NEXORELAY — LEGAL

Data Processing Agreement (DPA)

Last updated · 2026-09-08

This DPA between you (customer/controller) and NexoRelay (processor) governs recipient personal data, and applies together with the Terms of Service. For a countersigned copy contact .

1. Scope

Subject matter: recipient addresses, content and engagement events in emails you entrust to us. Purposes: delivery, status callbacks, unsubscribe/suppression and abuse control only. We never use recipient data for our own purposes and never train models on it.

2. Instructions only

We process only on your API calls, console actions and this DPA; if an instruction would breach data protection law we tell you before executing.

3. Confidentiality and personnel

Personnel with data access are bound by confidentiality; production access follows least privilege with audit trails.

4. Security measures

HTTPS everywhere; sensitive fields encrypted with AES-256-GCM; passwords argon2id; production secrets live only in infrastructure variables; enforced tenant isolation (tenant_id on every business table); audit trails on all privileged actions.

5. Subprocessors

AWS (SES delivery, us-east-1), Railway (hosting), Cloudflare (DNS), OpenRouter (AI assistant), Google (optional OAuth sign-in). New subprocessors are announced in-app 14 days ahead; you may object in writing within 14 days, and we will offer an alternative or allow termination of affected services with pro-rata refund.

6. Data subject requests

Contact export/deletion is self-service in the console; other requests (access, rectification, restriction, portability) get our technical assistance within 7 days.

7. Personal data breaches

We notify you within 72 hours of confirmation, describing nature, impact and remediation, and cooperate on regulator and data-subject notifications.

8. International transfers

Processing is primarily in the US (AWS us-east-1). Third-country transfers rely on Standard Contractual Clauses plus supplementary technical measures (encryption in transit, minimization).

9. Deletion and return

On termination or request, recipient data is deleted or returned within 30 days (except audit logs the law requires), with written confirmation.

10. Audit rights

One audit per year (or via an independent auditor) with 30 days written notice, scoped to processing of your data, at your cost; security reports available on request.

DPA · NexoRelay · NexoRelay