Data Processing Addendum
A concise DPA framework. A countersigned DPA identifying both legal parties is required before external production processing.
Scope
The customer is the controller or processor that instructs Postline; Postline is the processor or subprocessor for email delivery data. Processing covers receipt, queueing, authentication, delivery, event reporting, suppression, security, and customer-directed deletion or export.
Instructions and confidentiality
Postline processes customer data only on documented instructions, including the service agreement and API actions, unless law requires otherwise. Authorized personnel are bound by confidentiality duties.
Measures and required contract schedules
- Scoped and hashed API credentials, one-time codes, and session tokens
- TLS on supported external paths and an HttpOnly, SameSite=Lax session cookie that is Secure in production
- Project-scoped authorization and suppression checks
- Signed webhooks with timestamp, event ID, and SSRF controls
- The signed DPA must still specify deletion/return, backups, incident notice, audits, subprocessors, processing locations, and any transfer mechanism; this web page is not the executed Article 28 contract
Subprocessors and transfers
The current categories are published on the Subprocessors page. The signed DPA must specify notice, objection, location, and transfer mechanisms appropriate to the parties.
Requests and incidents
Postline will provide reasonable assistance with data-subject requests, risk assessments, deletion, export, and qualifying security incidents according to the signed agreement. Contact privacy@srs-postline.com.