Data processing agreement
Draft — the final version will be published before paid plans open.
Last updated:
No data processing agreement has been signed yet. This draft sets out what it will cover, so you know what to expect before personal data is used in production.
1. Parties and instructions
The agreement will name both parties and their roles, your documented instructions, the purpose and duration of processing, the categories of data and of people, and each party’s responsibilities. Workspace settings do not replace contractual instructions.
2. Technical and organisational measures
The product enforces workspace-scoped permissions and database row-level security, encrypts integration secrets, stores API keys only as hashes and keeps an audit log. Sendalto support can see a workspace only with the owner’s time-limited grant, and every such read is logged.
The security annex will describe the deployed infrastructure, staff confidentiality, restore tests and incident response. Implemented controls are not the same as independent assurance.
3. Subprocessors and transfers
The parties will agree the list of subprocessors, how changes are announced and objected to, where processing happens and which safeguards apply to international transfers. A provider’s name on the integrations page is not a signed subprocessing contract.
4. Assistance, return and deletion
The agreement will cover help with data-subject requests and impact assessments, how and when incidents are reported, audit rights, and return or deletion of data at the end of the contract, along with any retention required by law. This draft does not set deadlines on its own.