Data Processing Agreement
Effective date: July 27, 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between you (and, if applicable, the organization you represent, "Customer," "you") and Digitload ("Processor," "we," "us"), the operator of MailInApp. It applies automatically to every Customer, with no separate signature required, for as long as the Terms of Service are in effect. Capitalized terms not defined here have the meaning given in the Terms of Service or the Privacy Policy.
1. Roles
As explained in Privacy Policy §1, Customer is the data controller for Content and Recipient Data (contact lists, form responses, poll votes, purchase records, and similar personal data Customer uploads or a Recipient generates), and Digitload is the data processor acting solely on Customer's documented instructions, as set out in the Terms of Service and this DPA. For Account Data (how Customer itself signs up, configures, and pays for the Services), Digitload is an independent controller, and this DPA does not apply to that processing.
2. Subject matter, duration, and nature of processing
- Subject matter and duration: Digitload processes personal data on Customer's behalf for as long as the Terms of Service remain in effect, and thereafter only as needed to comply with Section 8 (return/deletion) or a legal obligation.
- Nature and purpose: hosting and rendering Customer's email campaigns; delivering them (via Customer's own SMTP relay, a domain Customer verifies, or Digitload's transactional Send API); receiving and storing inbound mail at a domain Customer verifies (the "Mailbox" feature); recording Recipient interactions (opens, clicks, votes, submissions, orders) and routing them back to Customer; processing payments through Customer's own connected Stripe account; and generating optional AI content suggestions.
- Categories of data subjects: Customer's Recipients (the people Customer's campaigns are sent to or received from), and, where Customer invites them, Customer's own Team Members.
- Categories of personal data: the categories described in Privacy Policy §2 — principally Recipient contact details (name, email, custom fields), campaign interaction data (votes, form answers, ratings, orders, clicks, opens), and, where Customer enables the Mailbox feature, inbound email content and attachments addressed to Customer's own verified domain.
3. Processor obligations
Digitload will:
- Process personal data only on Customer's documented instructions, as given through the Services' own configuration (the projects, audiences, and integrations Customer sets up) and this DPA — Digitload does not repurpose Recipient personal data for its own independent ends (see Privacy Policy §3).
- Ensure personnel authorized to process the data are subject to confidentiality obligations.
- Implement the technical and organizational security measures described in Privacy Policy §10 (encryption in transit and at rest, domain-separated signed tokens, hashed/masked credential storage, sandboxed rendering, rate limiting).
- Taking into account the nature of the processing, assist Customer in responding to data subject requests and in fulfilling Customer's own obligations under Articles 32–36 of the GDPR (security, breach notification, DPIAs), including through the self-serve tools described in Section 6 below.
- Notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's Content or Recipient Data, providing the information reasonably available at the time and updating it as Digitload's own investigation progresses.
- Make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer — given the shared-infrastructure nature of the Services, Digitload may satisfy this by providing this DPA, the Privacy Policy, its current sub-processor list, and a written summary of security measures in lieu of an on-site audit, unless a supervisory authority requires otherwise.
4. Sub-processors
Customer authorizes Digitload to engage the sub-processors listed at mailinapp.com/subprocessors, which is the authoritative, dated record of who they are, what they do, and when each was added. Digitload will:
- Impose data protection terms on each sub-processor that are no less protective than this DPA, to the extent applicable to the service the sub-processor provides.
- Remain responsible for each sub-processor's performance of its data protection obligations.
- Give Customer reasonable advance notice — via an update to the sub-processors page and, for a material change, an email or in-app notice per Terms of Service §20 — before engaging a new sub-processor, so Customer has the opportunity to object on reasonable data-protection grounds. If Customer objects and the parties cannot resolve the objection, Customer's remedy is to stop using the feature that relies on the new sub-processor, or, for a material unresolved objection, to terminate the affected Services.
5. International transfers
Digitload and its sub-processors may process personal data outside Customer's or a Recipient's country of residence, including in Canada and the United States, as described in Privacy Policy §11. Where personal data is transferred out of the EEA, UK, or Switzerland, the transfer is governed by the applicable Standard Contractual Clauses (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor for onward sub-processor transfers, as adopted by the European Commission), incorporated into this DPA by reference and available on request at [email protected].
6. Data subject requests and Customer's own tools
Because Digitload processes Content and Recipient Data solely on Customer's instructions, Digitload will not itself respond to a data subject request from a Recipient except to route it to Customer or, where Customer is unreachable, to assist directly (Privacy Policy §7). To make this practical rather than purely manual, the Services provide:
- A working unsubscribe link on every campaign, and a "request my data be deleted or corrected" option alongside it, which creates a trackable request in Customer's own dashboard.
- Self-serve account data export and account deletion tools for Customer's own Account and Content data, available from Settings.
7. Liability
Each party's liability arising out of this DPA is subject to the limitations and exclusions set out in Terms of Service §17, applied as if this DPA were part of the Terms.
8. Return or deletion of data on termination
On termination of the Terms of Service, and on request or via the self-serve account deletion tool described in Section 6, Digitload will delete Customer's Content and Recipient Data in accordance with Privacy Policy §9 — except where retention is required by law or for the legal-obligation reasons already documented there (for example, suppression records, which are kept indefinitely so an unsubscribe or bounce continues to be honored even after other data is deleted, and fraud/accounting records such as payment disputes).
9. Precedence
If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls. For everything else, the Terms of Service and Privacy Policy control.
10. Contact
Questions about this DPA, or to request a countersigned copy or the Standard Contractual Clauses referenced in Section 5:
Digitload 330 Bay Street, Toronto, ON M5H 2S8, Canada Email: [email protected]