Product Service featuresMobility FlexibilitySafety
Pricing SubscriptionsCredit rates
Resources Technical helpEmail software iPhone & smartphonesTroubleshooting FAQContact
Log in Create account
FREN

Overview

Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

Last updated: 6 August 2026

Processing by Spirion of the personal data provided by the Customer

The purpose of these clauses is to define the conditions under which the processor, Spirion (SAS with share capital of EUR 8,000, 149 avenue du Maine, 75014 Paris, France, Nanterre Trade and Companies Register no. 515 023 273, operator of the Service-SMTP service, hereinafter “the Processor”), undertakes to carry out, on behalf of the Customer, acting as controller, the personal data processing operations defined below.

Within the framework of their contractual relations, the parties undertake to comply with the regulations in force applicable to the processing of personal data and, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, applicable from 25 May 2018 (hereinafter “the European data protection regulation” or GDPR).

This agreement forms an integral part of the Terms of use and sale of the Service: acceptance of the Terms when placing an order implies acceptance of this agreement. A signed copy can be obtained on request from dpo@spirion.fr. In the event of any discrepancy with the French version, the French version prevails.

Article 1 - Description of the processing subject to subcontracting

The processor is authorised to process, on behalf of the controller, the personal data necessary to provide the following service(s):

Routing of emails via SMTP relay and sending API, with delivery tracking (sending reports and history).

The nature of the operations carried out on the data is: transmission of the Customer’s messages to the recipient servers; temporary storage of message content for the time of delivery (queues); logging of the sendings and of their delivery status.

The purpose(s) of the processing are:

To route the emails sent by the Customer to their recipients and to report on their delivery.

The personal data processed are:

The email addresses of the recipients and of the sender, the subject of the messages, the content of the messages (transiently, for the time of delivery), and the sending and delivery metadata (timestamp, status, recipient server).

The categories of data subjects are:

The recipients of the emails sent by the Customer through the service.

Retention periods: message content is not kept beyond delivery; detailed sending and delivery logs are kept for thirty (30) days and then automatically purged; only aggregated statistics (sending volumes) are kept beyond that period.

The data is hosted in France. No personal data is transferred outside the European Union.

Article 2 - Obligations of the processor towards the controller

The processor undertakes to:

  1. process the data only for the purpose(s) subject to the subcontracting;

  2. process the data in accordance with the documented instructions of the controller (the configuration and use of the service by the Customer constituting instructions). If the processor considers that an instruction constitutes a breach of the European data protection regulation or of any other provision of Union or Member State law relating to data protection, it shall immediately inform the controller. Furthermore, if the processor is required to transfer data to a third country or to an international organisation under Union law or the law of the Member State to which it is subject, it must inform the controller of this legal obligation before the processing, unless the law concerned prohibits such information on important grounds of public interest;

  3. guarantee the confidentiality of the personal data processed under this contract;

  4. ensure that the persons authorised to process the personal data under this contract:

    • undertake to respect confidentiality or are subject to an appropriate legal obligation of confidentiality;
    • receive the necessary training in the protection of personal data;
  5. take into account, with regard to its tools, products, applications or services, the principles of data protection by design and data protection by default;

  6. Subcontracting

    The controller authorises the processor to engage another processor (hereinafter “the sub-processor”) to carry out specific processing activities (in particular the hosting of the servers). The processor shall ensure that these sub-processors are bound by written agreements requiring them to provide at least the level of data protection required from Spirion under this agreement.

    The sub-processor is required to comply with the obligations of this contract on behalf of and in accordance with the instructions of the controller. It is the initial processor’s responsibility to ensure that the sub-processor provides the same sufficient guarantees regarding the implementation of appropriate technical and organisational measures so that the processing meets the requirements of the European data protection regulation. If the sub-processor fails to fulfil its data protection obligations, the initial processor remains fully liable to the controller for the performance by the other processor of its obligations.

  7. Right of information of data subjects

    It is the controller’s responsibility to provide information to the persons concerned by the processing operations at the time the data is collected.

  8. Exercise of data subjects’ rights

    To the extent possible, the processor must assist the controller in fulfilling its obligation to respond to requests to exercise the rights of data subjects: right of access, rectification, erasure and objection, right to restriction of processing, right to data portability, right not to be subject to an automated individual decision (including profiling).

    Where data subjects submit requests to exercise their rights to the processor, the processor must forward these requests upon receipt by email to the controller’s DPO.

  9. Notification of personal data breaches

    The processor shall notify the controller of any personal data breach within a maximum of 24 working hours after becoming aware of it, by the following means: an email to the controller’s DPO. This notification shall be accompanied by any useful documentation to enable the controller, if necessary, to notify the breach to the competent supervisory authority.

    With the controller’s agreement, the processor shall notify the competent supervisory authority (the CNIL), in the name and on behalf of the controller, of personal data breaches without undue delay and, where feasible, no later than 72 hours after becoming aware of them, unless the breach in question is unlikely to result in a risk to the rights and freedoms of natural persons.

    The notification shall contain at least:

    • a description of the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
    • the name and contact details of the data protection officer or other contact point where more information can be obtained;
    • a description of the likely consequences of the personal data breach;
    • a description of the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

    Where, and insofar as, it is not possible to provide all this information at the same time, the information may be provided in phases without undue further delay.

    With the controller’s agreement, the processor shall communicate, in the name and on behalf of the controller, the personal data breach to the data subject without undue delay, where the breach is likely to result in a high risk to the rights and freedoms of a natural person.

    The communication to the data subject shall describe, in clear and plain language, the nature of the personal data breach and shall contain at least the same elements as the notification above.

  10. Assistance of the processor in the controller’s compliance with its obligations

    The processor shall assist the controller in carrying out data protection impact assessments.

    The processor shall assist the controller in carrying out the prior consultation of the supervisory authority.

    The controller shall bear all costs and expenses incurred by the processor as a result of these assistance requests.

  11. Security measures

    The processor undertakes to implement adequate security measures for the protection of its customer’s personal data.

  12. Fate of the data

    The Customer may request the return and/or a certificate of destruction of all copies of its personal data under the control or in the possession of Spirion and of the sub-processors.

    Within 3 months of the closure of the account, the processor shall destroy all personal data processed under this agreement. This provision shall not affect any legal obligations of the parties to keep archives for the retention periods set by law or by contract. Spirion may keep electronic copies of files containing the Customer’s personal data created in accordance with automatic archiving or backup procedures which cannot reasonably be deleted. In such cases, Spirion shall ensure that the Customer’s personal data is not actively processed thereafter.

    All additional costs related to the return or deletion of personal data after the termination or expiry of the contract shall be borne by the Customer.

  13. Contact for the protection of personal data

    The processor shall at all times maintain a data protection contact responsible for assisting the Customer:

    • to respond to enquiries concerning the processing of data from data subjects;
    • and to satisfy all applicable legal obligations regarding information and disclosure associated with the data processing.

    This data protection contact can be reached directly at dpo@spirion.fr.

    Spirion’s Data Protection Officer is Loïc Bresler.

  14. Record of categories of processing activities

    The processor declares that it keeps a written record of all categories of processing activities carried out on behalf of the controller, including:

    • the name and contact details of the controller on behalf of which it acts, of any processors and, where applicable, of the data protection officer;
    • the categories of processing carried out on behalf of the controller;
    • where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1) of the European data protection regulation, the documentation of suitable safeguards;
    • where possible, a general description of the technical and organisational security measures, including inter alia, as appropriate:
      • the pseudonymisation and encryption of personal data;
      • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
      • the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
      • a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
  15. Documentation

    The processor shall make available to the controller, upon written request, the information reasonably necessary to demonstrate compliance with this agreement.

  16. Audits

    The controller, or a third-party auditor mandated by the controller, may, upon written request, inspect the processing activities carried out by Spirion on its personal data to the extent necessary under EU data protection laws, without interrupting Spirion’s business activities and while preserving confidentiality. The controller shall bear all costs and expenses incurred by the processor as a result of the exercise of these audit rights.

Article 3 - Obligations of the controller towards the processor

The data controller accepts and warrants the following:

  • the processing, including the actual transfer of the personal data, has been and will continue to be carried out in accordance with the relevant provisions of the applicable data protection law and does not infringe the relevant provisions of that State;
  • it has instructed, and will instruct throughout the duration of the personal data processing services, the processor to process the personal data transferred on the sole behalf of the data controller and in accordance with the applicable data protection law and these clauses;
  • it will ensure compliance with the security measures;
  • it will forward any notification received from the processor or from any sub-processor to the data protection supervisory authority if it decides to continue the transfer or to suspend it;
  • it will make available to the data subjects, upon request, a copy of these clauses and a summary description of the security measures, as well as a copy of any sub-processing contract concluded in accordance with these clauses, unless the clauses or the contract contain commercial information, in which case it may remove such information.