hellosendly
FeaturesPricingHow It WorksSign In

Data Processing Agreement

Template · Updated August 27, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in the Sendly account ("Controller") and Sendly Technologies ("Processor") for the Sendly service. It applies whenever Sendly processes personal data on the Controller's behalf.

1. Parties

ControllerThe business named in the Sendly account, represented by the account owner.
ProcessorSendly Technologies, 6 Ilupeju Road, Oluyole Sharp Corner, Ibadan, Nigeria — [email protected]

2. Subject matter, duration, nature and purpose

Subject matter: personal data of the Controller's customers and prospects held in the Controller's database and contact lists. Duration: the term of the Sendly subscription plus the deletion period in section 9. Nature: read-only querying of the Controller's database, storage of contact identifiers for campaigns, sending of email on the Controller's behalf, recording of delivery events. Purpose: email marketing — segmentation, personalisation, automated flows and campaign reporting, as instructed by the Controller through the service.

3. Categories of data and data subjects

Data subjectsCategoriesSource
Controller's customers and prospectsEmail address, name, phone, location (city/country/region), signup and activity dates, purchase/transaction summaries (counts, amounts, dates), subscription status, engagement with emails (sent, opened, clicked, bounced, unsubscribed)Controller's database (read-only), Controller's uploads, Sendly delivery events
Controller's staffLogin email, name, roleAccount registration

The Controller instructs the Processor not to process special-category data. Columns that appear to hold credentials, payment-card data or national identifiers are excluded from processing by design.

4. Processor obligations

  • Process personal data only on the Controller's documented instructions, which are given through the service (connections, segments, campaigns, flows).
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement the security measures in section 6.
  • Assist the Controller with data-subject requests (access, rectification, erasure, objection to marketing) — unsubscribe and suppression are honoured automatically and immediately.
  • Make available the information necessary to demonstrate compliance and allow audits (section 8).
  • Delete or return personal data at the end of the service (section 9).

5. Sub-processors

Sub-processorPurposeLocation
DigitalOcean, LLCCloud hosting of the Sendly application and its databaseEU / US regions (see account settings for the region serving you)
Resend, Inc.Email delivery and delivery eventsUnited States
DeepSeekOptional AI mapping of database structure to marketing attributes. Receives table and column names, data types and masked sample values only — never customer identifiers.See provider terms
PaystackSubscription billing for the Sendly account (Controller's own billing details only)Nigeria

The Processor gives at least 30 days' notice before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds and terminate if the objection cannot be resolved.

6. Security measures

  • Read-only database access enforced twice: SELECT-only database user and a statement parser that refuses anything else.
  • Database credentials and provider keys encrypted at rest with AES-256-GCM; TLS in transit.
  • Single static egress IP for all database connections; private and cloud-metadata addresses refused.
  • Per-query execution timeouts on every connection to the Controller's database.
  • Tenant isolation enforced at the data layer and covered by an automated regression suite.
  • Role-based access for Sendly staff; platform administration requires an explicit operator-granted flag.
  • Password hashing with bcrypt; sessions bound to HttpOnly, SameSite cookies; rate limiting on authentication and public endpoints.

7. Personal data breach

The Processor notifies the Controller without undue delay and within 72 hours of becoming aware of a personal data breach affecting the Controller's data, describing the nature of the breach, the data concerned, likely consequences and the measures taken.

8. Audit

Once per year, on 30 days' written notice, the Controller (or an independent auditor bound by confidentiality) may audit the Processor's compliance with this DPA during business hours without unreasonably disrupting operations. The Processor will first offer available documentation and reports.

9. Deletion and return

On termination the Processor deletes the stored database connection immediately and all personal data within 30 days, unless retention is required by law. On request before then the Processor exports the Controller's contacts and campaign data in a machine-readable format.

10. International transfers and law

Where personal data is transferred outside the data subject's country, the Processor relies on the safeguards required by the applicable law (NDPR/NDPA, POPIA, Ghana DPA, Kenya DPA, GDPR Standard Contractual Clauses as applicable). This DPA is governed by the laws of the Federal Republic of Nigeria unless the main agreement provides otherwise.

11. Contact

Data Protection Officer: [email protected] · Security: [email protected] · See also Security.

hellosendly

Email marketing built for African businesses.

Product

FeaturesPricingHow It WorksDocumentation

Company

BlogContactCareers

Legal

Privacy PolicyTerms of ServiceData Processing
© 2026 Sendly. All rights reserved.
𝕏in