DATA PROCESSING AGREEMENT (DPA)

Version: 1.0.0 Effective Date: September 1, 2026 Last Updated: September 2026


Between:

Data Processor: Devi Devs Technologies S.R.L., a company incorporated under the laws of Romania, with registered office at Aleea Textiliștilor 7, Bl. MY12, Sc. 2, Et. 8, Ap. 63, Sector 3, București, registered at the Trade Registry under no. J40/13982/2023, fiscal code (CUI) 48553919 ("Processor", "DeviDevs", "we", "us")

and

Data Controller: The entity identified in the Service Agreement that has executed or accepted the Terms of Service of ClevMail ("Controller", "Client", "you")

Collectively referred to as the "Parties" and individually as a "Party".


1. DEFINITIONS

1.1. In this DPA, the following terms shall have the meanings set out below, unless the context requires otherwise:

TermDefinition
Applicable Data Protection LawAll laws and regulations applicable to the processing of Personal Data, including but not limited to: Regulation (EU) 2016/679 ("GDPR"), Legea nr. 190/2018 (Romanian GDPR implementation law), Legea nr. 506/2004 (processing of personal data in electronic communications), Directive 2002/58/EC ("ePrivacy Directive"), Regulation (EU) 2024/1689 ("EU AI Act"), and Regulation (EU) 2023/2854 ("Data Act"), as amended or superseded.
ControllerThe natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data (GDPR Art. 4(7)). In this DPA, the Client.
Data BreachA breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed (GDPR Art. 4(12)).
Data SubjectAn identified or identifiable natural person to whom the Personal Data relates (GDPR Art. 4(1)). In this DPA, primarily the Controller's subscribers and contacts.
DPIAData Protection Impact Assessment as defined in GDPR Art. 35.
EEAThe European Economic Area (EU Member States plus Iceland, Liechtenstein, and Norway).
Personal DataAny information relating to an identified or identifiable natural person (GDPR Art. 4(1)).
PlatformClevMail, a SaaS email marketing and automation service accessible at the URLs specified in the Service Agreement.
ProcessingAny operation or set of operations performed on Personal Data, whether or not by automated means (GDPR Art. 4(2)), including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
ProcessorA natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller (GDPR Art. 4(8)). In this DPA, DeviDevs.
Service AgreementThe Terms of Service, order form, or other agreement between the Parties governing the provision of the Platform services.
Standard Contractual Clauses (SCCs)The standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021.
Sub-processorAny third party engaged by the Processor to process Personal Data on behalf of the Controller.
Supervisory AuthorityThe independent public authority responsible for monitoring the application of data protection law. For Romania: Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP).
Technical and Organisational Measures (TOMs)The security measures implemented by the Processor to protect Personal Data, as described in Annex 2 of this DPA.

1.2. Terms not defined herein shall have the meaning ascribed to them in the GDPR or the Service Agreement, as applicable.


2. SCOPE AND ROLES

2.1. This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Platform services under the Service Agreement.

2.2. The Controller is the entity that determines the purposes and means of processing its subscribers' Personal Data through the Platform. The Controller is responsible for:

  • (a) ensuring the lawfulness of the collection and processing of Personal Data, including obtaining and maintaining valid consent from Data Subjects where required;
  • (b) providing documented instructions to the Processor regarding the processing of Personal Data;
  • (c) complying with all Applicable Data Protection Law in its capacity as Controller.

2.3. The Processor processes Personal Data solely on behalf of and under the documented instructions of the Controller, as further described in this DPA and Annex 1.

2.4. This DPA supplements and forms an integral part of the Service Agreement. In the event of any conflict between this DPA and the Service Agreement regarding data protection matters, this DPA shall prevail.

2.5. The Processor provides sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of the GDPR and ensure the protection of the rights of Data Subjects (GDPR Art. 28(1)).


3. SUBJECT-MATTER, NATURE, PURPOSE, AND DURATION OF PROCESSING

3.1. The details of the processing are set out in Annex 1 and include:

  • (a) the subject-matter and duration of the processing;
  • (b) the nature and purpose of the processing;
  • (c) the type of Personal Data processed;
  • (d) the categories of Data Subjects.

3.2. The duration of processing shall be the term of the Service Agreement, unless otherwise specified in this DPA or required by Applicable Data Protection Law.


4. CONTROLLER'S OBLIGATIONS

4.1. Lawful Basis. The Controller warrants that it has a valid legal basis for the processing of Personal Data under GDPR Art. 6(1), including but not limited to:

  • (a) consent of the Data Subject (Art. 6(1)(a)) for marketing communications;
  • (b) performance of a contract (Art. 6(1)(b)) where applicable;
  • (c) legitimate interest (Art. 6(1)(f)) where applicable and documented.

4.2. Consent Management. Where the lawful basis is consent, the Controller shall:

  • (a) obtain consent that is freely given, specific, informed, and unambiguous, by a clear affirmative act (GDPR Art. 4(11), Art. 7; EDPB Guidelines 05/2020);
  • (b) maintain verifiable records of consent, including: identity of the Data Subject, date and time of consent, information provided at the time, and method of consent;
  • (c) comply with Legea 506/2004 Art. 12 regarding prior express consent for commercial electronic communications;
  • (d) ensure that withdrawal of consent is as easy as giving it (GDPR Art. 7(3)).

4.3. Documented Instructions. The Controller shall provide the Processor with documented instructions regarding the processing of Personal Data. The use of the Platform in accordance with the Service Agreement and this DPA constitutes the Controller's complete documented instructions, unless additional instructions are provided in writing.

4.4. Compliance. The Controller is responsible for ensuring that the content of emails sent through the Platform complies with Applicable Data Protection Law, including but not limited to:

  • (a) Legea 506/2004 Art. 12 (identification of sender, valid unsubscribe mechanism);
  • (b) Legea 365/2002 (clear identification of commercial communications);
  • (c) CAN-SPAM Act (for US recipients: physical address, opt-out processing within 10 business days);
  • (d) the Processor's Anti-Spam Policy and Acceptable Use Policy.

5. PROCESSOR'S OBLIGATIONS

5.1. Processing on Instructions (Art. 28(3)(a))

5.1.1. The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation.

5.1.2. If the Processor is required by EU or Member State law to process Personal Data other than as instructed by the Controller, the Processor shall inform the Controller of that legal requirement before processing, unless such law prohibits such information on important grounds of public interest.

5.1.3. The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes the GDPR or other EU or Member State data protection provisions (GDPR Art. 28(3), final paragraph).

5.2. Confidentiality (Art. 28(3)(b))

5.2.1. The Processor shall ensure that all persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.2.2. The Processor shall ensure that access to Personal Data is limited to those personnel who need access to fulfil the Processor's obligations under this DPA.

5.3. Security Measures (Art. 28(3)(c), Art. 32)

5.3.1. The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2 of this DPA.

5.3.2. These measures shall include, as appropriate:

  • (a) the pseudonymisation and encryption of Personal Data (Art. 32(1)(a));
  • (b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services (Art. 32(1)(b));
  • (c) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident (Art. 32(1)(c));
  • (d) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing (Art. 32(1)(d)).

5.3.3. The Processor shall regularly review and update the security measures to ensure continued appropriateness.

5.4. Sub-processing (Art. 28(3)(d), Art. 28(2), Art. 28(4))

5.4.1. The Controller hereby grants the Processor a general written authorisation to engage Sub-processors for the performance of specific processing activities on behalf of the Controller. The current list of approved Sub-processors is set out in Annex 3.

5.4.2. Notification of Changes. The Processor shall inform the Controller of any intended changes regarding the addition or replacement of Sub-processors at least thirty (30) days before such change, thereby giving the Controller the opportunity to object to such changes.

5.4.3. Right to Object. If the Controller objects to a new Sub-processor on reasonable grounds relating to data protection, the Processor shall use commercially reasonable efforts to make available to the Controller a change in the Platform or recommend a commercially reasonable alternative. If the Processor is unable to provide such alternative within thirty (30) days of the Controller's objection, the Controller may terminate the Service Agreement with respect to the affected processing activities, with a pro-rata refund of any prepaid fees for the terminated portion.

5.4.4. Sub-processor Obligations. Where the Processor engages a Sub-processor, the Processor shall:

  • (a) impose on the Sub-processor, by way of a written contract, the same data protection obligations as set out in this DPA (Art. 28(4));
  • (b) remain fully liable to the Controller for the performance of the Sub-processor's obligations (Art. 28(4)).

5.5. Assistance with Data Subject Rights (Art. 28(3)(e))

5.5.1. The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights under Chapter III of the GDPR (Articles 15-22), including:

  • (a) right of access (Art. 15);
  • (b) right to rectification (Art. 16);
  • (c) right to erasure ("right to be forgotten") (Art. 17);
  • (d) right to restriction of processing (Art. 18);
  • (e) notification obligation regarding rectification, erasure, or restriction (Art. 19);
  • (f) right to data portability (Art. 20);
  • (g) right to object (Art. 21);
  • (h) rights related to automated individual decision-making, including profiling (Art. 22).

5.5.2. If a Data Subject contacts the Processor directly regarding the exercise of their rights, the Processor shall promptly redirect such request to the Controller and shall not respond to the Data Subject directly without the Controller's prior written authorisation.

5.5.3. The Platform provides self-service tools enabling the Controller to respond to Data Subject requests, including subscriber data export, modification, and deletion functionality.

5.6. Assistance with Compliance Obligations (Art. 28(3)(f))

5.6.1. The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor:

  • (a) security of processing (Art. 32);
  • (b) notification of a Data Breach to the Supervisory Authority (Art. 33);
  • (c) communication of a Data Breach to the Data Subject (Art. 34);
  • (d) data protection impact assessments (Art. 35);
  • (e) prior consultation with the Supervisory Authority (Art. 36).

5.7. Data Deletion and Return (Art. 28(3)(g))

5.7.1. Upon termination or expiry of the Service Agreement, the Processor shall, at the Controller's choice:

  • (a) return all Personal Data to the Controller in a commonly used, machine-readable format (CSV or JSON); or
  • (b) delete all Personal Data and existing copies.

5.7.2. The Processor shall complete the return or deletion within thirty (30) days of termination, unless Applicable Data Protection Law requires further storage.

5.7.3. The Controller may request the data export using the Platform's self-service export functionality at any time during the term of the Service Agreement.

5.7.4. Upon completion of deletion, the Processor shall provide written confirmation of deletion upon the Controller's request.

5.7.5. The Processor may retain Personal Data to the extent required by EU or Member State law, in which case the Processor shall inform the Controller of any such retention requirement and shall limit the processing to the extent necessary for that purpose, ensuring appropriate confidentiality.

5.8. Audit and Compliance Demonstration (Art. 28(3)(h))

5.8.1. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.

5.8.2. The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

5.8.3. Audit Procedures:

  • (a) The Controller may conduct an audit of the Processor's data processing activities once per calendar year, or more frequently if required by a Supervisory Authority or following a Data Breach.
  • (b) The Controller shall provide at least thirty (30) days prior written notice of any planned audit.
  • (c) Audits shall be conducted during normal business hours, in a manner that minimises disruption to the Processor's operations.
  • (d) Any auditor mandated by the Controller must execute a non-disclosure agreement (NDA) reasonably acceptable to the Processor.
  • (e) The Controller shall bear its own costs in connection with any audit, unless the audit reveals material non-compliance by the Processor.

5.8.4. As an alternative or supplement to on-site audits, the Processor may provide:

  • (a) summaries or copies of relevant audit reports, certifications, or assessments conducted by qualified third parties;
  • (b) evidence of compliance with industry-standard security frameworks.

6. SUB-PROCESSORS

6.1. The Controller acknowledges and agrees that the Processor may engage the Sub-processors listed in Annex 3 to perform specific processing activities.

6.2. The Processor shall maintain an up-to-date list of Sub-processors, which shall be made available to the Controller upon request and published on the Processor's website.

6.3. The notification and objection procedure for changes to Sub-processors is described in Section 5.4 of this DPA.

6.4. Where a Sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor's obligations (Art. 28(4)).


7. INTERNATIONAL DATA TRANSFERS

7.1. The Processor shall not transfer Personal Data to a country outside the EEA unless one of the following conditions is met:

  • (a) the European Commission has issued an adequacy decision for the recipient country (Art. 45 GDPR);
  • (b) appropriate safeguards are in place, such as Standard Contractual Clauses (Art. 46(2)(c) GDPR), as adopted by Commission Implementing Decision (EU) 2021/914;
  • (c) the transfer falls within a permitted derogation under Art. 49 GDPR.

7.2. The current international transfers are described in Annex 3. Where transfers are made to the United States, the Processor relies on:

  • (a) the EU-US Data Privacy Framework adequacy decision (adopted 10 July 2023), where the Sub-processor is certified under the framework; and/or
  • (b) Standard Contractual Clauses (Module 3: Processor to Sub-processor) as a supplementary or alternative safeguard.

7.3. The Processor shall conduct and document a Transfer Impact Assessment (TIA) for each transfer to a third country, evaluating:

  • (a) the laws and practices of the destination country regarding government access to data;
  • (b) the effectiveness of the safeguards in place;
  • (c) any supplementary measures necessary to ensure adequate protection.

7.4. If the Processor becomes aware that the legislation of a destination country prevents the Sub-processor from fulfilling its obligations under the SCCs, the Processor shall promptly notify the Controller and take reasonable steps to remedy the situation, including considering alternative Sub-processors located in the EEA.


8. DATA BREACH NOTIFICATION

8.1. The Processor shall notify the Controller of a Data Breach without undue delay and no later than forty-eight (48) hours after becoming aware of the breach (contractual obligation; cf. GDPR Art. 33(2) which requires processor notification "without undue delay"). This timeframe ensures the Controller has sufficient time to meet its own seventy-two (72) hour notification obligation to the Supervisory Authority under Art. 33(1) GDPR.

8.2. The notification shall include, at a minimum:

  • (a) a description of the nature of the Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • (b) the name and contact details of the Processor's point of contact from whom more information can be obtained;
  • (c) a description of the likely consequences of the Data Breach;
  • (d) a description of the measures taken or proposed to be taken by the Processor to address the Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

8.3. Where it is not possible to provide all information at the same time, the Processor shall provide the information in phases without further undue delay.

8.4. The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Data Breach.

8.5. The Processor shall assist the Controller in complying with its obligations under Articles 33 and 34 of the GDPR (notification to the Supervisory Authority and communication to Data Subjects).

8.6. The Processor shall document all Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken, in accordance with Art. 33(5) GDPR.

8.7. The Processor's notification of or response to a Data Breach under this Section shall not be construed as an acknowledgement by the Processor of any fault or liability with respect to the Data Breach.


9. DATA SUBJECT RIGHTS

9.1. The Processor shall assist the Controller in responding to requests from Data Subjects to exercise their rights under the GDPR, as specified in Section 5.5.

9.2. The Platform provides the following self-service tools to the Controller for handling Data Subject requests:

  • (a) Access and Portability: subscriber data export in CSV format;
  • (b) Rectification: subscriber data editing through the Platform interface;
  • (c) Erasure: subscriber deletion functionality;
  • (d) Restriction: subscriber status management (active/inactive);
  • (e) Objection to processing: unsubscribe mechanism in every email.

9.3. To the extent that the Controller is unable to independently address a Data Subject request through the Platform's tools, the Processor shall, upon the Controller's written request, provide reasonable assistance, at the Controller's expense.


10. DATA PROTECTION IMPACT ASSESSMENT

10.1. The Processor shall provide reasonable assistance to the Controller with any DPIA that the Controller is required to carry out under Art. 35 GDPR, taking into account the nature of the processing and the information available to the Processor.

10.2. The Processor shall provide reasonable assistance to the Controller in the context of any prior consultation with the Supervisory Authority under Art. 36 GDPR.


11. DATA RETENTION

11.1. The Processor shall process Personal Data only for the duration of the Service Agreement, unless otherwise instructed in writing by the Controller or required by Applicable Data Protection Law.

11.2. The Processor shall not retain Personal Data longer than is necessary for the purposes of the processing as set out in this DPA and Annex 1.

11.3. Specific retention periods are as follows:

Data CategoryRetention PeriodBasis
Subscriber data (email, name, tags)Duration of Service Agreement + 30 daysContract performance
Email engagement data (opens, clicks)Duration of Service Agreement + 30 daysContract performance
Consent recordsDuration of Service Agreement + 3 yearsLegal obligation (proof of consent)
Email send logs12 months after sendingLegitimate interest (deliverability)
Audit logs12 monthsSecurity and compliance
Backup copiesMaximum 30 days after primary deletionTechnical necessity

12. LIABILITY

12.1. Each Party's liability under this DPA shall be subject to the limitations and exclusions of liability set out in the Service Agreement, except that:

  • (a) the liability of either Party to Data Subjects under Art. 82 GDPR cannot be limited or excluded by this DPA;
  • (b) neither Party's liability for breaches of the Standard Contractual Clauses (where applicable) shall be limited by this DPA.

12.2. The Controller shall indemnify the Processor against any costs, claims, damages, or expenses incurred by the Processor arising from:

  • (a) the Controller's breach of Applicable Data Protection Law;
  • (b) the Controller's processing instructions that infringe the GDPR, where the Processor has informed the Controller of such infringement in accordance with Section 5.1.3;
  • (c) claims by Data Subjects arising from the Controller's failure to obtain or maintain valid consent.

12.3. The Processor shall indemnify the Controller against any costs, claims, damages, or expenses incurred by the Controller arising from:

  • (a) the Processor's breach of its obligations under this DPA;
  • (b) the Processor's processing of Personal Data outside or contrary to the Controller's lawful documented instructions, unless required by EU or Member State law.

13. GOVERNING LAW AND JURISDICTION

13.1. This DPA shall be governed by and construed in accordance with the laws of Romania, in compliance with Regulation (EU) 2016/679 (GDPR) and Legea nr. 190/2018.

13.2. Any disputes arising out of or in connection with this DPA shall be submitted to the exclusive jurisdiction of the competent courts of Bucharest, Romania.

13.3. The competent Supervisory Authority for the purposes of this DPA and any applicable Standard Contractual Clauses is the Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, cod postal 010336, Bucharest, Romania.


14. TERM AND TERMINATION

14.1. This DPA shall enter into force on the effective date of the Service Agreement (or on the date of first processing of Personal Data, whichever is earlier) and shall remain in effect for the duration of the Service Agreement.

14.2. Sections 5.7 (Data Deletion and Return), 5.8 (Audit), 8 (Data Breach Notification), 11 (Data Retention), 12 (Liability), and 13 (Governing Law) shall survive termination or expiry of this DPA.

14.3. Either Party may terminate this DPA immediately by written notice if the other Party materially breaches this DPA and fails to remedy such breach within thirty (30) days of receiving written notice of the breach.


15. MISCELLANEOUS

15.1. Written Form. This DPA is in written form in compliance with GDPR Art. 28(9). Amendments to this DPA shall be made in writing and signed by both Parties (electronic signatures are accepted).

15.2. Severability. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that most closely reflects the original intent.

15.3. Entire Agreement. This DPA, together with its Annexes, constitutes the entire agreement between the Parties regarding the processing of Personal Data under the Service Agreement and supersedes all prior agreements, understandings, and negotiations related thereto.

15.4. Updates. The Processor may update this DPA from time to time to reflect changes in Applicable Data Protection Law, provided that such updates do not materially diminish the level of data protection. The Controller will be notified of material changes at least thirty (30) days in advance.


ANNEX 1: DETAILS OF PROCESSING

A. List of Parties

Data Exporter (Controller):

  • Name: [CLIENT_NAME]
  • Address: [CLIENT_ADDRESS]
  • Contact person: [CLIENT_CONTACT]
  • Activities relevant to the transfer: Email marketing and subscriber management through the Platform
  • Role: Controller (GDPR Art. 4(7))

Data Importer (Processor):

  • Name: Devi Devs Technologies S.R.L.
  • Address: Aleea Textiliștilor 7, Bl. MY12, Sc. 2, Et. 8, Ap. 63, Sector 3, București
  • Contact person: privacy@devidevs-agency.com
  • Activities relevant to the transfer: Provision of email marketing SaaS platform, including subscriber data storage, email campaign management, email sending, and engagement analytics
  • Role: Processor (GDPR Art. 4(8))

B. Description of Processing

ElementDescription
Subject-matterProvision of ClevMail, a SaaS email marketing and automation service
DurationThe term of the Service Agreement between Controller and Processor
Nature of processingStorage, organisation, structuring, retrieval, use, disclosure by transmission (email sending), and erasure of Personal Data
Purpose of processing(1) Storage and management of Controller's subscriber lists; (2) Sending email campaigns and automated email sequences on behalf of Controller; (3) Tracking email engagement metrics (delivery, opens, clicks, bounces); (4) Providing analytics and reporting to Controller; (5) Managing subscriber consent and preferences (subscribe/unsubscribe)
Categories of Data Subjects(1) Controller's newsletter subscribers; (2) Controller's customers and prospects who have opted into email communications; (3) Controller's contacts imported into the Platform
Categories of Personal Data(1) Email address; (2) Name (first and/or last); (3) Subscriber tags and segments; (4) Consent timestamp and method; (5) Email engagement data (delivery status, open timestamps, click timestamps, bounce information); (6) Subscription status and preferences; (7) IP address (at time of subscription, if collected by Controller)
Special categories of data (Art. 9)Not applicable. The Processor does not intentionally process special categories of data. The Controller shall not upload special category data to the Platform without prior written agreement.
Frequency of transferContinuous, during the term of the Service Agreement
Retention periodAs specified in Section 11 of this DPA

C. Competent Supervisory Authority

Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP), Romania.


ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES

The Processor implements the following technical and organisational measures pursuant to GDPR Art. 32:

1. Encryption

MeasureImplementation
Encryption in transitAll data transmitted between the Platform components and to/from end users is encrypted using TLS 1.2 or higher
Encryption at restDatabase (Supabase PostgreSQL) uses AES-256 encryption at rest. Backups are encrypted.
Sending credentialsThe Platform sends through a single provider (Resend); the provider's API key is kept in the server's environment variables, not in the database. Clients do not entrust the Platform with sending credentials of their own; their sender identity is established through domain verification (SPF, DKIM, DMARC).
Secret managementCritical secrets (CRON_SECRET) stored in Supabase Vault (encrypted at rest). API keys and credentials stored in environment variables, not in source code.

2. Access Control

MeasureImplementation
AuthenticationJWT-based authentication via Supabase Auth for all API requests
Multi-tenancy isolationRow Level Security (RLS) enforced at database level. All application queries additionally filtered by client_id for defense in depth.
Principle of least privilegeEach client can only access their own data. API endpoints enforce client_id scoping on every query.
Administrative accessLimited to authorised personnel with role-based access
Password policyEnforced through Supabase Auth (minimum complexity, no plaintext storage)

3. Availability and Resilience

MeasureImplementation
Database hostingSupabase PostgreSQL hosted in EU (eu-central-1, Frankfurt) with automated backups
Application hostingBackend on Render (Frankfurt region), frontend on Vercel (global CDN)
Health monitoringAutomated health checks every 10 minutes (pg_cron keep-alive), external monitoring via UptimeRobot
Disaster recoveryDatabase point-in-time recovery. Application stateless, redeployable from source control.

4. Data Backup and Recovery

MeasureImplementation
Automated backupsDaily automated database backups by Supabase
Backup retentionIn accordance with Supabase plan (minimum 7 days)
Recovery testingPeriodic verification of backup restoration capability

5. Logging and Monitoring

MeasureImplementation
Audit trailDatabase audit_log table records significant operations (create, update, delete on subscriber and campaign data)
Application logsStructured logging via Render, retained per provider policy
Error monitoringAutomated error tracking and alerting
Email engagementPer-email delivery tracking (sent, delivered, opened, clicked, bounced) for compliance and deliverability

6. Breach Detection and Incident Response

MeasureImplementation
Bounce and complaint monitoringAutomated monitoring of bounce rate (threshold: <5%) and complaint rate (threshold: <0.1%) via the email provider's signed webhooks (Resend)
Anomaly detectionMonitoring of unusual sending patterns and access patterns
Incident response planDocumented procedure for identifying, containing, assessing, and notifying about Data Breaches

7. Personnel Measures

MeasureImplementation
ConfidentialityAll personnel with access to Personal Data are bound by confidentiality obligations
TrainingPersonnel handling Personal Data receive data protection awareness training
Access reviewPeriodic review of personnel access rights

8. Vendor Security

MeasureImplementation
Sub-processor assessmentSub-processors are assessed for their security practices before engagement
Contractual safeguardsAll Sub-processors are bound by data processing agreements with equivalent security obligations
Ongoing monitoringRegular review of Sub-processor security posture and compliance

ANNEX 3: LIST OF SUB-PROCESSORS

The following Sub-processors are authorised to process Personal Data on behalf of the Controller:

Sub-processorLegal EntityPurposeData ProcessedLocationTransfer Mechanism
Supabase Inc.Supabase, Inc. (Delaware, USA; HQ Singapore)Database hosting (PostgreSQL)All subscriber data, campaign data, engagement data, consent recordsEU (Frankfurt, eu-central-1)N/A (data stored and processed in EU)
ResendPlus Five Five, Inc. (San Francisco, USA)Email delivery serviceEmail addresses, email content, delivery/bounce/complaint metadataUSA (sending from the EU region; data stored in the USA)EU-US Data Privacy Framework + SCCs (Resend DPA)
Render Inc.Render Services, Inc. (USA)Backend API hostingAll data processed by the API (transient processing)EU (Frankfurt)N/A (data processed in EU)
Vercel Inc.Vercel, Inc. (USA)Frontend hosting (Next.js)Session tokens, client-side state (no subscriber PII stored server-side on Vercel)USA (Edge: global)EU-US Data Privacy Framework + SCCs
Anthropic PBCAnthropic, PBC (USA)AI content generation (Claude)Newsletter topics, writing instructions (no subscriber PII sent to AI)USASCCs
Google LLCGoogle LLC (USA)AI content generation (Gemini)Newsletter topics, writing instructions (no subscriber PII sent to AI)USAEU-US Data Privacy Framework + SCCs (Google DPA)
Resend Inc.Plus Five Five, Inc. d/b/a Resend (USA)Email delivery service (optional, per client configuration)Email addresses, email contentUSASCCs

Notes:

  1. Subscriber Personal Data (email addresses, names) is stored in the EU (Supabase Frankfurt). The primary database never leaves the EU.
  2. AI services (Anthropic, Google) receive only newsletter content generation prompts and topic data. No subscriber PII is transmitted to AI services.
  3. Vercel hosts the frontend application; subscriber PII is fetched client-side via API calls to the backend (Render, EU) and is not stored on Vercel servers.
  4. The Processor will notify the Controller at least 30 days before adding or replacing a Sub-processor, as described in Section 5.4.

ANNEX 4: STANDARD CONTRACTUAL CLAUSES

Where transfers of Personal Data to third countries are made as described in this DPA and Annex 3, the Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 shall apply:

  • Module 2 (Controller to Processor): for transfers from the Controller (EEA) to Sub-processors located outside the EEA
  • Module 3 (Processor to Sub-processor): for transfers from the Processor (DeviDevs) to Sub-processors located outside the EEA

The SCCs are incorporated by reference and are available at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj

The following selections apply to the SCCs:

ClauseSelection
Clause 7 (Docking clause)Included
Clause 9 (Sub-processors)Option 2: General written authorisation (with 30-day notification period)
Clause 11 (Redress)Optional provision NOT included
Clause 13 (Supervision)Competent supervisory authority: ANSPDCP (Romania)
Clause 17 (Governing law)Romanian law
Clause 18 (Forum and jurisdiction)Courts of Bucharest, Romania

This Data Processing Agreement is effective as of the date of the Service Agreement and remains in force for the duration of the processing of Personal Data by the Processor.

For the Controller:

Name: ___________________________ Title: ___________________________ Date: ___________________________ Signature: ___________________________

For the Processor (Devi Devs Technologies S.R.L.):

Name: ___________________________ Title: ___________________________ Date: ___________________________ Signature: ___________________________


Document ID: DPA-v1.0.0 Classification: Legal — Confidential This document does NOT constitute legal advice and should be reviewed by a qualified legal professional before execution.