Data Processing Addendum
Last updated September 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between STATUSAPP LTD ("Processor", "we") and the customer ("Controller", "you"). It applies where we process personal data about your contacts on your behalf in providing SendBeam.
1. Roles
For contact data you upload and the emails you send, you are the Controller and we are the Processor. You are responsible for the lawfulness of the data and for having a valid basis (such as consent) to email your contacts.
2. Scope and instructions
We process personal data only to provide the Service and on your documented instructions (including through your use of the product), unless required by law to do otherwise.
3. Nature of processing
- Subject matter: providing email marketing and automation.
- Data subjects: your contacts and subscribers.
- Data types: email address, name, custom fields you collect, engagement events (opens/clicks), and delivery outcomes.
4. Confidentiality and security
We ensure personnel are bound by confidentiality and we maintain appropriate technical and organisational measures, including encryption in transit, access controls, and tenant isolation.
5. Sub-processors
You authorise us to engage sub-processors to process contact data as needed. We remain responsible for their performance. The current list is published, with what each one does and where it processes, in the Privacy Policy — you do not have to ask us for it. We will give you at least 30 days' notice before adding or replacing a sub-processor, during which you may object or terminate this agreement.
6. Data subject requests
The product lets you access, export, update, unsubscribe, and delete contacts so you can respond to data subject requests. We will assist you where a request is made to us directly.
7. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your contact data, with information reasonably available to us.
8. Deletion and return
On termination you may export your data for 14 days, after which we delete it within 30 days, save for copies required by law. Backups containing it expire within 30 days of that deletion. We will confirm in writing that deletion has taken place if you ask.
Deleting a workspace withdraws access immediately and schedules permanent deletion 14 days later, so that an accidental deletion can be undone. You may instruct us to delete it at once instead, and we will. A data subject's erasure request is never deferred this way: it is carried out straight away, whether or not a deletion is pending.
Note that suppression records (unsubscribes, bounces, complaints) are retained to honour opt-outs — an address erased at a person's request keeps a one-way hash alone, which is what lets us keep honouring the opt-out without holding the address.
9. International transfers
Where contact data is transferred across borders, the parties rely on appropriate safeguards permitted by applicable data protection law.
10. Assisted onboarding and migration
Where you ask us to move contact data from another platform or to set up a workspace for you (the "Move-in" and "Setup" services), we act only on your documented written instruction: the request you submit and the scope we agree with you in writing. The work is performed by named SendBeam staff bound by confidentiality, using access that you grant (a read-only key or a temporary seat on the other platform, and access to your DNS where you choose to give it) and that you can revoke at any time. Every use of that access is logged. Suppression records are imported before any email is sent, and contacts without consent evidence are excluded rather than emailed. Working copies of imported data that we hold outside your workspace are deleted within 30 days of cutover, and you may request the migration log for the work at any time.
11. Audits and inspections
We will make available to you the information you reasonably need to demonstrate that we are meeting our obligations under this DPA and under Article 28 of the UK GDPR, and we will allow for and contribute to audits and inspections of that processing.
In the first instance we will satisfy a request by giving you our current security information and, where you use one, a completed security questionnaire. That is usually enough, and it costs you nothing. Where it is not, you may audit or inspect us, or appoint an independent auditor who is not a competitor of ours and who signs a reasonable confidentiality undertaking, on the following basis:
- once in any twelve-month period, unless a personal data breach affecting your contact data or a supervisory authority's instruction gives you cause to ask sooner;
- on at least 30 days' written notice, at a time we agree, in working hours, and without unreasonable disruption to the Service or to other customers;
- limited to the systems and records used to process your contact data — not another customer's data, and not information that would compromise the security of the Service or breach a duty we owe to someone else;
- at your cost, save that we bear our own costs of an audit that follows a personal data breach we notified to you.
Where an inspection is of a sub-processor's own infrastructure, we will use the audit rights we hold under our contract with them and pass on what we are permitted to pass on, rather than granting access we do not have.
12. Contact
Data protection queries: use the contact form and we will reply by email.