Roles of the parties
For personal data contained in the mail you send (“Customer Personal Data”), you are the controller and PulsePigeon is the processor. Where you are yourself a processor for your end customer, PulsePigeon acts as a sub-processor and the same obligations apply.
Scope and instructions
PulsePigeon processes Customer Personal Data only to provide the service and only on your documented instructions, including as set out in the Terms, the console configuration, and your API calls. We will inform you if, in our opinion, an instruction infringes applicable data protection law.
Subject matter: delivery of transactional and permission-based email and related reporting and abuse-prevention. Duration: the term of the agreement plus limited retention as described. Nature and purpose: sending, delivery, suppression, and delivery analytics. Data subjects: your recipients. Data categories: email addresses, message content and metadata, and delivery events.
Confidentiality
PulsePigeon ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access it only on a need-to-know basis under least-privilege controls.
Security measures
PulsePigeon implements appropriate technical and organizational measures to protect Customer Personal Data, including:
- encryption of data in transit and at rest;
- tenant isolation and project-scoped access controls;
- server-side secret management that never exposes credentials to clients;
- access logging, monitoring, and abuse controls; and
- regular review of controls and a vulnerability-management process.
A summary of these measures is maintained on the Security page and forms the technical and organizational measures (Annex II) for this DPA.
Sub-processors
You provide general authorization for PulsePigeon to engage sub-processors to provide the service. The current sub-processors are listed on the Subprocessors page. PulsePigeon imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance.
We will give notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds, we will work with you in good faith to address the concern.
Assistance and data subject rights
Taking into account the nature of processing, PulsePigeon will assist you, by appropriate technical and organizational measures, in fulfilling your obligations to respond to data-subject rights requests and to ensure security, breach notification, and data-protection impact assessments. The console provides suppression export, data deletion, and retention controls to support this.
Personal data breach notification
PulsePigeon will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help you meet your own notification obligations.
Return and deletion
On termination, and at your choice, PulsePigeon will delete or return Customer Personal Data and delete existing copies, except where retention is required by law or, for suppression data, to prevent unlawful sending. Deletion follows the retention windows described in the Privacy Policy.
Audits
PulsePigeon will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and scope limits.
International transfers
Where PulsePigeon transfers Customer Personal Data outside the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is governed by the applicable Standard Contractual Clauses, which are incorporated into this DPA by reference and completed by the details in this document and the Subprocessors page.
Contact
To request a countersigned copy of this DPA or ask questions, contact [email protected].