← Email Buster

Data Processing Addendum (DPA)

Last updated: June 25, 2026

PLACEHOLDER CONTENT. This is a starter DPA stub. The final DPA should be reviewed by counsel, include Standard Contractual Clauses where applicable for international transfers, and a current Subprocessor list. Replace before going live.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you (the "Controller") and Email Buster (the "Processor") regarding the processing of personal data on the Controller's behalf.

1. Roles

The Controller determines the purposes and means of processing personal data (e.g. which contacts to email). The Processor processes personal data only on the documented instructions of the Controller — by operating the Service the Controller has purchased.

2. Scope of processing

  • Categories of data subjects: the Controller's prospect / contact records, mailbox owners, and end-recipients of campaigns.
  • Types of data: email address, name, company affiliation, custom fields supplied by the Controller, and event data about messages sent (opens, clicks, replies, bounces).
  • Duration: for the term of the Service plus the retention windows in our Privacy Policy.

3. Security measures

  • Mailbox credentials encrypted at rest with AES-256-GCM.
  • Tenant isolation enforced at the database layer via Postgres Row-Level Security.
  • Authenticated webhook verification (HMAC-SHA256) for inbound integrations.
  • SSO-friendly auth (Argon2id password hashing, JWT in httpOnly cookies).
  • Continuous SPF/DKIM/DMARC monitoring of customer sending domains.
  • Backups, access controls, and incident-response policies maintained internally.

4. Subprocessors

We use a small set of vetted subprocessors for hosting, payments, and transactional mail delivery. A current Subprocessor list is maintained at privacy@email-buster.app and is updated when sub-processors change. Customers may object to new sub-processors per applicable data-protection law.

5. International transfers

Where the Service involves transfers of personal data from the EEA, UK, or Switzerland to a third country without an adequacy decision, we rely on the Standard Contractual Clauses incorporated by reference. (Final DPA to attach the relevant SCCs as an annex.)

6. Data subject rights

We will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, objection) within applicable statutory time-limits.

7. Breach notification

We will notify the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a personal data breach affecting Controller data.

8. Audit

The Controller may, on reasonable notice and at its own cost, audit our compliance with this DPA via a mutually agreed third-party assessor, subject to confidentiality and non-disruption to other customers.

9. Contact

DPA questions or to formally execute the DPA, contact privacy@email-buster.app.

← Back to email-buster.app