Legal
Data Processing Agreement
The Art. 28 GDPR terms on which Aethon Systems OÜ processes personal data on your behalf.
Preamble
This Data Processing Agreement ("DPA") forms part of the DeliverSight Terms of Service (the "Terms") between Aethon Systems OÜ, registry code 17345654, Sepapaja 6, 15551 Tallinn, Estonia ("DeliverSight", "we", "us" or "Processor") and the customer that accepts the Terms ("Customer").
This DPA applies to the extent we process Customer Personal Data on behalf of Customer in connection with the Service. It is intended to satisfy Article 28 of Regulation (EU) 2016/679 ("GDPR") and equivalent processor-contract requirements under other Data Protection Laws that apply to the processing.
Electronic acceptance of the Terms constitutes written acceptance of this DPA. A signed copy is available on request — write to us and we will provide one; the terms will be these terms. If this DPA conflicts with the Terms concerning the processing of Customer Personal Data, this DPA controls. The Terms otherwise remain in effect.
1. Definitions
"Customer Personal Data" means personal data processed by us on behalf of Customer through the Service, including personal data contained in test emails, message headers and bodies, DMARC reports, domain-monitoring inputs, and the reports generated from that material.
"Data Protection Laws" means the GDPR and applicable EEA or Member State laws governing the processing of Customer Personal Data. Where applicable to a Customer, it also includes the UK GDPR and the UK Data Protection Act 2018.
"Service" means the DeliverSight email-deliverability testing, monitoring, DMARC reporting, API, reporting, alerting and related services covered by the Terms.
"Subprocessor" means a third party engaged by us to process Customer Personal Data on behalf of Customer. A vendor we use only for our own controller processing — billing, or website analytics — is not a Subprocessor under this DPA, and is disclosed in the Privacy Policy instead.
The terms "controller", "processor", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given in the applicable Data Protection Laws.
2. Roles and scope
2.1 Customer as controller — where Customer determines why and how Customer Personal Data is processed, Customer is the controller and we are the processor. This turns on the factual role rather than on what kind of customer you are: an individual acting as a controller is covered by this DPA in the same way a company is.
2.2 Customer as processor — where Customer processes personal data on behalf of another controller, Customer acts as a processor and appoints us as its subprocessor. Customer confirms that it is authorised by the relevant controller to appoint us and to give the instructions described in this DPA. This is the ordinary case for an agency or managed service provider testing on behalf of its own clients.
2.3 DeliverSight as independent controller — we act as an independent controller for personal data we process for our own business purposes, including account administration, authentication, billing, tax records, fraud and abuse prevention, service security, operational logs, support communications and legal compliance. That processing is governed by the Privacy Policy and is outside the scope of this DPA.
2.4 Customer responsibilities — Customer is responsible for ensuring that its instructions comply with Data Protection Laws; for having an appropriate lawful basis for providing Customer Personal Data to us; for giving any required notices to data subjects; for obtaining any permissions or authorisations required for the processing; for using reasonable data-minimisation practices; and for securing its accounts, API keys, integrations and user access.
Customer must not intentionally submit special-category data under Article 9 GDPR or criminal-conviction data under Article 10 GDPR unless the processing is necessary, lawful, and we have agreed to it in writing. Accidental submission remains covered by this DPA, but Customer must notify us promptly after becoming aware of it.
3. Processing details
The subject matter, duration, nature, purpose, personal-data categories and data-subject categories are described in Annex A.
4. Documented instructions
4.1 Scope of instructions — we will process Customer Personal Data only on Customer’s documented instructions, including instructions concerning transfers to a third country or international organisation, unless processing is required by EU or Member State law applicable to us.
Customer’s documented instructions consist of: the Terms and this DPA; Customer’s settings and configuration in the Service; actions taken through the dashboard, API and integrations; use of a Service feature for its documented purpose; and additional written instructions accepted by us. Using a feature is an instruction to perform it — we do not need a separate instruction to run the analysis you asked for.
If law requires processing outside Customer’s instructions, we will inform Customer before carrying out that processing unless the law prohibits the notice.
4.2 Unlawful instructions — we will immediately inform Customer if, in our opinion, an instruction infringes Data Protection Laws. We may suspend only the affected processing while the parties resolve the issue.
4.3 Use restrictions — we will not sell Customer Personal Data, use it for advertising, build advertising profiles from it, or use message content to train machine-learning models.
We may use service metrics and statistical information only where the information has been aggregated or anonymised so that neither a person nor Customer is reasonably identifiable. Such information will not include reusable message-body content or direct identifiers.
4.4 Additional instructions — instructions outside the normal functionality of the Service are subject to technical feasibility. If complying would require material additional work, we will explain the expected work and any reasonable charge before proceeding rather than after.
5. Confidentiality and authorised personnel
We will ensure that each person authorised to process Customer Personal Data is bound by a contractual, statutory or professional confidentiality obligation; receives access only where necessary for an authorised task; is subject to least-privilege access controls; and receives appropriate data-protection and security guidance.
Production access is limited to personnel who need it to operate, secure, maintain or support the Service, investigate an incident, comply with law, or carry out an instruction from Customer. Administrative and support access is logged.
Confidentiality obligations continue after a person’s employment or engagement ends.
6. Security
We will implement and maintain appropriate technical and organisational measures under Article 32 GDPR, taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals.
The current measures are described in Annex B. We may update those measures as the Service changes, but will not materially reduce the overall level of protection during the term without Customer’s agreement, unless a change is required to address an urgent security risk or comply with law.
Customer acknowledges that security is a shared responsibility and will use the available security controls, including multi-factor authentication and scoped API credentials, where appropriate.
7. Subprocessors
7.1 General written authorisation — Customer gives us general written authorisation to engage the Subprocessors listed on our subprocessors page. The list in effect when this DPA becomes binding is the initial list authorised by Customer and forms part of this DPA.
The list identifies, for each Subprocessor, its legal name, service and processing activity, the categories of Customer Personal Data processed, principal processing locations, the applicable transfer mechanism, and the date added.
7.2 Changes — we will notify Customer by email at least 30 days before adding or replacing a Subprocessor, with enough information for Customer to assess the change. Where an urgent replacement is necessary to protect the Service, Customer Personal Data or users, we may make the change sooner and will notify Customer without undue delay.
7.3 Objections — Customer may object during the notice period on reasonable grounds relating to the protection of Customer Personal Data. We will use commercially reasonable efforts to avoid use of the proposed Subprocessor for Customer or to provide a reasonable alternative. If no reasonable alternative is available, Customer may terminate the affected Service before the Subprocessor begins processing Customer Personal Data, and we will refund the unused portion of prepaid fees for the terminated Service. Objecting costs you nothing and does not affect anything else.
7.4 Subprocessor obligations — we will enter into a written agreement with each Subprocessor imposing data-protection obligations providing substantially the same level of protection required by this DPA, to the extent applicable to the processing that Subprocessor performs. We remain responsible to Customer for the performance of each Subprocessor’s data-protection obligations.
Where Customer acts as a processor, Customer is responsible for obtaining any authorisation required from the relevant controller before appointing us or approving our Subprocessors.
8. Data-subject requests
Taking account of the nature of the processing, we will assist Customer through appropriate technical and organisational measures, insofar as reasonably possible, with Customer’s obligations to respond to requests under Chapter III GDPR.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively unless instructed by Customer or required by law; we will direct the person to Customer where appropriate; and we will notify Customer unless prohibited by law.
Where the dashboard or API allows Customer to fulfil a request directly, Customer should use those functions — it is faster than asking us. We will provide reasonable additional assistance where the required action is not available through the Service.
We will not charge for ordinary and reasonable assistance. If a request is manifestly excessive, repetitive or requires disproportionate technical work, the parties will agree any reasonable cost in advance. No charge will be used to prevent Customer from exercising a right required by Data Protection Laws.
9. Security incidents and compliance assistance
9.1 Personal data breaches — we will notify Customer without undue delay and, in any event, within 48 hours after becoming aware of a personal data breach affecting Customer Personal Data. The 72-hour clock to your supervisory authority under Art. 33 is yours to meet, which is why ours is shorter.
The initial notice will include the information reasonably available at the time: the nature of the breach; the categories and approximate numbers of affected data subjects and records, where known; likely consequences; measures taken or proposed to contain, investigate and remediate the breach; and a contact point for follow-up.
We may provide information in phases as the investigation progresses, and will not delay an initial notice solely because all details are not yet available.
Customer remains responsible for deciding whether notifications to a supervisory authority or to data subjects are required, and for making them, unless the parties agree otherwise in writing. We will not make that decision on Customer’s behalf.
9.2 Assistance under Articles 32 to 36 — taking account of the nature of processing and the information available to us, we will reasonably assist Customer with security-of-processing obligations; breach notifications to authorities and data subjects; data protection impact assessments; and prior consultation with a supervisory authority.
10. Return, export and deletion
10.1 During the term — Customer may access or export available Customer Personal Data through the dashboard and API while its account and the relevant data remain available. Test history and webhook delivery history export to CSV. Service-plan retention periods continue to apply during the term, and Customer is responsible for exporting information before the applicable retention period expires.
Plan retention windows are 30 days on Free, 90 days on Starter, and a year on Pro, Business and Custom. Test material ages out on that window and is deleted when it does, whether or not the subscription is still running. Stored message bodies are additionally subject to an outer expiry in object storage that no plan configuration can exceed.
10.2 End of processing — at the end of the Services involving processing, Customer may choose to (1) receive or export Customer Personal Data in a commonly used format and then have the remaining copies deleted, or (2) have Customer Personal Data deleted without return. Customer should communicate its choice before termination or promptly afterwards.
If Customer gives no instruction, deletion happens automatically and needs no action: closing an account or workspace removes it from the Service immediately, starts a 14-day recovery period during which signing in again restores it, and then permanently deletes the account and its data, including stored messages. In every case we will delete Customer Personal Data from active systems within 30 days after the end of the affected Service or the closure of the relevant account or workspace.
We may retain Customer Personal Data only where EU or Member State law requires continued storage. If that occurs, we will isolate the retained data, process it only for the legally required purpose, and inform Customer unless prohibited by law.
10.3 Backups — after deletion from active systems, residual copies may remain in encrypted backup media until the applicable backup cycle expires, for no longer than 30 days. Backup copies are not used for ordinary processing and are restored only for disaster recovery. If a backup is restored, we will reapply the relevant deletion instructions and retention rules.
10.4 Early deletion and confirmation — Customer may request earlier deletion where technically feasible. On request, we will provide reasonable written confirmation when deletion has been completed.
Billing, tax, security and legal records that we hold as an independent controller are not Customer Personal Data under this DPA. They are retained under the Privacy Policy and applicable law, which requires longer than any period above.
11. Compliance information and audits
We will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, including relevant information about security controls, processing locations, retention, transfers and Subprocessors.
We may first satisfy an audit request by providing current documentation, answering a reasonable security questionnaire, or arranging a remote review. In practice, ask us — we would rather answer a questionnaire or walk through Annex B than have you assume.
Customer or an independent auditor mandated by Customer may conduct an audit, including an inspection, subject to the following safeguards: ordinarily no more than once in any 12-month period; at least 30 days’ prior notice where reasonably possible; during normal business hours and without unreasonable disruption; under appropriate confidentiality obligations; without access to another customer’s data or systems; and with a scope reasonably related to Customer Personal Data and this DPA.
The annual limit and ordinary notice period do not apply where a supervisory authority requires an audit; a personal data breach affects Customer Personal Data; Customer has reasonable evidence of material non-compliance; or urgent circumstances make the ordinary period inappropriate.
Customer bears its own audit costs. We may charge reasonable direct costs for extraordinary, repeated or highly customised audit work, agreed in advance. We will not charge for an audit required because of our material breach of this DPA, or for cooperation required by a supervisory authority.
Nothing in this section prevents Customer from choosing its auditor or determining an appropriate audit method, subject to reasonable security and confidentiality protections.
12. International transfers
We will not transfer Customer Personal Data outside the EEA except on Customer’s documented instructions, or where the transfer is necessary to provide the Service and is supported by a valid mechanism under Chapter V GDPR. The primary storage and inbound processing infrastructure for Customer Personal Data is in Finland, an EU member state. Cloudflare may process authenticated report and API traffic in transit through its global network, as described in the Subprocessor list.
The Subprocessor list identifies the relevant processing locations and transfer mechanisms.
Where an adequacy decision applies, we may rely on that decision while it remains valid and applicable to the recipient.
Where Standard Contractual Clauses are required, we will enter into the applicable module of the European Commission’s 2021 international-transfer clauses with the relevant recipient and implement supplementary measures where required. We will make information about the safeguards available to Customer on request, subject to lawful redactions protecting confidential information and other customers. That is a right under Art. 46(1); you should not have to argue for it.
We will monitor the continued validity of the transfer mechanisms we rely on. If a mechanism becomes invalid or unavailable, we will implement a lawful alternative, suspend the affected transfer, or cease use of the affected recipient.
This DPA is not itself intended to operate as the European Commission’s international-transfer Standard Contractual Clauses unless the parties expressly complete and incorporate those clauses for a specific restricted transfer.
13. Liability and data-subject rights
The liability provisions in the Terms apply to this DPA, subject to applicable law.
Nothing in this DPA limits a data subject’s rights under Data Protection Laws; either party’s responsibility to a supervisory authority; liability that cannot lawfully be limited or excluded; or the statutory allocation of liability under Article 82 GDPR.
Any contractual allocation of responsibility between the parties does not reduce the rights of data subjects.
14. Term, changes and governing law
This DPA becomes effective when Customer accepts the Terms, accepts this DPA electronically, or otherwise enters into a binding agreement incorporating it. It continues for as long as we process Customer Personal Data.
We may update this DPA to reflect changes in law, regulatory guidance or the Service, and will give reasonable advance notice of material changes. A change that materially reduces the protection of Customer Personal Data will not apply during an existing paid subscription term without Customer’s agreement, unless required by law or necessary to address an urgent security risk.
Subprocessor changes are governed by Section 7 rather than by this general change provision.
The governing-law and dispute provisions of the Terms apply to this DPA.
15. Contact
Questions, signed-copy requests, data-protection instructions, security questionnaires, incident communications, audit requests and transfer-safeguard requests: [email protected].
Annex A — Details of processing
Subject matter — provision of the DeliverSight email-deliverability testing, monitoring, DMARC aggregation, reporting, alerting, API and related support services.
Duration — the period in which we provide the affected Service, together with the applicable plan-retention periods and the deletion periods in Section 10.
Nature and purpose — receiving test email at addresses we allocate; parsing and analysing message headers, authentication results and content; receiving and processing DMARC aggregate reports; querying public DNS and reputation sources; monitoring domains, DNS records and sending infrastructure; storing and presenting reports, scores, histories and alerts; delivering configured notifications and signed webhooks; providing exports and API access; and securing, troubleshooting and supporting the processing.
Categories of Customer Personal Data, depending on Customer’s use of the Service — sender and recipient email addresses and display names; message headers, subject lines, body content and attachments submitted for testing; sending IP addresses and infrastructure identifiers; domains, DNS records, SPF, DKIM and DMARC data; identifiers and metadata contained in DMARC reports; report results, scores, monitoring history and alert records; webhook payloads and delivery history; and support material supplied by Customer that contains Customer Personal Data.
Categories of data subject, depending on Customer’s use of the Service — Customer’s employees, contractors, users and representatives; senders and recipients appearing in submitted test material; personnel or users associated with domains and infrastructure monitored by Customer; customers or clients on whose behalf Customer uses the Service; and other individuals appearing in Customer-provided material.
Frequency — continuous or recurring according to Customer’s configuration, with individual test processing initiated by Customer.
Retention — according to the plan-retention periods published for the Service and Section 10 of this DPA.
Annex B — Technical and organisational measures
In force as of 2026-07-30. These measures apply according to the nature and risk of the processing.
Hosting and data location — production application services, databases, object storage and mail-processing components are operated by us on infrastructure hosted by Hetzner Online GmbH in Finland. We operate these ourselves rather than buying them as third-party products, so the number of parties holding a copy of Customer Personal Data is as small as the architecture allows.
Administrative access — the staff console is not reachable from the public internet: it resolves only on our private network and has no public DNS record. Staff sign-in additionally requires multi-factor authentication. The two are independent, so neither a stolen credential nor network access alone is sufficient.
Access control — least-privilege access to production systems; role-based permissions and restricted administrative access; multi-factor authentication available for Customer accounts; passwords stored using Argon2id hashes, never in a recoverable form; API credentials scoped to permissions, displayed once, stored only as a hash, and revocable or rotatable at any time; session revocation following password changes and account closure; and review and removal of access that is no longer required.
Tenant separation — Customer records are associated with a workspace or account boundary, and application requests are authorised against current membership and permissions on each request rather than relying on client-supplied identifiers.
Encryption and network security — TLS protects website and API traffic in transit; internal service traffic is restricted to private infrastructure and network controls; secrets are held in configuration rather than source code; webhook requests are signed so recipients can verify authenticity; and inbound test mail is accepted only at addresses the Service has allocated.
Logging and monitoring — administrative actions are recorded in an append-only audit log identifying the actor, the target and the time; support access to a customer account is read-only unless Customer has asked for something requiring otherwise, and is recorded on the same log; and service and infrastructure monitoring is used to detect availability and security problems.
Secure operation and development — changes are reviewed before production deployment; dependencies, operating systems and infrastructure components are maintained and patched; access to deployment and production systems is restricted; and security defects are prioritised according to risk.
Availability and recovery — database backups and point-in-time recovery are maintained; backup retention is limited as described in Section 10; and rate limits and quota controls reduce abuse and resource exhaustion.
Incident response — we maintain procedures to identify, contain, investigate, remediate and document security incidents and to notify affected Customers in accordance with Section 9.
Data minimisation and deletion — plan-retention rules are enforced through scheduled deletion rather than manual housekeeping; stored message content is subject to an outer storage-expiry limit that no configuration can exceed; and account or workspace deletion is tracked through to completion, including the removal of stored objects.
Personnel and organisation — confidentiality obligations apply to authorised personnel; access is granted according to need and removed when no longer required; and responsibilities for operation, incident handling and customer requests are assigned.
Annex C — Subprocessors
The current Subprocessor list is published on our subprocessors page. It forms part of this DPA and is maintained in accordance with Section 7.
Only providers that process Customer Personal Data on behalf of Customer appear as Subprocessors under this DPA. Providers used solely for our own independent-controller activities — billing, and website analytics — are listed separately on that page and disclosed in the Privacy Policy, because they are not Subprocessors under this agreement.