Data Processing Addendum

Baseline processing terms for customer-controlled personal data.

Effective or last updated 22 August 2026

This Data Processing Addendum (DPA) forms part of the Sendlander Terms between Pettman Consulting Limited (Processor) and the customer (Controller) when we process personal data on the customer’s behalf. Capitalised terms not defined here have the meaning in the Terms or applicable data-protection law.

1. Scope and instructions

We process personal data only to provide, secure, support, and bill for Sendlander; on documented instructions expressed through the customer’s configuration and use; or as law requires. The subject matter is email deliverability and related workflows. Processing continues for the service term and applicable deletion or retention period.

2. Data and people

Data may include business contact information, sender and recipient addresses, message and header content, authentication and domain records, product events, support content, and technical identifiers. People may include customer users, team members, senders, intended recipients, test contacts, and other people represented in customer-submitted content. The customer must minimise data and establish a lawful basis.

3. Processor duties

We will process on lawful instructions; ensure authorised personnel are subject to confidentiality; maintain reasonable technical and organisational measures appropriate to risk; inform the customer if an instruction appears unlawful where permitted; and provide reasonable information needed to demonstrate these duties.

4. Security and incidents

Measures include access control, authentication and session safeguards, credential protection, organisation separation, logging and monitoring, provider controls, operational recovery, and procedures for assessing incidents. We will notify the customer without undue delay after confirming a personal-data breach affecting its data and provide reasonably available information for required notices. Notification is not an admission of fault.

5. Subprocessors

The customer gives general authorisation for the providers on our Subprocessor List. We require subprocessors to protect personal data through applicable contractual obligations. We will post material changes. A customer may object within 14 days on reasonable data-protection grounds; if the parties cannot resolve the concern, either may end the affected feature, and our liability and refund duties remain subject to the Terms.

6. International processing

Where required, the parties will use a lawful transfer mechanism and cooperate to complete reasonable transfer documentation. This DPA does not by itself certify that every customer’s use satisfies a particular jurisdiction’s transfer requirements.

7. Requests and assessments

Taking account of the nature of processing, we will provide reasonable assistance with individual rights, breach duties, and data-protection assessments. If we receive a request concerning customer-controlled data, we may redirect it to the customer. Customer remains responsible for the decision and response.

8. Return and deletion

On account closure or written instruction, we will delete or de-identify customer personal data from active systems within a commercially reasonable period, except where law, billing, security, fraud prevention, backup cycles, or legal claims require retention. Customers should export data before closure.

9. Audit

On reasonable written request no more than once per year, we will provide available security or compliance information reasonably sufficient to demonstrate this DPA. Any further audit must be legally required, narrowly scoped, protect other customers and our confidential information, occur during business hours, avoid disruption, and be at the customer’s cost. Independent reports may satisfy an audit request.

10. Responsibility and order

Customer is responsible for notices, lawful basis, instructions, accuracy, minimisation, connected services, and its users. Liability under this DPA is subject to the exclusions and aggregate cap in the Terms to the maximum extent permitted by law. If this DPA conflicts with the Terms on processing customer personal data, this DPA controls only to that extent.

Contact

Privacy Officer, Pettman Consulting Limited · privacy@sendlander.com.