Template · Updated August 27, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in the Sendly account ("Controller") and Sendly Technologies ("Processor") for the Sendly service. It applies whenever Sendly processes personal data on the Controller's behalf.
| Controller | The business named in the Sendly account, represented by the account owner. |
|---|---|
| Processor | Sendly Technologies, 6 Ilupeju Road, Oluyole Sharp Corner, Ibadan, Nigeria — [email protected] |
Subject matter: personal data of the Controller's customers and prospects held in the Controller's database and contact lists. Duration: the term of the Sendly subscription plus the deletion period in section 9. Nature: read-only querying of the Controller's database, storage of contact identifiers for campaigns, sending of email on the Controller's behalf, recording of delivery events. Purpose: email marketing — segmentation, personalisation, automated flows and campaign reporting, as instructed by the Controller through the service.
| Data subjects | Categories | Source |
|---|---|---|
| Controller's customers and prospects | Email address, name, phone, location (city/country/region), signup and activity dates, purchase/transaction summaries (counts, amounts, dates), subscription status, engagement with emails (sent, opened, clicked, bounced, unsubscribed) | Controller's database (read-only), Controller's uploads, Sendly delivery events |
| Controller's staff | Login email, name, role | Account registration |
The Controller instructs the Processor not to process special-category data. Columns that appear to hold credentials, payment-card data or national identifiers are excluded from processing by design.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Cloud hosting of the Sendly application and its database | EU / US regions (see account settings for the region serving you) |
| Resend, Inc. | Email delivery and delivery events | United States |
| DeepSeek | Optional AI mapping of database structure to marketing attributes. Receives table and column names, data types and masked sample values only — never customer identifiers. | See provider terms |
| Paystack | Subscription billing for the Sendly account (Controller's own billing details only) | Nigeria |
The Processor gives at least 30 days' notice before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds and terminate if the objection cannot be resolved.
The Processor notifies the Controller without undue delay and within 72 hours of becoming aware of a personal data breach affecting the Controller's data, describing the nature of the breach, the data concerned, likely consequences and the measures taken.
Once per year, on 30 days' written notice, the Controller (or an independent auditor bound by confidentiality) may audit the Processor's compliance with this DPA during business hours without unreasonably disrupting operations. The Processor will first offer available documentation and reports.
On termination the Processor deletes the stored database connection immediately and all personal data within 30 days, unless retention is required by law. On request before then the Processor exports the Controller's contacts and campaign data in a machine-readable format.
Where personal data is transferred outside the data subject's country, the Processor relies on the safeguards required by the applicable law (NDPR/NDPA, POPIA, Ghana DPA, Kenya DPA, GDPR Standard Contractual Clauses as applicable). This DPA is governed by the laws of the Federal Republic of Nigeria unless the main agreement provides otherwise.
Data Protection Officer: [email protected] · Security: [email protected] · See also Security.