This Data Processing Addendum (DPA) forms part of the agreement between the customer using Email Bump and the operator of Email Bump identified in the customer's order or account terms. It applies when Email Bump processes Customer Personal Data on the customer's behalf.
Scope and roles
The customer is the controller or business, and Email Bump is the processor or service provider, for Customer Personal Data processed through the service. Each party will comply with the data protection laws that apply to its role, including the GDPR, UK GDPR, and applicable US state privacy laws when those laws apply.
The customer determines the purposes and means of processing Customer Personal Data and is responsible for its notices, lawful bases, recipient permissions, and instructions. Email Bump will process that data only to provide, secure, maintain, and support the service and as otherwise instructed in writing by the customer.
Processing details
Subject matter and purpose
Email Bump processes personal data to provide marketing and transactional email, campaigns, automated flows, contact management, segmentation, forms, reporting, deliverability, APIs, webhooks, storage, troubleshooting, and customer support.
Duration and frequency
Processing occurs on a continuous or customer-directed basis for the term of the service agreement and for the limited retention period described in this DPA.
Data subjects and data types
Data subjects may include the customer's prospects, subscribers, recipients, customers, users, employees, contractors, and other contacts. Data may include names, email addresses, contact attributes, list and segment membership, consent and suppression status, message content, event data, IP address, device or browser information, and delivery, open, click, bounce, complaint, and unsubscribe activity.
The service is not designed for special-category data, protected health information, payment-card data, government identifiers, or other highly sensitive data. The customer will not submit that data unless Email Bump has agreed in writing to appropriate terms.
Instructions and confidentiality
The service agreement, this DPA, the customer's configuration and use of product features, and other written directions accepted by Email Bump are the customer's documented instructions. Email Bump will notify the customer if an instruction appears to violate applicable data protection law, unless the law prohibits that notice.
Personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and may access the data only as needed to perform their work. If law requires processing beyond the customer's instructions, Email Bump will provide advance notice unless legally prohibited.
Security
Email Bump will maintain administrative, technical, and organizational safeguards appropriate to the risk, nature, and scope of the processing. Measures include access controls, least-privilege practices, encrypted network transport, credential protection, logging and monitoring, backup and recovery practices, vulnerability and dependency management, incident response procedures, and controls for service-provider access.
Security measures may evolve as technology and risks change, but Email Bump will not materially reduce the overall protection of Customer Personal Data during a subscription term.
Subprocessors
The customer gives Email Bump general authorization to use subprocessors to operate the service. Email Bump will require subprocessors that process Customer Personal Data to protect it under obligations that are materially consistent with this DPA and remains responsible for their performance to the extent required by applicable law.
Depending on the customer's features and configuration, current providers may include:
- Amazon Web Services, including Amazon SES, for email delivery and related infrastructure.
- Cloudflare for image and object storage and delivery when those features are enabled.
- PostHog for product analytics when analytics is configured.
- Google for authentication when a user chooses Google sign-in.
- Stripe for subscription billing and related payer information.
Email Bump may add or replace providers as the service evolves. Customers may request notice of material subprocessor changes by emailing [email protected]. A customer with a reasonable data-protection objection may contact us within 15 days of notice, and both parties will work in good faith toward a practical resolution.
Customer assistance
Taking into account the nature of the processing and information available to Email Bump, we will provide reasonable assistance with verified requests involving access, correction, deletion, restriction, objection, or portability. If we receive a request directly from a data subject concerning Customer Personal Data, we will direct the person to the customer unless law requires a different response.
We will also provide reasonable information needed for the customer's data protection impact assessments and regulator consultations. Assistance that requires substantial effort beyond normal service operations may be subject to reasonable fees agreed in advance.
Personal data breaches
Email Bump will notify the customer without undue delay after becoming aware of a confirmed personal data breach involving Customer Personal Data. As information becomes available, the notice will describe the nature of the incident, affected data and people, likely consequences, mitigation taken or planned, and a contact for follow-up.
Email Bump will take reasonable steps to contain, investigate, mitigate, and remediate the incident and will reasonably cooperate with the customer's legally required notifications. Notice does not constitute an admission of fault or liability.
Compliance and audits
Email Bump will make information reasonably necessary to demonstrate compliance with this DPA available on request. Customers should first use current security documentation, certifications, and written responses supplied by Email Bump.
Where applicable law requires more, a customer may conduct one audit per year with at least 30 days' written notice. Audits must occur during normal business hours, avoid unreasonable disruption, protect other customers and confidential information, and use an independent auditor bound by confidentiality. The customer bears its audit costs unless the audit identifies a material breach by Email Bump.
International transfers
Email Bump and its subprocessors may process Customer Personal Data in countries other than the country where it was collected. Each party will comply with applicable transfer requirements. Where required, the parties incorporate the then-current European Commission Standard Contractual Clauses, using Module Two for controller-to-processor transfers and Module Three for processor-to-processor transfers, as applicable.
For transfers governed by UK data protection law, the applicable UK International Data Transfer Addendum modifies those clauses. The customer is the data exporter, Email Bump is the data importer, this DPA describes the processing, and the competent supervisory authority and governing law are determined by the customer's establishment where the clauses permit.
Return and deletion
During the subscription term, the customer may use available product features to export or delete Customer Personal Data. After termination or a valid written request, Email Bump will delete or return Customer Personal Data within 30 days, except where law requires retention or limited copies remain temporarily in protected backups, security records, or suppression records. Retained data remains protected by this DPA and will not be used for another purpose.
General terms
This DPA begins when the customer accepts the service agreement or first submits Customer Personal Data and continues while Email Bump processes that data. If this DPA conflicts with the service agreement on personal-data processing, this DPA controls. The service agreement's liability limits and governing-law terms otherwise apply to this DPA, except where applicable law requires otherwise.
Email Bump may update this DPA to reflect changes in law, the service, or security practices. Material changes will receive notice where required. Data protection questions and requests can be sent to [email protected].