Legal
Data Processing Agreement
Last updated · July 2026
01Parties
This data processing agreement (the "Agreement") is entered into between:
- the legal entity that has accepted Sendnord's Terms of Service (the "Main Agreement"), hereinafter the "Controller"; and
- Sitepulse Marketing AB, reg. no. 559332-8510, hereinafter the "Processor".
The Controller and the Processor are referred to individually as a "Party" and jointly as the "Parties".
The Agreement is concluded by the Controller accepting the Main Agreement, of which the Agreement forms an integral part. No separate signature is required; on request, the Processor provides the Agreement in signed form.
02Background and purpose
The Processor provides the service Sendnord, a platform for email marketing and transactional messages with AI-assisted features (the "Service"). Through the Service, the Processor will process personal data on behalf of the Controller.
Applicable Data Protection Law requires a written agreement governing the Processor's processing of personal data on behalf of the Controller. This Agreement constitutes such an agreement under Article 28(3) of the GDPR.
In the event of conflict between the Agreement and the Main Agreement in matters concerning the processing of personal data, the Agreement prevails.
Customer Data remains the property of the Controller. The Controller grants the Processor a non-exclusive right to process Customer Data only to the extent necessary to provide the Service.
03Definitions
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council. "Data Protection Law" means the GDPR together with supplementary Swedish data protection legislation and regulations and guidance issued by the Swedish Authority for Privacy Protection (IMY).
The terms "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Article 4 of the GDPR.
"Customer Data" means the personal data that the Processor processes on behalf of the Controller within the Service, as further described in Annex 1.
"Sub-processor" means another processor engaged by the Processor for the processing of Customer Data.
04Processing and instructions
The Processor, and persons performing work under its direction, may process Customer Data only in accordance with the Controller's documented instructions, unless processing is required under Union or Swedish law; in that case, the Processor shall inform the Controller of the legal requirement before processing, unless such information is prohibited by law.
The Main Agreement, this Agreement, and the Controller's configuration and use of the Service: including the choice of tracking mode, enabled features and use of the API: constitute the Controller's complete documented instructions.
The Processor provides only the tools for the collection and processing of personal data. It is the Controller's responsibility to ensure that processing rests on a lawful basis, that any necessary consents are obtained from data subjects, and that data subjects receive information in accordance with Articles 12-14 of the GDPR. On request, the Processor shall without delay provide the records held in the Service: such as consent and signup logs - that the Controller needs in order to demonstrate that data subjects have been informed and that the processing meets its accountability obligations.
The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction infringes Data Protection Law.
The subject matter, duration, nature and purposes of the processing, the categories of data subjects and the categories of personal data are set out in Annex 1. Special categories of personal data may not be processed in the Service without separate written agreement, and never in AI features.
05Prohibition on use for own purposes and AI training
The Processor may not use Customer Data for its own purposes.
The Processor may not use Customer Data to train, fine-tune or otherwise improve AI or machine-learning models, and shall ensure that its AI model providers are contractually prohibited from doing the same. Account-specific optimization features process only the Controller's own Customer Data within the Service and are not shared between customers. Aggregated, anonymized statistics that can identify neither a data subject nor the Controller do not constitute Customer Data.
06Confidentiality
The Processor shall ensure that persons authorized to process Customer Data have committed themselves to confidentiality or are subject to a statutory obligation of confidentiality, and that access is limited to what is necessary for each role.
The Processor undertakes not to disclose Customer Data, or other information about the processing obtained as a result of the Agreement, to any third party, except for (a) information that a Party can show was publicly known at the time of receipt, and (b) information that a Party is required to disclose by law or by decision of a public authority, in which case the Controller shall, where legally permitted, be informed before disclosure.
The confidentiality undertakings remain in force after the Agreement has otherwise ceased to apply.
07Security measures
The Processor shall implement the technical and organizational measures required under Article 32 of the GDPR to protect Customer Data against unauthorized access, loss, destruction and alteration. The measures implemented are set out in Annex 2.
The Processor may update the measures in Annex 2 provided that the overall level of protection is not reduced.
08Engagement of Sub-processors
The Controller hereby grants the Processor general prior authorization to engage Sub-processors. The Sub-processors engaged at any given time, including purpose and location of processing, are set out in the Processor's sub-processor register at /subprocessors (the "Register"), which constitutes Annex 3.
The Processor shall notify the Controller of any intention to add or replace a Sub-processor at least fourteen (14) days in advance, by updating the Register and by email to the account owner. The Controller may raise a substantiated objection within the notice period; if the Parties cannot reach agreement, the Controller may terminate the part of the Service affected.
The Processor shall, by written agreement, impose on each Sub-processor data protection obligations materially equivalent to the Processor's obligations under this Agreement, including confidentiality, and remains fully liable to the Controller for the Sub-processor's performance.
Transfers of Customer Data to a third country may take place only subject to appropriate safeguards under Chapter V of the GDPR, such as an adequacy decision or the European Commission's standard contractual clauses under Implementing Decision (EU) 2021/914, which are incorporated by reference where required. Any such transfers are identified in the Register.
09Data subjects' rights and assistance
Taking into account the nature of the processing, the Processor shall, by appropriate technical and organizational measures, assist the Controller in fulfilling its obligations under Chapter III of the GDPR. Assistance is provided primarily through the Service's self-serve functions for searching, exporting, rectifying and deleting individual data subjects' data, and otherwise without undue delay.
If a data subject, a supervisory authority or any other third party contacts the Processor concerning the processing of Customer Data, the Processor shall refer them to the Controller. The Processor may not disclose Customer Data or information about the processing without the Controller's prior instruction, unless disclosure is required by law; in that case, the Controller shall be informed before disclosure, where legally permitted. Requests received by the Processor directly from a data subject are forwarded to the Controller without undue delay and without being answered on the merits.
10Personal data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach concerning Customer Data. To the extent the information is available, the notification shall contain the information set out in Article 33(3) of the GDPR: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed: and shall be supplemented as further information becomes available.
The Processor does not notify supervisory authorities or data subjects on the Controller's behalf, unless instructed in writing or required by law. The Parties acknowledge that the Controller is responsible for its own notification obligations, including the 72-hour deadline under Article 33.
11Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to the Processor, the Processor shall assist the Controller in fulfilling the obligations under Articles 32-36 of the GDPR, including data protection impact assessments and prior consultation with the supervisory authority. The Processor maintains its own risk assessment of the Service's processing, which is provided to the Controller on request.
12Deletion and return
During the term of the Agreement, the Controller may at any time export and delete Customer Data through the Service.
Upon termination of the Main Agreement, the Controller may export Customer Data for thirty (30) days. No later than thirty (30) days after termination of the Main Agreement, the Processor shall have deleted all Customer Data, including instructing Sub-processors to do the same, unless continued storage is required under Union or Swedish law or otherwise agreed in writing between the Parties. Written confirmation of deletion is provided on request.
Backups are encrypted and rotate out within thirty-five (35) days. Deleted Customer Data is not restored to the production environment; if a restore from backup takes place, the deletion is re-applied.
A minimal hashed suppression record may be retained after deletion of a data subject, solely so that the data subject's opt-out remains effective; the record cannot be used to reconstruct the personal data.
13Audits
The Processor shall make available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Controller or by an auditor mandated by the Controller.
Audits may take place no more than once per twelve-month period : except following a personal data breach or at the request of a supervisory authority: on thirty (30) days' notice, during business hours, subject to confidentiality, and without jeopardizing the security or confidentiality of other customers' data. The Controller bears its own audit costs. Audit requests may in the first instance be satisfied by the provision of relevant third-party audit reports or certifications, where available.
14Location of processing
Customer Data is stored and processed within the EU/EEA in accordance with Annex 3. Any transfer to a third country is subject to the safeguards set out under "Engagement of Sub-processors".
15Remuneration
The Processor is not entitled to separate remuneration for the performance of its obligations under the Agreement. Assistance with data subjects' rights and with impact assessments and prior consultation through the Service's self-serve functions is included in the fees for the Service; for extraordinary manual assistance, the Processor may charge reasonable costs.
16Liability
The Controller shall without undue delay notify the Processor of any claim by a data subject or other third party based on the Processor's processing of Customer Data.
The Processor's aggregate liability under this Agreement is limited to fifty per cent (50%) of the fees paid by the Controller for the Service during the twelve (12) months preceding the event giving rise to the claim, and is otherwise subject to the limitations of liability set out in the Main Agreement, to the extent not otherwise prescribed by mandatory law.
17Force majeure
Grounds for relief are governed by the Main Agreement and apply equally to the Parties' undertakings under this Agreement.
18Term
The Agreement applies for as long as the Processor processes Customer Data under the Main Agreement, and thereafter until deletion under "Deletion and return" has been completed.
19Governing law and dispute resolution
The Agreement, and all processing of personal data under the Agreement, is governed by Swedish law, excluding its conflict-of-law rules. Disputes arising out of the Agreement shall be resolved in accordance with the dispute resolution provisions of the Main Agreement.
Annex 1: Description of the processing
Subject matter: Provision of a platform for email marketing and transactional messages (together with additional channels, such as SMS and RCS, if and when activated by the Controller).
Duration: The term of the Main Agreement plus the deletion period under "Deletion and return".
Nature and purposes: Storage and operation; list and consent management; composition and dispatch of marketing and transactional messages; handling of deliveries, bounces and complaints; suppression management; measurement of engagement (opens and clicks), including derivation of coarse geographic location (city/country level) from IP addresses; analytics and reporting; AI-assisted content generation, send-time optimization and campaign insights; customer support.
Collection channels: Signup forms published via the Service; imports in the Service interface; the Service's API; integrations activated by the Controller.
Categories of data subjects: The Controller's subscribers and recipients.
Categories of personal data: Contact details (email address, name, telephone number where provided); custom attributes provided by the Controller; consent records (time, source, IP address at signup, version of consent text); message content to the extent it contains personal data; delivery and engagement events (sent, delivered, bounced, opened, clicked, unsubscribed, complained) with timestamps; coarse IP-derived location (city/country); device and email-client information; suppression records.
Special categories of personal data: Not processed, except by separate written agreement between the Parties; never in AI features.
Annex 2: Technical and organizational measures
- Encryption of Customer Data in transit (TLS) and at rest.
- Role-based access control on a least-privilege basis; logging of personnel access to Customer Data.
- Tenant isolation between customers enforced at the application and query layer, verified by automated tests.
- Data minimization: IP addresses used for engagement geolocation are resolved against a local geolocation database (no third-party lookup), retained in raw form for a maximum of 72 hours in a segregated security log and thereafter truncated or deleted; location is never stored at finer than city level.
- Filtering of automated engagement events (mailbox-provider prefetching, link scanning by security gateways) from per-recipient reporting, where identifiable.
- Suppression checks at the time of sending on all sending paths, including the API, with typed rules per message class (hard bounce blocks all; complaints and unsubscribes block marketing).
- Message-queue payloads contain references rather than full personal data records, with short retention at the broker.
- Pseudonymization or exclusion of personal data in AI calls where the feature permits; AI inference restricted to providers in EU regions under contractual training prohibitions.
- Engagement events are retained for the duration of the Agreement and deleted in accordance with "Deletion and return".
- Encrypted backups with defined rotation; deletion re-applied on restore.
- Vulnerability and patch management; segregated environments.
- Documented incident-management process, including the notification chain under "Personal data breaches", tested contact routes to Sub-processors, and an internal incident register.
- Confidentiality undertakings and data protection training for personnel.
- Due diligence of Sub-processors before engagement and ongoing follow-up.
Annex 3: Sub-processors
The Sub-processors engaged at any given time, with entity, purpose and location of processing, are set out in the Register at /subprocessors, which forms part of this Agreement. Customer Data is processed within the EU/EEA in accordance with the Register.
This page is provided for general information and is not legal advice.