Legal · Updated 2026-04-01
Data Processing Agreement.
Pre-signed DPA, current sub-processor list, and security overview. Enterprise customers can request a counter-signed version with custom terms.
Sub-processors
| Vendor | Purpose | Region |
|---|---|---|
| EU cloud provider | Cloud hosting & object storage | EU |
| Resend | Transactional email | US |
| Cloudflare | Bot protection and CDN | Global |
Security overview
- Strict access controls with least-privilege for production systems.
- Customer data hosted in the EU (EU data residency).
- Data encrypted in transit (TLS 1.3) and at rest (AES-256).
- Mandatory 2FA for all employees with production access.
- Regular security reviews of application code and dependencies.
- Incident response: customers notified within 72 hours per GDPR Art. 33.
Sub-processor changes
We will notify customers at least 30 days before adding or replacing a sub-processor. You may object during that window.
Contact
Reach our Data Protection Officer through the contact page — choose “Customer support” and we'll route to the DPO.
Email signatures, finally treated as the brand asset they are.
Book a demo