This Data Processing Agreement governs the processing of Personal Data by the Processor on behalf of the Controller in accordance with GDPR requirements.
The Client using MailFred's services
Modern Business Workers V.O.F., operating MailFred
This Data Processing Agreement ("DPA") is incorporated into the MailFred Terms of Service ("Agreement") and governs the processing of Personal Data by the Processor on behalf of the Controller.
Terms such as "Personal Data," "Data Subject," "Processing," "Controller," and "Processor" shall have the meanings ascribed to them in Article 4 of the GDPR.
The details of the processing activities, including subject matter, duration, purpose, and data types, are specified in Annex I of this DPA.
Processor shall only process Personal Data on the documented instructions of the Controller. Instructions may be provided via email, shared documents, or during onboarding calls.
Processor shall ensure that all personnel authorized to process the Personal Data are bound by a strict duty of confidentiality.
Processor shall implement and maintain the appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in Annex II.
Controller provides a general written authorization for Processor to engage the subprocessors listed in Annex III. Processor shall inform Controller of any intended changes to this list, thereby giving Controller the opportunity to object.
Processor shall, to the extent legally permitted, provide prompt assistance to the Controller to enable the Controller to respond to requests from Data Subjects exercising their rights under GDPR.
Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's data.
Upon termination of the Agreement and at the Controller's written request, Processor shall delete or return all Personal Data to the Controller within thirty (30) days, unless required by law to retain it.
Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 of the GDPR. Processor shall allow for and contribute to audits conducted by the Controller or a mandated auditor, upon reasonable notice and at the Controller's expense, ensuring minimal disruption to Processor's business operations.
Controller represents and warrants that it has a valid legal basis for the processing of all Personal Data provided to or sourced by the Processor and that its instructions comply with all applicable data protection laws.
The liability of each party under this DPA shall be subject to the limitations and exclusions set forth in the "Limitation of Liability" section of the main Agreement (Terms of Service).
This DPA shall be governed by Dutch law. Any disputes shall be resolved in the courts of Amsterdam, the Netherlands.
B2B cold email outreach services.
The term of the main Agreement.
Scraping, verification, personalization, and campaign management for B2B outreach on behalf of the Controller.
Business professionals identified by the Controller as potential customers or partners.
Professional contact details, including but not limited to Name, Title, Company Name, Business Email Address, and LinkedIn profile URL.
None are to be processed under this DPA.
Processor implements the following measures to protect Personal Data:
Sensitive client data is encrypted in database and all data transmission is secured over TLS.
Office premises are locked and secured against unauthorized physical access.
A plan is in place to detect, respond to, and report on security incidents and potential data breaches in a timely manner.
As of the date of this DPA, Processor is authorized to use the following subprocessors:
Purpose: AI Content Generation for Outreach
Country of Processing: USA
Purpose: Workspace for Email & Calendar Infrastructure
Country of Processing: USA / Global
Purpose: Backend Database & Infrastructure
Country of Processing: Sweden (Stockholm)
Purpose: Virtual Private Server Infrastructure
Country of Processing: Germany (Falkenstein)
Purpose: Database Services
Country of Processing: Germany (AWS Frankfurt)