Last updated: June 25, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you (the "Controller") and Email Buster (the "Processor") regarding the processing of personal data on the Controller's behalf.
The Controller determines the purposes and means of processing personal data (e.g. which contacts to email). The Processor processes personal data only on the documented instructions of the Controller — by operating the Service the Controller has purchased.
We use a small set of vetted subprocessors for hosting, payments, and transactional mail delivery. A current Subprocessor list is maintained at privacy@email-buster.app and is updated when sub-processors change. Customers may object to new sub-processors per applicable data-protection law.
Where the Service involves transfers of personal data from the EEA, UK, or Switzerland to a third country without an adequacy decision, we rely on the Standard Contractual Clauses incorporated by reference. (Final DPA to attach the relevant SCCs as an annex.)
We will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, objection) within applicable statutory time-limits.
We will notify the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a personal data breach affecting Controller data.
The Controller may, on reasonable notice and at its own cost, audit our compliance with this DPA via a mutually agreed third-party assessor, subject to confidentiality and non-disruption to other customers.
DPA questions or to formally execute the DPA, contact privacy@email-buster.app.