Data Processing Agreement (DPA)
Last updated · 2026-09-08
This document is maintained in English and Chinese — showing the English version. 本文件以英文与中文为准,此处显示英文版。
This DPA between you (customer/controller) and NexoRelay (processor) governs recipient personal data, and applies together with the Terms of Service. For a countersigned copy contact .
1. Scope
Subject matter: recipient addresses, content and engagement events in emails you entrust to us. Purposes: delivery, status callbacks, unsubscribe/suppression and abuse control only. We never use recipient data for our own purposes and never train models on it.
2. Instructions only
We process only on your API calls, console actions and this DPA; if an instruction would breach data protection law we tell you before executing.
3. Confidentiality and personnel
Personnel with data access are bound by confidentiality; production access follows least privilege with audit trails.
4. Security measures
HTTPS everywhere; sensitive fields encrypted with AES-256-GCM; passwords argon2id; production secrets live only in infrastructure variables; enforced tenant isolation (tenant_id on every business table); audit trails on all privileged actions.
5. Subprocessors
AWS (SES delivery, us-east-1), Railway (hosting), Cloudflare (DNS), OpenRouter (AI assistant), Google (optional OAuth sign-in). New subprocessors are announced in-app 14 days ahead; you may object in writing within 14 days, and we will offer an alternative or allow termination of affected services with pro-rata refund.
6. Data subject requests
Contact export/deletion is self-service in the console; other requests (access, rectification, restriction, portability) get our technical assistance within 7 days.
7. Personal data breaches
We notify you within 72 hours of confirmation, describing nature, impact and remediation, and cooperate on regulator and data-subject notifications.
8. International transfers
Processing is primarily in the US (AWS us-east-1). Third-country transfers rely on Standard Contractual Clauses plus supplementary technical measures (encryption in transit, minimization).
9. Deletion and return
On termination or request, recipient data is deleted or returned within 30 days (except audit logs the law requires), with written confirmation.
10. Audit rights
One audit per year (or via an independent auditor) with 30 days written notice, scoped to processing of your data, at your cost; security reports available on request.