Purpose and scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer", acting as data controller) and Empowered Founders, operator of FlackEmail ("FlackEmail", acting as data processor).
It applies whenever FlackEmail processes personal data on your behalf to provide the service. Where this DPA conflicts with the main Terms, this DPA controls for data protection matters.
Subject matter and duration
The subject matter of the processing is the provision of the FlackEmail service to you under the Terms.
The duration of the processing matches the term of your subscription, plus any post-termination retention period set out in the Privacy Policy (currently up to 30 days for self-serve export, then deletion).
Nature and purpose of processing
FlackEmail processes personal data to host your account, store your contact lists and content, send email on your behalf, measure engagement (opens, clicks, bounces, complaints), support deliverability, prevent abuse, and provide customer support.
We do not process your subscriber data for any other purpose, and we never sell it.
Type of personal data and categories of data subjects
Personal data: email addresses, names, custom fields you choose to upload, engagement data (opens, clicks, bounces, complaints, unsubscribes), IP addresses, and message content you create.
Categories of data subjects: your subscribers, leads, customers, contacts, and end users, and any other individuals whose personal data you choose to upload.
Subprocessors
You authorise FlackEmail to engage subprocessors to provide the service (hosting, transactional email, payments, customer support tooling, error monitoring).
The current list lives at /legal/subprocessors. We notify customers in advance of material changes (additions or replacements). You may object on reasonable data protection grounds; if we cannot accommodate the objection you may terminate the affected service for a refund of any prepaid, unused fees.
Security measures
FlackEmail maintains the technical and organisational measures described in our Security page, including encryption in transit (TLS 1.2+), encryption at rest, role-based access control with least-privilege, MFA for staff access, audit logging, dependency scanning, and periodic penetration testing.
Measures evolve as the product evolves. They will not materially decrease over the term of your subscription.
Data subject requests
FlackEmail will assist you in responding to data subject requests (access, correction, deletion, restriction, portability, objection).
Where possible we provide self-serve tools in the product. For anything that needs our help, email hi@flackemail.com and we will respond within a reasonable timeframe, normally within 7 business days.
Breach notification
If FlackEmail becomes aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware.
The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned (where known), the likely consequences, and the measures we are taking or proposing.
Audit rights
Once per year and on at least 30 days written notice, you may audit FlackEmail's compliance with this DPA. Audits must happen during business hours, must not disrupt the service, and must protect our and other customers' confidentiality.
Where we can, we will satisfy audit obligations by sharing existing reports, certifications, or written responses. Onsite audits are reserved for cases where written information is genuinely insufficient.
Return or deletion at termination
On termination of the service, you can export your data from the product for up to 30 days.
After that we delete it from active systems and let it age out of backups on our standard backup cycle, except where we are legally required to keep records (for example invoices).
International transfers
Where personal data is transferred outside the EEA, the parties agree that the European Commission's Standard Contractual Clauses (SCCs) apply.
For controller-to-processor transfers, Module Two applies. For processor-to-subprocessor transfers, Module Three applies. The clauses are incorporated by reference and the data exporter is the Customer.