1. Parties and roles
Controller: you, the customer. Processor: SNS Software Solutions GmbH, Schrötlgasse 8a, 1220 Vienna, Austria.
We process personal data only on your documented instructions. Your instructions are what you do in the product: the settings you save, the templates you write, the files you upload, the sends you enable. We will tell you if we believe an instruction breaches the GDPR.
2. Subject matter, duration, nature and purpose
- Subject matter
- Sending follow-up email to the customers you have quoted, and recording what happened to each message.
- Duration
- The term of your subscription, plus the deletion period in section 8.
- Nature and purpose
- Storing, reading, formatting, transmitting, recording delivery events, suppressing addresses, and deleting.
- Types of personal data
- Name, email address, telephone number, postal address, the quoted amount, what was quoted, the salesperson’s name, any further columns your spreadsheet contains, and the delivery and reply events for each message.
- Categories of data subject
- The prospective and existing customers you have issued quotes to, and the members of your own staff named in the export.
- Special categories
- None. Do not upload data revealing health, religion, political opinion, trade union membership, sex life, biometric or genetic data. Our processing is not designed for it.
3. Confidentiality
Everyone we allow to process your data is bound to confidentiality and is instructed on their obligations. Access is granted on a need-to-know basis and withdrawn when it is no longer needed.
4. Security measures (Article 32)
The measures below are the ones actually implemented, not aspirations:
- TLS for all traffic in transit; encryption at rest for the database and for backups.
- Tenant separation enforced in the database by row-level security policies, so a query issued for one company cannot return another company’s rows regardless of what the application asks for.
- Authorisation rules that matter — who may invite a colleague, whose plan permits a send — are enforced in the database alongside the data, not only in application code.
- The elevated database credential is confined to the scheduled sender and to signed inbound webhooks. It is never present in anything served to a browser.
- Passwordless sign-in by one-time link, so there is no credential to reuse or leak.
- Signed webhooks: unsigned or wrongly signed delivery events are rejected rather than trusted.
- Sending is constrained by a verified domain, a send window, a daily cap and a per-plan allowance, all applied atomically at the moment a message is claimed, so no code path can bypass them.
- Managed, automatically patched infrastructure with point-in-time database backups.
5. Subprocessors
You give general authorisation for the subprocessors listed at Subprocessors. We will give you at least 30 days’ notice by email before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate the affected service without penalty.
Each subprocessor is bound by written terms that are no less protective than this agreement.
6. International transfers
The database holding your uploaded data is in Ireland. Where a subprocessor is outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses and, where the provider is certified, on the EU–US Data Privacy Framework, together with the additional measures set out in section 4.
7. Assistance to you
We help you meet your own obligations: with requests from data subjects under Articles 15 to 22 that reach us instead of you, with data protection impact assessments and prior consultation under Articles 35 and 36, and with the security obligations of Article 32.
We notify you of a personal data breach affecting your data without undue delay after becoming aware of it, with enough detail for you to meet your own 72-hour obligation under Article 33.
8. Return and deletion
You can export or delete your data at any time while the account is open. When the contract ends we delete it within 30 days, together with copies held by subprocessors, unless EU or Austrian law requires us to keep it.
One exception, and it is deliberate: the suppression list — the addresses that unsubscribed, bounced or complained — is retained. It holds only the address and the reason, its purpose is to protect those people, and erasing it would allow them to be emailed again.
9. Audit
On request we provide the information needed to demonstrate compliance with Article 28. You may audit no more than once a year, at your cost, with 30 days’ notice, at a time that does not disrupt operations, and under confidentiality — or accept an independent report covering the same ground.
10. Liability and precedence
Liability under this agreement is governed by the Terms of Service. Where this agreement conflicts with those terms on the processing of personal data, this agreement prevails.