Data Processing Addendum
Effective August 24, 2026 · Version v1.4.0-2026-08-24
This Data Processing Addendum (the "DPA") forms part of our Terms of Service and applies when, in using Inventory Mailer, you process the personal data of your contacts and recipients. It sets out how we handle that data on your behalf. It is written to meet GDPR Article 28 and the equivalent California requirements. If you need a countersigned copy for your records, email support@inventorymailer.com.
1. Roles of the parties
For the personal data of your contacts and recipients processed through the Service ("Customer Personal Data"), you are the controller and we are your processor. Where you are yourself acting as a processor for another controller, we act as your subprocessor, and the same obligations flow through. For your own account data, we act as a controller, as described in our Privacy Policy; that is outside the scope of this DPA.
2. Scope and instructions
We will process Customer Personal Data only on your documented instructions, which include: (a) providing and maintaining the Service; (b) what you direct through your use of the Service, such as the campaigns you send and the segments you build; (c) what is set out in the Terms and this DPA; and (d) any other written instruction you give that we agree to. We will tell you if, in our opinion, an instruction infringes applicable data protection law, unless we are legally prohibited from doing so. We will not process Customer Personal Data for any other purpose, and we will not sell it.
3. Confidentiality
We ensure that the people we authorize to process Customer Personal Data are bound by an appropriate duty of confidentiality and only access the data as needed to provide, secure, and improve the Service.
4. Security
We implement and maintain technical and organizational measures appropriate to the risk, taking into account the nature of the data. These include: tenant isolation enforced at the database layer through row-level security, applied on every read rather than by application logic; encryption of data in transit; access controls and authentication; an audit history of important changes; and hosting on infrastructure that is itself SOC 2 Type II certified (Supabase and Vercel). Card data is handled by Stripe, a PCI Level 1 provider, and never reaches our servers. We review and update these measures as the Service evolves.
5. Subprocessors
You give us general authorization to engage the subprocessors listed on our Subprocessors page to process Customer Personal Data. We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain responsible to you for their performance. Before adding or replacing a subprocessor that handles Customer Personal Data, we will update the Subprocessors page and give notice at least 30 days in advance. If you have a reasonable, data-protection-based objection, tell us; we will work with you in good faith, and if we cannot resolve it, you may terminate the affected part of the Service.
6. Assisting you with data subject requests
The Service gives you tools to access, correct, and delete individual contact records directly. Inquiry records from your public pages can be viewed, assigned, and marked handled in the app; to delete one, ask us and we will do it within 45 days. We will provide a full export on request within the same window. Taking that into account, we will provide reasonable assistance, by appropriate technical and organizational measures, to help you respond to requests from data subjects exercising their rights. If a data subject contacts us directly about data you control, we will promptly refer them to you rather than respond on our own.
7. Assisting you with compliance
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to help you meet your obligations under GDPR Articles 32 through 36, including security of processing, notifying personal data breaches, communicating breaches to data subjects, and carrying out data protection impact assessments and prior consultations where required.
8. Security incident response
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, and in any case within 72 hours of becoming aware. Our notice will describe, to the extent known, the nature of the breach, its likely consequences, and the measures we have taken or propose to take. We will cooperate with you and take reasonable steps to mitigate and remediate.
9. Audits and reports
We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To respect the security and confidentiality of our other customers, audits are on reasonable prior notice, no more than once a year except where a regulator requires otherwise or following a breach, and may be satisfied by our providing relevant policies and the summary audit reports of our infrastructure subprocessors.
10. Return and deletion
You can request an export of Customer Personal Data at any time. On termination, and at your choice, we will return or delete Customer Personal Data; deletion follows our standard 30-day soft-delete grace window before a permanent purge. We may retain data where required by law, and we keep suppression-list entries (unsubscribes, bounces, and complaints) as needed to keep honoring opt-outs, in de-identified or minimized form where practical.
11. International transfers
The Service is operated from the United States, and Customer Personal Data is stored and processed in the United States. Some subprocessors route requests and run bot protection through global edge networks, and AI assistant requests are routed to a provider-dependent region; each vendor's location is listed on our Subprocessors page. Where you transfer Customer Personal Data subject to the GDPR or UK data protection law to us, the parties agree that the European Commission's Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Addendum) are incorporated by reference and apply to that transfer, with you as data exporter and us as data importer, and with the relevant modules and options completed consistent with this DPA. We will assist with transfer impact information you reasonably request.
12. California (CCPA/CPRA)
Where the California Consumer Privacy Act applies, we act as a "service provider" and process Customer Personal Data only to provide the Service to you (the specified business purpose). We will not: (a) sell or share that data, as those terms are defined under California law; (b) retain, use, or disclose it for any purpose other than providing the Service or as permitted by the CCPA; (c) retain, use, or disclose it outside our direct business relationship with you; or (d) combine it with personal information from other sources, except as the CCPA permits. We certify that we understand and will comply with these restrictions, and we provide the same level of privacy protection the CCPA requires of you. You may take reasonable steps to confirm our use of the data remains consistent with your obligations.
13. Processing details (Annex)
- Subject matter
- Providing the Inventory Mailer email marketing service to the Customer.
- Duration
- For the term of the Terms of Service, plus the retention periods described above.
- Nature and purpose
- Storing, organizing, and transmitting email and related data so the Customer can send campaigns to its contacts, and recording engagement on those campaigns. Publishing the Customer's inventory on public item pages and showcases at the Customer's direction, and receiving, routing, and storing inquiries submitted through those pages.
- Types of data
- Contact identifiers (such as names and email addresses), any custom fields the Customer adds, email content, and engagement events (opens, clicks, bounces, complaints, unsubscribes). For inquiries submitted through the Customer's public pages: the sender's name and email address, a phone number and free-text message where provided, their marketing consent choice, and the item, campaign, or showcase the inquiry came from.
- Data subjects
- The Customer's own contacts and email recipients, and people who submit an inquiry through the Customer's public item pages or showcases.
- Subprocessors
- As listed on the Subprocessors page.
14. General
Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service. If there is a conflict between this DPA and the rest of the Terms about the processing of Customer Personal Data, this DPA controls. This DPA stays in effect for as long as we process Customer Personal Data. It is governed by the same law and forum as the Terms, except where data protection law requires otherwise.
To request a countersigned copy of this DPA, or for any question about it, email support@inventorymailer.com.