Data Processing Addendum
Last updated —
Placeholder pending legal review. A signable DPA must be prepared with counsel before launch.
Roles
For customer data, the customer is the controller and SendNectar is the processor. SendNectar processes personal data only on documented instructions from the customer.
Security measures
Credentials and secrets are encrypted server-side, access is scoped and least-privilege, and the API exposes only an explicit allow-list of resources. Secret and credential stores are never reachable through the API.
Sub-processors
Customers connect their own sending provider, so delivery sub-processing stays under the customer's contract with that provider. A current list of SendNectar's own sub-processors will be maintained here.
Data subject requests
The platform supports access, portability, correction, and erasure, with erasure tombstones, region-aware retention, and legal holds to assist controllers in meeting their obligations.
Deletion
On termination, customer data is deleted or returned in line with the applicable retention policies and any active legal holds.