PufferPost

Data Processing Agreement

Version 2026-06 · Effective 1 June 2026 · Download as text

This agreement is provided for transparency and is pending final legal review. The hosting provider named in section 6 is confirmed in your countersigned copy. For a countersigned copy, or to add your own terms, email privacy@pufferpost.com.

1. Parties and roles

This Data Processing Agreement forms part of the agreement between you (the customer, acting as the data controller) and PufferPost (acting as the data processor) for the processing of personal data carried out when we deliver your transactional email. It is incorporated into our Terms of Service and is accepted when you create an account and use the service; no separate signature is required. A countersigned copy is available on request.

2. Subject matter and duration

We process personal data on your behalf for as long as you have an active account, and for the limited retention window after which message content and delivery events are purged automatically. The retention window is set by your plan and your workspace retention settings (which you can configure down from the plan maximum); delivery events and metadata may be kept slightly longer than message content.

3. Nature and purpose

We process the data only to accept, render, send, and report on the transactional email you ask us to deliver, and to operate your account. We never use it for advertising, profiling, or for any purpose of our own.

4. Data and data subjects

The data concerns your recipients and consists of the recipient address, the message content and template variables you supply, and the resulting delivery events. The data subjects are the people you choose to email.

5. Our obligations

We process the data only on your documented instructions — being this Agreement and the configuration and requests you make through our API and dashboard; any other instruction must be agreed in writing. If we are required by EU or member-state law to process the data otherwise than on your instructions, we will inform you of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.

Any of our personnel authorised to process the data are bound by a contractual or statutory duty of confidentiality. We secure the data with appropriate technical and organisational measures (section 8); taking into account the nature of processing and the information available to us, we assist you with security of processing, personal-data-breach notification, data-protection impact assessments, and prior consultation with the supervisory authority. We make available the information needed to demonstrate compliance with these obligations, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate (section 8). Personal data is stored on infrastructure inside the European Union.

6. Sub-processors

You authorise us to engage the following sub-processors to host the platform, deliver your email, report delivery events, and operate billing. Each one's purpose and processing region is below.

Sub-processor Purpose Region
EU cloud host (named in your countersigned copy) Platform hosting, database, and attachment storage EU
Amazon SES Email delivery EU (Frankfurt)
Amazon SNS Delivery event notifications EU (Frankfurt)
Stripe Payments Europe, Ltd. Billing and payments (account and billing-contact data; card data never reaches PufferPost servers) EU; US transfers under Standard Contractual Clauses

We impose on each sub-processor, by written contract, the same data-protection obligations set out in this Agreement, and we remain fully liable to you for any sub-processor that fails to fulfil them. We will give you at least 30 days' prior notice, by email to your account contact and on this page, before a new sub-processor begins processing. If you reasonably object on data-protection grounds and we cannot accommodate the objection, you may terminate the affected service without penalty for the unused prepaid term.

7. International transfers

All recipient email data is stored at rest only in the European Union. Email delivery and delivery-event processing take place in Frankfurt (eu-central-1) under our delivery provider's data processing agreement and EU Standard Contractual Clauses. Billing data is processed by Stripe, whose group is headquartered in the United States, under Stripe's data processing agreement and EU Standard Contractual Clauses. Where any sub-processor is operated by a company based outside the European Union, the transfer is covered by those clauses together with additional safeguards, and the recipient data continues to be stored in an EU region.

8. Security and breach notification

Data is encrypted in transit and at rest. Access is restricted, least-privilege, and logged. Recipient data in delivery events is minimised at ingest, and security-relevant actions are kept in an audit log. We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any breach affecting personal data we process on your behalf — describing its nature, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken — and we will assist you in meeting your own notification obligations.

Technical and organisational measures

9. Data subject requests and deletion

Taking into account the nature of processing, we provide self-service export and erasure tooling in the dashboard and API so you can fulfil data-subject access and erasure requests directly, and we otherwise assist you promptly. On termination, at your choice we will delete or return all personal data we process on your behalf, and delete existing copies within 30 days — except suppression entries (and any data we are legally required to retain), which we keep so opted-out recipients stay opted out. We will confirm deletion on request.