) applies; in Clause 9, Option 2 (general authorization) applies with the notice period in the Subprocessors section; the optional language in Clause 11 does not apply;
  • in Clauses 17 and 18, the governing law and courts are those of Ireland;
  • Annex I is completed by the Details of the processing section above (the customer is the data exporter, FutureMail the data importer), and Annex II by the Annex below; and
  • for the UK, the International Data Transfer Addendum issued by the UK Information Commissioner applies, and for Switzerland the SCCs apply with the references adapted to Swiss law.

If the SCCs conflict with this DPA or the Terms, the SCCs prevail.

6.Personal data breaches

FutureMail will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, its likely consequences, and the measures taken or proposed. We will take reasonable steps to contain and remediate the breach and provide further information as it becomes available. Notifying a breach is not an admission of fault.

7.Deletion and return

During the subscription the customer can export and delete Customer Personal Data using the Service, the API and the CLI. After the subscription ends, Customer Personal Data stays available for export for at least 30 days, after which FutureMail may delete it, and will delete it on the customer's request unless the law requires us to keep it. Deleted data is purged from backups on a rolling basis, within 400 days at most, and remains protected by this DPA until then.

8.Audits

On written request, no more than once a year (or after a personal data breach, or when required by a supervisory authority), FutureMail will answer reasonable written questions and provide documentation about its processing and security measures. If that is not enough to demonstrate compliance, the customer may conduct an audit, at its own cost, with reasonable advance notice, during business hours, in a way that does not disrupt the Service or compromise other customers' data, and subject to confidentiality. Audit requests go to support@futuremail.dev.

9.Liability

Each party's liability under or in connection with this DPA, including the SCCs to the extent permitted, is subject to the exclusions and limitations of liability in the Terms. Nothing in this DPA limits a data subject's rights under the SCCs or Data Protection Laws.

10.Annex: technical and organizational measures

  • Encryption in transit. TLS for the website, the API, webhooks and connections to our providers; TLS for email in transit whenever the other server supports it, with an option to require it per domain.
  • Encryption at rest. Off-site backups are encrypted, and objects stored in Amazon S3 are encrypted at rest.
  • Credentials. API keys are stored only as hashes and shown once; keys can be scoped to read or send, pinned to one mailbox or domain, and given an expiry. Webhook deliveries are HMAC-signed.
  • Access control. Organizations have owner, admin, developer and viewer roles. Administrative access to production systems is limited to authorized personnel and granted only as needed.
  • Isolation. Every query is scoped to the customer's organization; agent keys can only reach their own mailbox.
  • Logging and monitoring. An audit log of organization changes, API request logs (30 days), and monitoring and alerting for errors, abuse and sending reputation.
  • Backups and resilience. Regular database snapshots and off-site, encrypted backups; deleted data is purged from backups on a rolling basis within 400 days at most.
  • Abuse prevention. Sending limits, new-account ramp-up, automatic suppression of bounces and complaints, and automatic suspension above bounce and complaint thresholds.
  • Vendor management. Subprocessors are bound by written data protection terms.

11.Contact

R&R Unicorns, LLC, doing business as FutureMail
1111b S South Governors Avenue, Dover, DE 19904, USA
support@futuremail.dev