1. Introduction, Scope and Definitions
This Data Processing Agreement ("DPA") forms part of the Terms of Service between JetEmail Pty Ltd ("JetEmail", "Processor", "we", "us", or "our") and the customer ("Controller", "you", or "your") for the provision of JetEmail's services, including Outbound Email, Inbound Email and the Marketing Suite.
This DPA applies where and to the extent that JetEmail processes Personal Data on behalf of the Controller in the course of providing the Services, and that processing is subject to:
- the General Data Protection Regulation (EU) 2016/679 ("GDPR");
- the UK GDPR and the Data Protection Act 2018;
- the Swiss Federal Act on Data Protection;
- the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles; or
- a United States state privacy law, in which case Section 11 also applies.
Where a term of this DPA conflicts with the Terms of Service, this DPA prevails for matters concerning the processing of Personal Data.
Definitions
- "Personal Data" has the meaning given in the GDPR, and includes personal information under the Australian Privacy Act and personal information under applicable US state privacy laws
- "Processing" has the meaning given in the GDPR
- "Data Subject" has the meaning given in the GDPR
- "Controller" has the meaning given in the GDPR, and includes a business under US state privacy laws
- "Processor" has the meaning given in the GDPR, and includes a service provider under US state privacy laws
- "Services" means JetEmail's email delivery, inbound filtering and marketing platform services
- "Contact" means a person record the Controller stores in the Marketing Suite
2. Data Processing Details
Subject Matter and Duration
The subject matter of processing is the provision of email delivery, inbound filtering and marketing platform services. The duration of processing is the term of the service agreement, plus the retention periods described in Section 9 and our Privacy Policy.
Nature and Purpose of Processing
JetEmail processes Personal Data for the purpose of:
- Delivering email messages on behalf of the Controller
- Filtering, quarantining and routing inbound mail for the Controller's domains
- Storing and managing Contacts, audiences, tags and custom attributes
- Operating hosted and embedded signup forms, including double opt-in confirmations and consent records
- Composing and storing campaigns, templates, template versions and uploaded image assets, and serving those assets from public URLs
- Executing broadcasts, scheduled sends, audience and merge snapshots, and template-based transactional sends
- Open and click tracking and delivery analytics, where the Controller enables them
- Running automation workflows, including custom event payloads the Controller sends us
- Recording and applying unsubscribes, complaints, bounces and suppression evidence, and hosting unsubscribe pages
- Form abuse prevention, deliverability protection, fraud and security processing, and legal compliance
- Object storage, cache and content delivery, including through Cloudflare
- Transmitting data to webhook and redirect destinations the Controller configures
Categories of Personal Data
The Personal Data processed may include:
- Email addresses of Contacts and recipients
- Names and any custom attributes, tags and merge data the Controller supplies
- Email content, subject lines and attachments
- Email metadata, including timestamps, message identifiers and delivery status
- Form submission data, including source page URL, consent wording and consent status
- Engagement data, including opens, clicks, destination URLs, approximate location, device, user agent and email client
- Workflow trigger and event data supplied by the Controller
- Unsubscribe, complaint and suppression records
- IP addresses, pseudonymous abuse signals and other technical identifiers
- Images and other files the Controller uploads, which may contain Personal Data
The Controller must not submit special category data under GDPR Article 9, sensitive information under the Australian Privacy Act, or sensitive personal information under US state privacy laws, unless JetEmail has expressly agreed in writing and the Controller has met the requirements of applicable law.
Categories of Data Subjects
Data subjects may include:
- Email recipients (customers, prospects, subscribers)
- People who submit a signup form published or embedded by the Controller
- Business contacts
- End users of the Controller's services
3. Controller and Processor Obligations
Controller Obligations
The Controller warrants and undertakes that:
- It has a lawful basis for processing under GDPR Article 6 and, for direct marketing, any consent required under GDPR, PECR or the equivalent law of the recipient's jurisdiction
- It has obtained all necessary consents and authorizations, and can produce evidence of them
- It will comply with all applicable data protection and anti-spam laws
- It will provide clear privacy and collection notices to data subjects, including at the point of collection on any signup form it publishes or embeds
- It will handle data subject requests and complaints relating to its Contacts and recipients
- It is responsible for the tracking settings it enables, the fields it collects, the events it sends, and any webhook or redirect destination it configures
- It will notify JetEmail of any relevant legal restrictions
Processor Obligations
JetEmail undertakes to:
- Process Personal Data only on documented instructions from the Controller, including for international transfers, unless required otherwise by law that applies to JetEmail, in which case we will inform the Controller before processing where the law permits
- Implement appropriate technical and organizational measures
- Ensure that personnel authorized to process Personal Data are bound by confidentiality
- Assist with data subject rights requests where feasible
- Assist with data protection impact assessments and prior consultations, taking into account the nature of processing and the information available to us
- Notify the Controller of any Personal Data breaches
- Delete or return Personal Data upon termination, subject to Section 9
- Not sell Personal Data, share it for cross-context behavioural advertising, or use it for our own commercial purposes
- Not use Contacts, campaign content or recipient engagement data to train machine learning models for use outside the Controller's account
The Controller's use of the Services, and its configuration of them, constitutes its documented instructions to JetEmail.
JetEmail's Independent Purposes
JetEmail acts as an independent controller, not as the Controller's processor, for a limited set of purposes that are its own:
- Billing, account administration and support records
- Security, fraud detection, abuse prevention and network protection, including automated content, attachment, link and image scanning
- Protecting the deliverability and reputation of shared sending infrastructure
- Complaint handling, including feedback loop data received from mailbox providers
- Compliance with laws that apply to JetEmail, including mandatory reporting obligations
- Aggregated and de-identified service telemetry
For those purposes JetEmail determines the means and purposes and is responsible under applicable law in its own right. We limit that processing to what is necessary and describe it in our Privacy Policy.
4. Technical and Organizational Measures
JetEmail implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Technical Measures
- Encryption of Personal Data in transit and at rest
- Access controls and authentication systems
- Logical separation of customer data by account owner
- Regular security monitoring and logging
- Secure data backup and recovery procedures
- Network security and firewall protection
Organizational Measures
- Staff training on data protection requirements
- Confidentiality agreements for all personnel
- Least-privilege access, with restricted and logged access to abuse and child safety case data
- Regular security assessments and audits
- Incident response and breach notification procedures
- Data retention and deletion policies
5. Sub-processors
The Controller provides general authorization for JetEmail to engage sub-processors for the processing of Personal Data, subject to the following conditions:
- JetEmail maintains a current list of sub-processors on our website
- All sub-processors are bound by data protection obligations equivalent to this DPA
- JetEmail remains fully liable for sub-processor performance
- JetEmail will give at least 30 days' notice before adding or replacing a sub-processor, by email or dashboard notice
- The Controller may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Controller may terminate the affected Services and receive a refund of prepaid fees for the unused term
- Where an urgent replacement is required for security or continuity, we may act first and notify the Controller promptly afterwards
The current list of sub-processors is available at: jetemail.com/legals/gdpr-subprocessors
6. International Data Transfers
JetEmail is located in Australia. Personal Data may be processed and stored in Australia, the United States and the European Union, and may transit the global networks of our infrastructure providers.
For transfers to countries without an adequacy decision, JetEmail ensures appropriate safeguards are in place, including:
- The European Commission Standard Contractual Clauses, using the module appropriate to the transfer, which are incorporated into this DPA by reference where they apply
- The UK International Data Transfer Addendum for transfers subject to UK law
- Standard Contractual Clauses with sub-processors
- Additional technical and organizational security measures as required
Where the Controller requires details of where a specific category of data is stored, we will provide them on request.
7. Data Subject Rights
JetEmail will assist the Controller in fulfilling data subject rights requests where technically feasible and legally required. This includes:
- Right of Access: Providing available Personal Data upon request
- Right to Rectification: Correcting inaccurate Personal Data
- Right to Erasure: Deleting Personal Data where legally required
- Right to Restrict Processing: Limiting processing where applicable
- Right to Data Portability: Providing data in a structured format
- Right to Object: Applying a suppression so that direct marketing stops
Marketing Suite records for one person can exist across contacts, form submissions, delivery logs, engagement events, workflow enrollments, message archives and suppression evidence. The Controller can action most of these itself in the dashboard, including contact deletion and export. Where a request needs our assistance, contact us and we will help within the timeframes the Controller needs to meet its own obligations.
An objection to direct marketing is given effect by recording a suppression. That record is retained rather than erased, because deleting it would allow the person to be re-added by a later import. This is the minimum data needed to honour the objection.
If a data subject contacts JetEmail directly about data we process for a Controller, we will not respond substantively on the Controller's behalf. We will refer them to the Controller and inform the Controller of the request.
The Controller remains responsible for responding to data subject requests and determining the legal basis for any actions taken.
8. Data Breach Notification
JetEmail will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data. The notification will include, to the extent known at the time:
- Description of the nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- A contact point for further information
Where full details are not available immediately, we will provide an initial notification and then further information as our investigation progresses, rather than delaying notification until the picture is complete.
The Controller remains responsible for determining whether to notify supervisory authorities and data subjects as required by GDPR Articles 33 and 34, or by the equivalent provisions of another applicable law.
9. Data Retention and Deletion
JetEmail will:
- Retain Personal Data only for as long as necessary to provide the Services or as described in our Privacy Policy
- Delete or return Personal Data upon termination of the service agreement, on the schedule set out in our Terms of Service
- Provide, on request, written confirmation of the deletion we have carried out and the categories of data that remain under the exceptions below
Exceptions to Deletion
Deletion does not extend to:
- Suppression and unsubscribe evidence, which is retained so that a data subject's objection continues to be honoured and cannot be reversed by a later import
- Billing, tax and accounting records required by law
- Security, abuse and complaint records, and material preserved for a legal claim, investigation or mandatory report
- Copies held in encrypted backups and disaster recovery systems, which expire on their own cycle rather than being individually deleted. Those copies are access-restricted and are not used for any other purpose.
- Cached copies of public asset URLs held by content delivery networks and mailbox providers, which are outside our direct control
Retained data is minimised to what the purpose requires, access-restricted, and deleted or de-identified when the purpose ends. We would rather state these limits than certify an erasure we cannot perform.
10. Audits and Compliance
JetEmail will:
- Maintain records of processing activities as required by GDPR Article 30
- Provide information necessary to demonstrate compliance with this DPA
- Allow for and contribute to audits by the Controller or an independent auditor it appoints
- Cooperate with supervisory authorities as required
How Audits Work
- We will first offer our security documentation, policies and completed assessment questionnaires. Where those reasonably answer the Controller's questions, they satisfy this section.
- Where they do not, the Controller may audit once in any 12 month period, and additionally where a supervisory authority requires it or following a confirmed breach affecting the Controller's data.
- Audits require at least 30 days' written notice, take place during business hours, must not unreasonably disrupt our operations, and are conducted at the Controller's cost.
- The auditor must not be a competitor of JetEmail and must sign a confidentiality agreement.
- Audits must not extend to any other customer's data, to systems shared with other customers in a way that would expose their data, or to information we are legally barred from disclosing.
11. United States State Privacy Laws
This section applies where the Controller is subject to a United States state privacy law, including the California Consumer Privacy Act as amended, and where JetEmail processes personal information on its behalf. In that case JetEmail is a service provider or processor, and the Controller is a business or controller.
JetEmail:
- Will not sell or share personal information, as those terms are defined in the applicable law
- Will not retain, use or disclose personal information for any purpose other than the business purposes specified in this DPA and the Terms of Service, or as otherwise permitted by law
- Will not retain, use or disclose personal information outside the direct business relationship between JetEmail and the Controller
- Will not combine personal information received from the Controller with personal information received from another source, except as permitted by the applicable law
- Will comply with the obligations applicable to a service provider and provide the same level of privacy protection required of the Controller
- Will notify the Controller if it determines it can no longer meet those obligations
- Will assist the Controller in responding to verified consumer requests, and will apply a suppression to give effect to an opt-out of marketing
The Controller may take reasonable and appropriate steps to stop and remediate unauthorized use of personal information. The Controller must not submit sensitive personal information unless JetEmail has expressly agreed in writing.
12. Australian Privacy Act
Where the Controller is an APP entity or otherwise subject to the Australian Privacy Act, JetEmail handles personal information on the Controller's behalf in a manner consistent with the Australian Privacy Principles, including APP 6 (use and disclosure), APP 8 (cross-border disclosure), APP 11 (security and destruction) and the Notifiable Data Breaches scheme.
The Controller is responsible for its own APP 1 and APP 5 obligations, including maintaining a privacy policy and giving collection notices at the point at which it collects personal information, whether through a signup form, a checkout or any other channel.
Section 6 describes the cross-border disclosures involved in providing the Services and the safeguards we apply.
13. Liability and Indemnification
Each party's liability under this DPA is subject to the limitations and exclusions set out in the main service agreement. JetEmail's total liability for all claims arising under this DPA shall not exceed the total fees paid by the Controller in the 12 months preceding the claim.
The Controller will indemnify JetEmail against claims arising from the Controller's breach of this DPA or applicable data protection laws.
Nothing in this section limits either party's liability where the law does not permit that liability to be limited, including a data subject's right to compensation under GDPR Article 82 and rights under the Australian Consumer Law.
14. Term and Termination
This DPA will remain in effect for the duration of the service agreement. Upon termination:
- JetEmail will cease processing Personal Data except as required by law or permitted under Section 9
- Personal Data will be deleted or returned as instructed by the Controller, subject to the exceptions in Section 9
- Confidentiality obligations will survive termination
15. Governing Law and Jurisdiction
This DPA is governed by the laws of New South Wales, Australia. Any disputes will be subject to the exclusive jurisdiction of the courts of New South Wales, Australia.
Where Standard Contractual Clauses apply to a transfer, the governing law and forum stated in those clauses apply to them, and the relevant supervisory authorities maintain their jurisdiction as provided under the GDPR.
16. Contact Information
For questions regarding this DPA or data protection matters, please contact:
JetEmail Pty Ltd
Australian Company Number: 641 539 166
Data Protection Officer: legal@jetemail.com
General Inquiries: Available through your JetEmail dashboard
17. Amendments
JetEmail may update this DPA from time to time to reflect changes in our processing activities, legal requirements, or business practices. Material changes will be communicated to Controllers with at least 30 days' notice, in line with our Terms of Service, except where an earlier change is required by law or to address a security risk.