This Data Processing Addendum (“DPA”) forms part of the agreement between Deliverably (“Deliverably,” “Processor,” “we,” or “us”) and the customer entity that accepts the Deliverably Terms of Service or an order form referencing this DPA (“Customer,” “Controller,” or “you”).
Together with the Terms of Service and Privacy Policy (as published), this DPA governs Deliverably’s processing of Customer Personal Data on Customer’s behalf when providing the Services.
The Parties intend this DPA to satisfy Article 28 of Regulation (EU) 2016/679 (GDPR) and equivalent requirements under the UK GDPR and other applicable Data Protection Laws.
1. Definitions
Capitalized terms not defined here have the meaning in the Terms or applicable Data Protection Laws.
- Customer Personal Data — Personal Data contained in Customer Content that Deliverably processes as a processor on Customer’s documented instructions (for example: email addresses submitted for validation; email HTML and related content; domain/IP monitoring configuration; DMARC aggregate report content routed for Customer; inbox seed/capture message content and test artifacts).
- Data Protection Laws — GDPR (EU) 2016/679, UK GDPR, Swiss FADP, and other applicable privacy laws that regulate this processing, including where relevant CCPA/CPRA (as a “service provider” / “processor”).
- GDPR — Regulation (EU) 2016/679.
- Personal Data Breach — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by Deliverably (also called a Security Incident in related Deliverably documents).
- Subprocessor — a third party engaged by Deliverably to process Customer Personal Data in connection with the Services.
- Services — the Deliverably platform modules described in the Terms, including Radar, Clarity, Email Validation, and Inbox Testing.
- EEA — the European Economic Area.
Account, billing, marketing, and site analytics data that Deliverably processes as an independent controller are governed by the Privacy Policy, not this DPA (except where the same data is also Customer Personal Data under Customer’s instructions).
2. Roles of the parties
- Customer is the controller (or business) of Customer Personal Data.
- Deliverably is the processor (or service provider) of Customer Personal Data.
- Each party will comply with its obligations under Data Protection Laws for its role, including the GDPR where applicable.
- Customer is solely responsible for the lawfulness of its instructions, for providing required notices to data subjects, and for obtaining any required consents for its email marketing, list processing, and related activities.
3. Processing of Customer Personal Data
Deliverably shall:
- Comply with all applicable Data Protection Laws in the Processing of Customer Personal Data; and
- Process Customer Personal Data only on Customer’s documented instructions, including to:
- Provide the Services (validation, analysis, monitoring, alerting, inbox testing, storage, support, and security);
- Perform processing documented in the Agreement (Terms, order forms, product documentation, and this DPA); and
- Comply with applicable law (in which case Deliverably will inform Customer before processing, unless legally prohibited).
Customer instructs Deliverably to process Customer Personal Data for the purposes and durations described in Annex I. If Deliverably believes an instruction infringes Data Protection Laws, it will notify Customer without undue delay.
Customer must not instruct Deliverably to process special categories of data or children’s data unless the parties agree in writing and Customer has a lawful basis.
4. Artificial intelligence and model training
- Deliverably may use artificial intelligence or machine-learning systems (including third-party AI services such as cloud model APIs) to provide the Services Customer requests — for example, content analysis in Clarity.
- Deliverably does not use Customer Personal Data to train, fine-tune, or improve Deliverably’s own foundation or general-purpose AI models.
- Deliverably will not permit Subprocessors to use Customer Personal Data to train their general-purpose models where Deliverably can reasonably prevent that use through contract or product configuration.
- Aggregated or de-identified data that is not Personal Data may be used to improve the Services, provided it cannot reasonably be used to identify a natural person.
If you need a different arrangement (for example, an opt-in to contribute data to model improvement), that must be agreed in a written addendum.
5. Processor personnel
Deliverably shall take reasonable steps to ensure the reliability of any employee, agent, or contractor who may have access to Customer Personal Data, ensuring that:
- Access is limited to individuals who need to know / access the data to perform the Services or comply with law; and
- Such individuals are subject to confidentiality undertakings or professional or statutory confidentiality obligations.
6. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Deliverably shall implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including measures referred to in Article 32(1) of the GDPR where applicable.
A summary of measures is in Annex II and the Security Policy. Customer is responsible for securing its own accounts, credentials, alert webhooks, and integration keys.
In assessing the appropriate level of security, Deliverably shall take account in particular of the risks presented by Processing, including from a Personal Data Breach.
7. Subprocessors
- Customer authorizes Deliverably to engage Subprocessors to process Customer Personal Data as needed to provide the Services.
- Deliverably will impose data-protection obligations on Subprocessors no less protective than those in this DPA.
- Deliverably remains responsible for Subprocessor performance under this DPA.
- A current list of Subprocessors will be maintained at
[SUBPROCESSORS_URL](or provided on request until published). - Deliverably will give Customer notice of material Subprocessor changes (for example, via email, in-product notice, or list update). Customer may object on reasonable data-protection grounds within 15 days. If the parties cannot resolve an objection, Customer may terminate the affected Services as its sole remedy.
Illustrative categories (not a final list): cloud hosting/infrastructure; payment processing (Stripe — typically controller/processor for payment data, not Customer list content); email transport; AI/content analysis providers; Google (OAuth / Postmaster); Microsoft (SNDS); logging/monitoring vendors.
8. Data subject rights
- Taking into account the nature of the Processing, Deliverably shall assist Customer by implementing appropriate technical and organizational measures, insofar as possible, for the fulfilment of Customer’s obligations to respond to requests to exercise Data Subject rights under Data Protection Laws (including GDPR Chapters III rights where applicable).
- Deliverably shall promptly notify Customer if it receives a request from a Data Subject under any Data Protection Law in respect of Customer Personal Data.
- Deliverably shall not respond to that request except on the documented instructions of Customer or as required by applicable law (in which case Deliverably shall, to the extent permitted by law, inform Customer of that legal requirement before responding).
- Customer remains primarily responsible for responding to its end users and list recipients.
9. Personal Data Breach
- Deliverably shall notify Customer without undue delay upon becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within 24 hours where feasible, providing sufficient information to allow Customer to meet any obligations to report or inform Data Subjects under Data Protection Laws (including GDPR Articles 33 and 34 where applicable).
- Notification will describe, to the extent known: nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.
- Deliverably shall cooperate with Customer and take reasonable commercial steps as directed by Customer to assist in the investigation, mitigation, and remediation of each Personal Data Breach.
- Notification is not an admission of fault.
10. Data protection impact assessment and prior consultation
Deliverably shall provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities that Customer reasonably considers required by Articles 35 or 36 of the GDPR (or equivalent provisions), solely in relation to Processing of Customer Personal Data by Deliverably and taking into account the nature of the Processing and information available to Deliverably.
11. Audits
- Deliverably shall make available to Customer on request information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer in relation to the Processing of Customer Personal Data, subject to this section.
- Upon written request no more than once per twelve (12) months (unless required by a supervisory authority or following a Personal Data Breach), Deliverably will provide security summaries, questionnaire responses, or third-party audit reports under NDA.
- On-site audits are available only if residual concerns cannot be addressed by documentation, on reasonable notice, during business hours, and at Customer’s expense unless a material breach of this DPA is confirmed.
12. Return and deletion
Upon termination of the Services or earlier written request (the “Cessation Date”), Deliverably shall delete or return Customer Personal Data (at Customer’s choice, where technically feasible), and procure deletion of copies, except:
- Data Deliverably must retain under law;
- Data in routine backups, deleted on the backup cycle;
- Short product-specific retention (for example, Inbox Testing artifacts typically expire in about 24 hours); and
- Aggregated or de-identified data that is not Personal Data.
Deletion timing target: without undue delay and in any event within 30 days after the Cessation Date or deletion request, subject to backup cycles.
13. International transfers
- Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the Parties shall ensure the data are adequately protected.
- Unless agreed otherwise, the Parties rely on the European Commission’s Standard Contractual Clauses (Module 2 Controller→Processor and/or Module 3 Processor→Processor as applicable), plus UK International Data Transfer Addendum and Swiss adaptations where required.
- The SCCs (when applicable) are incorporated by reference and completed with Annex I–III of this DPA.
- Primary hosting is in the United States (AWS us-east-1). Customer Personal Data may also be processed in the US and other countries where Subprocessors operate. Exporting countries include the EEA, UK, and Switzerland where Customer or data subjects are located there; importing country for primary infrastructure is the United States.
14. CCPA / US state privacy (service provider)
To the extent the CCPA/CPRA or similar US state laws apply to Customer Personal Data:
- Deliverably acts as a service provider / processor.
- Deliverably will not sell or share Customer Personal Data, retain/use/disclose it outside the business purpose of providing the Services or as permitted by law, or combine it with other personal information except as permitted for service providers.
- Deliverably will comply with applicable restrictions and provide reasonable assistance for Consumer requests routed through Customer.
15. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms (including the twelve-month fees cap), except where Data Protection Laws prohibit limiting liability for a party’s obligations.
16. Confidentiality of this DPA
Each Party must keep this DPA and non-public information it receives about the other Party in connection with this DPA confidential, and must not use or disclose that information without the other Party’s prior written consent, except where disclosure is required by law or the information is already public through no fault of the receiving Party.
17. Term; precedence
This DPA takes effect on the Effective Date and continues for as long as Deliverably processes Customer Personal Data. If there is a conflict between this DPA and the Terms regarding processing of Customer Personal Data, this DPA controls. Mandatory SCCs control over this DPA where required.
18. Contact
Privacy / DPA notices: privacy@deliverably.co
Legal: legal@deliverably.co
Annex I — Description of processing
A. Subject matter and duration
Processing of Customer Personal Data to provide the Services for the term of the customer relationship plus deletion/retention periods in Section 12 and product-specific limits.
B. Nature and purpose
Hosted SaaS processing: storage, transmission, analysis (including AI-assisted analysis to deliver the feature Customer requested), validation, monitoring, alerting, rendering previews, and support. Not for training Deliverably’s own general-purpose AI models (see Section 4).
C. Types of Customer Personal Data (examples)
| Module | Examples |
|---|---|
| Email Validation | Email addresses; validation statuses, reasons, flags |
| Clarity | Email HTML creatives; subjects; analysis outputs |
| Radar | Domains/IPs; DNS/DMARC-related content; alert destination emails/webhook URLs; share tokens; Postmaster/SNDS metrics tied to Customer domains/IPs |
| Inbox Testing | Capture addresses; inbound message content/headers; placement results; preview artifacts |
| Support | Data Customer chooses to share in tickets |
Special categories are not intended to be processed. Customer must not submit them unless agreed in writing.
D. Categories of data subjects
Customer’s employees/contractors (account users); Customer’s subscribers, prospects, or other email recipients whose addresses or message content Customer submits; senders/recipients appearing in DMARC or inbox-capture data as incidental content.
E. Frequency
Continuous / as initiated by Customer use of the Services.
Annex II — Security measures (summary)
See also the Security Policy. Illustrative measures Deliverably maintains as appropriate to risk:
- Access control and authentication for console accounts
- Least-privilege access for production systems
- Encryption in transit (TLS) for public endpoints
- Encryption at rest where provided by infrastructure defaults
- Network and application logging / monitoring for abuse and reliability
- Segregation of customer workspaces at the application data model layer
- Vendor due diligence for material Subprocessors
- Incident response procedures
- Backup and retention controls aligned to product design (including short-lived inbox capture retention)
© 2026 Deliverably. All rights reserved.