hellosendly
FeaturesPricingHow It WorksSign In

Data Processing Agreement

Last updated: March 29, 2026

1. Definitions

"Controller" means you, the customer, who determines the purposes and means of processing personal data.

"Processor" means Sendly Technologies, which processes personal data on behalf of the Controller.

"Personal Data" means any data relating to an identified or identifiable natural person.

2. Scope of Processing

Sendly processes personal data solely for the purpose of providing the email marketing service, including:

  • Sending emails, WhatsApp messages, and SMS on your behalf
  • Managing your contact lists and segments
  • Tracking email delivery, opens, clicks, and bounces
  • Executing read-only queries against your connected database

3. Data Categories

CategoryExamplesPurpose
Contact identifiersEmail addresses, names, phone numbersEmail delivery, personalization
Custom fieldsCity, order history, preferencesSegmentation, personalization
Engagement dataOpens, clicks, bouncesAnalytics, automation triggers
Account dataAdmin email, business nameAuthentication, billing

4. Sub-Processors

Sendly uses the following sub-processors:

Sub-ProcessorPurposeLocation
Resend Inc.Email deliveryUnited States
Microsoft AzureCloud hosting, databaseSouth Africa (Cape Town region)
Paystack (Stripe)Payment processingNigeria
TermiiSMS deliveryNigeria

We will notify you at least 30 days before adding a new sub-processor.

5. Security Measures

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • Role-based access control for Sendly staff
  • SSL-encrypted database connections
  • IP whitelisting for database access
  • Regular security audits and penetration testing

6. Data Breach Notification

In the event of a personal data breach, Sendly will notify the Controller within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, data affected, likely consequences, and measures taken.

7. Compliance

This DPA is designed to comply with:

  • Nigerian Data Protection Regulation (NDPR)
  • Ghana Data Protection Act, 2012 (Act 843)
  • South Africa Protection of Personal Information Act (POPIA)
  • Kenya Data Protection Act, 2019

8. Data Deletion

Upon termination of the Service, Sendly will delete all personal data within 30 days unless retention is required by law. You may request immediate deletion by contacting legal@hellosendly.com.

9. Audit Rights

The Controller may audit Sendly's compliance with this DPA once per year, with 30 days' written notice. Audits shall be conducted during normal business hours and shall not unreasonably interfere with Sendly's operations.

10. Contact

Data Protection Officer: legal@hellosendly.com
Sendly Technologies, 6 Ilupeju Road, Oluyole Sharp Corner, Ibadan, Nigeria

hellosendly

Email marketing built for African businesses.

Product

FeaturesPricingHow It WorksDocumentation

Company

BlogContactCareers

Legal

Privacy PolicyTerms of ServiceData Processing
© 2026 Sendly. All rights reserved.
𝕏in