Data Processing Agreement
Last updated: 2026-07-31
This Data Processing Agreement (“DPA”) forms part of the SendLint Terms of Service between SendLint (“Processor”) and the customer organization (“Controller”) for any personal data Processor handles on Controller’s behalf. It is intended to support compliance with the EU General Data Protection Regulation (“GDPR”), the UK Data Protection Act, and equivalent regimes.
1. Subject matter & duration
Processor processes personal data submitted by Controller’s users (email QA inputs, account credentials, usage telemetry) for the duration of the active service subscription, terminating automatically upon account deletion.
2. Nature & purpose of processing
Processing is limited to (a) hosting and analyzing the email HTML Controller uploads, (b) generating QA reports against Controller’s configured brand rules, (c) optional AI passes against Anthropic Claude with explicit per-call opt-in, and (d) operational telemetry necessary to run the service (auth, billing, performance monitoring).
End-recipient consent: Controller is solely responsible for ensuring the lawful basis on which marketing emails are sent to end-recipients, including compliance with CAN-SPAM (US), CASL (Canada), GDPR/ePrivacy (EU/UK), and equivalent regimes. Processor does not send marketing emails to end-recipients on behalf of Controller; it only analyzes the email content Controller uploads for QA purposes.
Controller-configured sharing: Controller may optionally (i) enable Slack notifications, which send QA notification content (round status, comment previews, and the email addresses of mentioned users) to a Slack workspace Controller designates, and (ii) generate public, unauthenticated, revocable links (30-day default expiry) that let recipients Controller chooses view a report or round brief without authenticating. These destinations are controlled by Controller, not Processor, and Controller is responsible for their configuration and use.
3. Categories of data subjects & personal data
Data subjects: Controller’s end-customers whose email addresses or names may appear inside marketing email HTML submitted for QA, plus Controller’s own employees authenticated to the platform.
Personal data: Account email + display name + role; raw email HTML which may include subscriber names, addresses, transactional values, or other tokens; payment instrument metadata processed by Stripe (Processor never sees full card numbers).
4. Sub-processors
The following sub-processors are engaged. Processor will give Controller 30 days’ notice before adding a new sub-processor, by email to the organization owner and a notice in the in-app dashboard. Controller may object during the notice period by emailing admin@sendlint.com; if the parties cannot resolve the objection, Controller may terminate the service without penalty for the unused portion of the term.
- Supabase (database, auth) — US East & EU
- Vercel (hosting, edge) — global edge
- Anthropic (AI features, opt-in only) — US
- Stripe (billing) — US, processes Standard Contractual Clauses
- Resend (transactional email) — US
- Sentry (error reporting) — US/EU
- PostHog (product analytics) — US
Slack (when Controller enables it) and public share links are Controller-configured destinations, not Processor sub-processors: data flows to a workspace or to recipients Controller designates and controls.
5. Security measures
Processor implements TLS 1.2+ in transit, AES-256 at rest, row-level security at the database layer, principle-of-least-privilege service-role usage, SSRF protections on outbound rendering, and rate limiting per-IP and per-org on heavy routes. Access to production data is restricted to named operators and logged. Optional two-factor authentication (TOTP) is available to all users, and security-relevant QA workflow actions (status changes, sign-offs, manual findings, shares) are recorded in an append-only audit log.
6. Data subject rights
Controller may exercise rights of access, rectification, erasure, restriction, and portability on behalf of its data subjects via the in-product profile page (/profile — profile details are user-editable; a JSON export of personal data is available via “Download my data”; account deletion is available from the Account tab) or by emailing admin@sendlint.com. To rectify data inside submitted email content, Controller should re-upload the corrected version and request deletion of the prior report. Processor will respond within 30 days of a verified request.
7. International transfers
Where personal data is transferred outside the EU/UK, Processor relies on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and an assessment of equivalent protection in the destination jurisdiction. A counter-signed copy of the SCCs is provided within 5 business days of request — email admin@sendlint.comwith Controller’s legal entity details to initiate. For expedited deals, Processor will execute Controller’s standard DPA template provided it covers EU-UK data transfers via SCCs.
8. Breach notification
Processor will notify Controller in writing within 72 hours of becoming aware of a personal data breach affecting Controller’s data, including the categories and approximate number of data subjects affected and the steps taken to mitigate the breach.
9. Audit rights
Processor will make available all information necessary to demonstrate compliance with this DPA. Controller may, with 30 days’ notice and no more than annually, conduct or commission an audit; audits will be conducted during business hours and will not unreasonably interfere with Processor’s operations.
10. Return or deletion of data
On termination of the service, Processor will, at Controller’s choice, return all personal data or delete it (including from sub-processors), within 30 days of termination, unless retention is required by law.
Execution
This DPA may be incorporated by reference into your subscription. For a counter-signed copy, contact admin@sendlint.com. For the full privacy policy see our privacy page.
This template covers the operational baseline for self-serve customers. Enterprise customers requiring custom redlines or executed Standard Contractual Clauses should contact admin@sendlint.com.