sendqube

Data Processing Addendum

Last updated: August 19, 2026

This is Sendqube's standard Data Processing Addendum. It's incorporated by reference into our Terms of Service and applies automatically to any workspace processing personal data through the Service. It isn't a substitute for your own legal review — if your organization needs negotiated terms, talk to your legal team first.

1. Definitions

  • "Agreement" means Sendqube's Terms of Service, which this DPA is incorporated into and forms part of.
  • "Customer" means the workspace/organization using the Service, acting as data controller for the personal data described below.
  • "Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Sub-processor" have the meanings given in the GDPR (Regulation (EU) 2016/679), and the equivalent terms under other applicable data protection laws.
  • "Service" means the Sendqube platform as described in the Agreement.

2. Scope and Roles

This DPA applies where Sendqube processes personal data on Customer's behalf as a processor, in the course of providing the Service — specifically, the contacts Customer uploads and emails through Sendqube, and the content of the resulting communications.

For Customer's own account data — names, emails, workspace, and billing details of Customer's users — Sendqube acts as an independent controller, as described in the Privacy Policy.

3. Processing on Instructions

Sendqube will process personal data only to provide the Service and only on Customer's documented instructions — including instructions given through Customer's use of the Service's features (sending sequences, tracking engagement, managing contacts, and honoring unsubscribes) — unless required to do otherwise by law, in which case Sendqube will inform Customer of that legal requirement first, unless the law prohibits this.

4. Confidentiality

Sendqube ensures that personnel authorized to process personal data have committed to confidentiality obligations, whether contractual or statutory, and that access is limited to what's necessary to provide the Service.

5. Security Measures

Sendqube implements appropriate technical and organizational measures to protect personal data, including encryption at rest and in transit, access controls limited to authorized personnel, and daily backups. Full detail is in the Security Safeguards section of our GDPR page.

6. Sub-processors

Customer generally authorizes Sendqube to engage sub-processors to provide the Service. The current list, and what each one does, is published at sendqube.in/sub-processors. Sendqube imposes data protection obligations on each sub-processor materially equivalent to those in this DPA, and remains liable for their performance.

We keep the published list current as sub-processors are added or removed. Customers with questions about a specific sub-processor can reach us at dev@sendqube.in.

7. Assistance with Data Subject Rights

Taking into account the nature of the processing, Sendqube will reasonably assist Customer in responding to requests from data subjects exercising their rights under applicable data protection law — primarily through the account and contact management, export, and deletion features already built into the Service, and directly where those features aren't sufficient.

8. Personal Data Breach Notification

Sendqube will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data, and will provide the information reasonably available at the time to help Customer meet its own notification obligations, updating that information as the investigation progresses.

9. Return and Deletion of Data

On termination of the Agreement, Sendqube will delete Customer's data within a reasonable period, except where retention is required for legal, accounting, or security reasons — see the Privacy Policy for the full retention schedule. Customers who need to export their data first can do so directly from the product before closing their account.

10. Audit Rights

Sendqube will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer — subject to reasonable advance notice, confidentiality, and no more than once per year absent a specific compliance concern.

11. International Data Transfers

Where personal data is transferred outside the data subject's region, Sendqube relies on its hosting and infrastructure providers' own compliance frameworks and standard contractual safeguards — including Standard Contractual Clauses where applicable — to protect that data in transit and at rest.

12. Liability

Liability under this DPA is governed by the liability provisions of the Agreement. This DPA does not create additional or separate liability beyond what the Agreement already provides.

13. Term

This DPA takes effect when Customer starts using the Service to process personal data, and remains in effect for as long as the Agreement does, or until Sendqube no longer processes personal data on Customer's behalf, whichever is later.

14. Governing Law

This DPA is governed by the same governing law as the Agreement, as set out in the Terms of Service.

Questions about this DPA? Email dev@sendqube.in.