This Data Processing Addendum ("DPA") forms part of the Terms of Servicebetween TokiSpace Inc ("Sendara", "Processor") and the customer agreeing to the Terms ("Customer", "Controller"). It applies where Sendara processes Personal Data on behalf of Customer in providing the Service. In case of conflict between this DPA and the Terms on a data-protection matter, this DPA controls.
1. Definitions
"Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). "Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in the Data Protection Laws. "Customer Personal Data" means Personal Data within Customer Content that Sendara processes on Customer's behalf (principally recipient email addresses, contact attributes, message content, and related send and event logs).
2. Roles and scope of processing
For Customer Personal Data, Customer is the Controller (or a processor acting for its own controller) and Sendara is the Processor. Sendara will process Customer Personal Data only to provide and support the Service and on Customer's documented instructions, which include the Terms, this DPA, and Customer's use of the Service's features. The subject-matter, duration, nature, and purpose of processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A.
3. Sendara's obligations
- process Customer Personal Data only on documented instructions, and notify Customer if an instruction infringes Data Protection Laws;
- ensure personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
- implement and maintain the technical and organizational measures in Annex B;
- assist Customer, taking into account the nature of processing, in responding to Data Subject requests and in meeting Customer's obligations regarding security, breach notification, and data-protection impact assessments; and
- make available information reasonably necessary to demonstrate compliance with this DPA.
4. Customer's obligations
Customer is responsible for the lawfulness of the Customer Personal Data and of its sending, including obtaining and maintaining all consents and providing all notices required to process recipient Personal Data and to send email to its recipients. Customer's instructions must comply with Data Protection Laws.
5. Subprocessors
Customer provides general authorization for Sendara to engage subprocessors to process Customer Personal Data. Sendara imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA and remains responsible for its subprocessors' performance. Sendara's current subprocessors are:
- Amazon Web Services, Inc. (AWS): email delivery (Amazon SES) and core infrastructure (Aurora/RDS, ElastiCache, S3, App Runner, Lambda), United States,
us-east-1. - AWS Bedrock:AI features, United States. Sendara Mail AI is engaged only where Customer enables it. The support assistant is engaged whenever Customer opens the support chat. It receives the messages Customer types into that chat as written, with no filtering applied by Sendara. From Customer's account records it receives message metadata (including the subject line, with email addresses removed) and masked recipient addresses; a message lookup returns no recipient address. It does not receive message bodies or attachments. Support conversations are stored by Sendara and are readable by authorized Sendara personnel, whose access is logged.
- Polar Software Inc. (Polar): billing and checkout as merchant of record.
- Cloudflare, Inc.: hosting and DNS.
Sendara will give Customer prior notice of any intended addition or replacement of a subprocessor (the "subprocessor change notice") with a reasonable opportunity to object on legitimate data-protection grounds before the new subprocessor begins processing. Notice will be given by email to account administrators and/or this page at least 30 days in advance. If Customer reasonably objects and the parties cannot resolve the objection, Customer may terminate the affected portion of the Service.
6. International transfers
Where Sendara transfers Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (SCCs) (Module Two: Controller-to-Processor, or Module Three where Customer is itself a processor) are incorporated into this DPA by reference and apply to that transfer, supplemented by the UK International Data Transfer Addendum for UK transfers and equivalent mechanisms for Swiss transfers. The optional docking clause applies, the supervisory authority and governing law are determined as set out in Annex A, and Annex A and Annex B serve as the corresponding annexes to the SCCs.
7. Security measures
Sendara maintains the technical and organizational security measures described in Annex B, designed to ensure a level of security appropriate to the risk of processing Customer Personal Data.
8. Personal Data Breach notification
Sendara will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Sendara will cooperate with Customer and take reasonable steps to mitigate and remediate.
9. Data Subject requests
Taking into account the nature of the processing, Sendara will provide reasonable assistance to enable Customer to respond to requests from Data Subjects to exercise their rights. If Sendara receives such a request directly, it will, unless legally prohibited, promptly inform the Data Subject to contact Customer and notify Customer of the request.
10. Audits
Sendara will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, on reasonable prior notice, no more than once per year (unless required by a supervisory authority or following a breach), and subject to confidentiality and to not unreasonably disrupting Sendara's operations. Sendara may satisfy this obligation by providing third-party certifications or audit reports where available.
11. Return and deletion
On termination or expiry of the Service, and at Customer's choice, Sendara will delete or return Customer Personal Data and delete existing copies, except where retention is required by applicable law. Backups are deleted on a rolling cycle in the ordinary course.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
Annex A: Details of processing
- Data exporter / Controller: Customer (as identified in its account).
- Data importer / Processor: TokiSpace Inc, Mile 11, Bort Street 25, Accra, Ghana.
- Subject-matter: provision of the Sendara email-sending Service.
- Duration: the term of the Service plus any retention period required by law.
- Nature and purpose: hosting, transmitting, and logging email and contact data to deliver email and provide event tracking, inbound handling, and analytics.
- Categories of Data Subjects:Customer's email recipients and contacts.
- Types of Personal Data: email addresses, names and contact attributes provided by Customer, message content, and send/event metadata. Customer must not send special-category data through the Service except as expressly agreed.
- Frequency: continuous, for the duration of the Service.
- Competent supervisory authority:determined under Clause 13 of the SCCs by reference to Customer's position as data exporter. Where Customer is established in an EEA Member State, the competent supervisory authority is the supervisory authority of that Member State.
- Governing law of the SCCs: Clause 17 of the SCCs requires the law of an EU Member State. The parties agree that law with Customer before Customer relies on the SCCs for a transfer. Contact [email protected] to agree it. This DPA is otherwise governed by the law stated in the Governing law and disputes section of the Terms of Service.
Annex B: Technical and organizational measures
- encryption of Personal Data at rest, and TLS on public network connections;
- hashing of account passwords and scoped, revocable API keys for authentication;
- access controls on the principle of least privilege, with authentication for administrative access;
- network segmentation and security controls on the underlying cloud infrastructure;
- logging, monitoring, and alerting for security-relevant events;
- regular backups and a documented incident-response and breach-handling process;
- confidentiality obligations and security awareness for personnel with access to Personal Data; and
- subprocessor due diligence and contractual data-protection commitments.
Contact
For questions about this DPA or to make data-protection requests, contact [email protected] or [email protected].