Data Processing Agreement

Effective Date: August 1, 2026

1. Introduction

This Data Processing Agreement ("DPA") supplements our Terms of Service and Privacy Policy. It applies when Qwik Mailer ("Data Processor") processes personal data subject to the General Data Protection Regulation (GDPR) or similar data protection laws on your behalf.

2. Roles of the Parties

In relation to personal data processed through our Service, you act as the Data Controller (or Processor on behalf of another Controller), and Qwik Mailer acts strictly as the Data Processor. We will only process Personal Data based on your documented instructions.

3. Processing of Personal Data

Qwik Mailer processes personal data strictly to provide our email automation and delivery service. The scope includes:

  • Recipient Details: Email addresses and names provided via API or SMTP for the purpose of transmission.
  • Template Variables: Dynamic variables injected into emails or PDFs (e.g., scores, certificates, custom identifiers).
  • Engagement Data: IP addresses and User-Agent strings collected via tracking pixels when recipients open or click emails to provide analytical reports.

4. Technical & Organizational Security Measures

We implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk. This includes:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Strict access controls, multi-factor authentication (MFA) for administrative access, and regular security audits.
  • Logical isolation of tenant data within our databases.

5. Sub-processors

You authorize Qwik Mailer to engage third-party sub-processors to fulfill our service. Our primary sub-processor is Amazon Web Services (AWS), which we use for:

  • Email Delivery (AWS SES)
  • Bounce & Complaint Tracking (AWS SNS)
  • Core Cloud Infrastructure (Hosting & Database management)

We remain fully liable for our sub-processors' compliance with this DPA and ensure they are bound by equivalent data protection obligations, including Standard Contractual Clauses (SCCs) for cross-border data transfers where applicable.

6. Breach Notification

In the event of a confirmed Personal Data Breach affecting your data, Qwik Mailer will notify you without undue delay and, where feasible, no later than 72 hours after having become aware of it. We will provide reasonable assistance to help you meet your regulatory notification obligations.

7. Data Subject Rights & Deletion

We will provide reasonable assistance to help you fulfill your obligations to respond to requests from data subjects exercising their rights under GDPR/CCPA.

Data Retention: Hard bounces and spam complaints are stored permanently in a suppression list to comply with federal anti-spam regulations. Upon termination of your account, we will delete or anonymize all other personal data (including recipient lists and campaign history) within 30 days, unless required otherwise by law.