Email Bump
Features
Behavioural trackingEmail that reacts to what people actually doNewsletters & campaignsWrite it once, send it when each reader is awakeTransactional & SMTPProduct email over an API or plain SMTPEmail for AI agentsGive an agent a mailbox it can actually answer fromInbound emailReceive email, not just send itAutomationsJourneys that run on their ownSegmentation & CRMAudiences that keep themselves up to dateDeliverabilityAuthenticated sending, and the numbers to prove itAnalyticsWhat happened, and what it was worth
PricingDocsResources
BlogGuides and product notesGlossaryEmail terms, explainedFree toolsCheckers and calculatorsAI agent emailAddresses agents can send and receive fromAgentsSkills, CLI and MCP
Company
AboutWho builds itCareersOpen roles
Log inStart For Free Join With Google
LEGAL / DPA

Data Processing Addendum

The data protection terms that apply when Email Bump processes personal data for a customer.

Effective July 22, 2026
EMAIL BUMP
ON THIS PAGE
Scope and rolesProcessing detailsInstructions and confidentialitySecuritySubprocessorsCustomer assistancePersonal data breachesCompliance and auditsInternational transfersReturn and deletionGeneral terms

This Data Processing Addendum (DPA) forms part of the agreement between the customer using Email Bump and the operator of Email Bump identified in the customer's order or account terms. It applies when Email Bump processes Customer Personal Data on the customer's behalf.

01

Scope and roles

The customer is the controller or business, and Email Bump is the processor or service provider, for Customer Personal Data processed through the service. Each party will comply with the data protection laws that apply to its role, including the GDPR, UK GDPR, and applicable US state privacy laws when those laws apply.

The customer determines the purposes and means of processing Customer Personal Data and is responsible for its notices, lawful bases, recipient permissions, and instructions. Email Bump will process that data only to provide, secure, maintain, and support the service and as otherwise instructed in writing by the customer.

02

Processing details

Subject matter and purpose

Email Bump processes personal data to provide marketing and transactional email, campaigns, automated flows, contact management, segmentation, forms, reporting, deliverability, APIs, webhooks, storage, troubleshooting, and customer support.

Duration and frequency

Processing occurs on a continuous or customer-directed basis for the term of the service agreement and for the limited retention period described in this DPA.

Data subjects and data types

Data subjects may include the customer's prospects, subscribers, recipients, customers, users, employees, contractors, and other contacts. Data may include names, email addresses, contact attributes, list and segment membership, consent and suppression status, message content, event data, IP address, device or browser information, and delivery, open, click, bounce, complaint, and unsubscribe activity.

The service is not designed for special-category data, protected health information, payment-card data, government identifiers, or other highly sensitive data. The customer will not submit that data unless Email Bump has agreed in writing to appropriate terms.

03

Instructions and confidentiality

The service agreement, this DPA, the customer's configuration and use of product features, and other written directions accepted by Email Bump are the customer's documented instructions. Email Bump will notify the customer if an instruction appears to violate applicable data protection law, unless the law prohibits that notice.

Personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and may access the data only as needed to perform their work. If law requires processing beyond the customer's instructions, Email Bump will provide advance notice unless legally prohibited.

04

Security

Email Bump will maintain administrative, technical, and organizational safeguards appropriate to the risk, nature, and scope of the processing. Measures include access controls, least-privilege practices, encrypted network transport, credential protection, logging and monitoring, backup and recovery practices, vulnerability and dependency management, incident response procedures, and controls for service-provider access.

Security measures may evolve as technology and risks change, but Email Bump will not materially reduce the overall protection of Customer Personal Data during a subscription term.

05

Subprocessors

The customer gives Email Bump general authorization to use subprocessors to operate the service. Email Bump will require subprocessors that process Customer Personal Data to protect it under obligations that are materially consistent with this DPA and remains responsible for their performance to the extent required by applicable law.

Depending on the customer's features and configuration, current providers may include:

  • Amazon Web Services, including Amazon SES, for email delivery and related infrastructure.
  • Cloudflare for image and object storage and delivery when those features are enabled.
  • PostHog for product analytics when analytics is configured.
  • Google for authentication when a user chooses Google sign-in.
  • Stripe for subscription billing and related payer information.

Email Bump may add or replace providers as the service evolves. Customers may request notice of material subprocessor changes by emailing [email protected]. A customer with a reasonable data-protection objection may contact us within 15 days of notice, and both parties will work in good faith toward a practical resolution.

06

Customer assistance

Taking into account the nature of the processing and information available to Email Bump, we will provide reasonable assistance with verified requests involving access, correction, deletion, restriction, objection, or portability. If we receive a request directly from a data subject concerning Customer Personal Data, we will direct the person to the customer unless law requires a different response.

We will also provide reasonable information needed for the customer's data protection impact assessments and regulator consultations. Assistance that requires substantial effort beyond normal service operations may be subject to reasonable fees agreed in advance.

07

Personal data breaches

Email Bump will notify the customer without undue delay after becoming aware of a confirmed personal data breach involving Customer Personal Data. As information becomes available, the notice will describe the nature of the incident, affected data and people, likely consequences, mitigation taken or planned, and a contact for follow-up.

Email Bump will take reasonable steps to contain, investigate, mitigate, and remediate the incident and will reasonably cooperate with the customer's legally required notifications. Notice does not constitute an admission of fault or liability.

08

Compliance and audits

Email Bump will make information reasonably necessary to demonstrate compliance with this DPA available on request. Customers should first use current security documentation, certifications, and written responses supplied by Email Bump.

Where applicable law requires more, a customer may conduct one audit per year with at least 30 days' written notice. Audits must occur during normal business hours, avoid unreasonable disruption, protect other customers and confidential information, and use an independent auditor bound by confidentiality. The customer bears its audit costs unless the audit identifies a material breach by Email Bump.

09

International transfers

Email Bump and its subprocessors may process Customer Personal Data in countries other than the country where it was collected. Each party will comply with applicable transfer requirements. Where required, the parties incorporate the then-current European Commission Standard Contractual Clauses, using Module Two for controller-to-processor transfers and Module Three for processor-to-processor transfers, as applicable.

For transfers governed by UK data protection law, the applicable UK International Data Transfer Addendum modifies those clauses. The customer is the data exporter, Email Bump is the data importer, this DPA describes the processing, and the competent supervisory authority and governing law are determined by the customer's establishment where the clauses permit.

10

Return and deletion

During the subscription term, the customer may use available product features to export or delete Customer Personal Data. After termination or a valid written request, Email Bump will delete or return Customer Personal Data within 30 days, except where law requires retention or limited copies remain temporarily in protected backups, security records, or suppression records. Retained data remains protected by this DPA and will not be used for another purpose.

11

General terms

This DPA begins when the customer accepts the service agreement or first submits Customer Personal Data and continues while Email Bump processes that data. If this DPA conflicts with the service agreement on personal-data processing, this DPA controls. The service agreement's liability limits and governing-law terms otherwise apply to this DPA, except where applicable law requires otherwise.

Email Bump may update this DPA to reflect changes in law, the service, or security practices. Material changes will receive notice where required. Data protection questions and requests can be sent to [email protected].

Email Bump

Marketing and transactional email for modern teams.

PricingDocsBlogGlossaryToolsCompareAI agent emailvs AgentMailAgentsCLIMCPAboutCareersPrivacyTermsDPALog inAgents.md
Free alternatives to
  • Mailchimp
  • ActiveCampaign
  • Klaviyo
  • HubSpot
  • SendGrid
  • Mailgun
  • Brevo
  • MailerLite
  • Kit
  • Constant Contact
  • GetResponse
  • Omnisend
  • Substack
  • Resend
Open-source alternatives to
  • Mailchimp
  • ActiveCampaign
  • HubSpot
  • Klaviyo
  • Resend
© 2026 Email Bump