Data Processing Agreement
This DPA governs our processing of personal data on your behalf when you send email through Send by Kodar. It forms part of the Terms of Service. Here, you are the controller and we are the processor.
Last updated 19 August 2026 · Kodar Tarkvara OÜ · Tallinn, Estonia
01Roles & scope
For the recipient email addresses and message content you submit to the Service, you are the controller and Kodar Tarkvara OÜ is the processor. We process this personal data only to provide the Service and on your documented instructions (including via the API and dashboard).
02Nature of the processing
- Subject matter
- Delivering transactional email you submit.
- Duration
- For the term of your account, plus limited log retention.
- Categories of data
- Recipient email addresses; message subject, body, and headers you supply.
- Data subjects
- The recipients you choose to email.
03Our obligations
- Process personal data only on your documented instructions.
- Ensure persons authorised to process it are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Art. 32).
- Assist you, taking account of the nature of processing, with data-subject requests and with your obligations under Arts. 32–36.
- Notify you without undue delay after becoming aware of a personal-data breach.
- At your choice, delete or return all personal data at the end of the service and delete existing copies, save where EU or Member State law requires us to retain it.
- Make available all information needed to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate.
- Immediately inform you if, in our opinion, an instruction you give infringes the GDPR or other EU or Member State data-protection law.
04Subprocessors
You give general authorisation for us to engage the subprocessors below. We impose data-protection terms on them no less protective than this DPA and remain responsible for their performance. We will give notice of intended changes so you may object.
- Amazon Web Services EMEA SARL (Amazon SES)
- Outbound email delivery (last mile) — EU (eu-north-1, Stockholm)
- Neon Inc.
- Managed Postgres — message metadata and bodies, recipient addresses, delivery events, account identity and credentials — EU region; US-incorporated provider, EU Standard Contractual Clauses
- Vercel Inc.
- Hosting for the dashboard, the REST API, the event ingest and the unsubscribe endpoint — EU region; US-incorporated provider, EU Standard Contractual Clauses
- Railway Corp.
- Hosting for the worker that renders and sends each message and dispatches webhooks — US-incorporated provider, EU Standard Contractual Clauses; deployment region not yet confirmed
05International transfers
Processing takes place in the EU except where the subprocessor table above states otherwise. Where a subprocessor may transfer data outside the EEA, such transfers rely on an adequacy decision or the EU Standard Contractual Clauses.
06Security & deletion
We apply measures including encryption in transit, encryption of secrets at rest, access controls, and tenant isolation. During the term, message bodies and attachments are erased 30days after final delivery and message metadata after your plan's log window (30 days on Free, 90 days on Pro, 12 months on Scale and Enterprise). On termination we delete or, at your choice, return your workspace data — including message metadata and recipient addresses — within a reasonable period, and delete existing copies, save where retention is legally required. Tell us before termination if you want the data returned rather than deleted.