1. Parties and roles
This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer (“Controller”) and Barrzen (“Processor”) for the Barrzen Email service. The Customer determines the purposes and means of processing. Barrzen processes personal data only on documented instructions from the Customer, unless required by Union or Member State law.
- Processor legal name: [TO BE COMPLETED]
- Processor registered address: [TO BE COMPLETED]
- Processor privacy / DPO contact: [TO BE COMPLETED]
- Controller legal name: [TO BE COMPLETED]
- Controller address / contact: [TO BE COMPLETED]
2. Subject matter and duration
Barrzen provides managed email services including business mailboxes, transactional sending (SMTP/API), marketing campaigns, delivery logs, and related support. Processing continues for the term of the service agreement and any retention period required by law or documented in Annex II.
Governing law / venue: [TO BE COMPLETED]
3. Nature and purpose of processing
Processing includes storage, transmission, authentication, logging, spam/abuse filtering, backup, support access, and deletion/return of personal data as needed to deliver Barrzen Email on the Customer’s instructions and to maintain the security and integrity of the service.
4. Categories of data subjects and personal data
Typical categories (to be confirmed in Annex II for each Customer):
- Customer personnel and mailbox users
- End users / customers of the Controller who receive transactional or marketing email
- Contacts stored for campaign and automation purposes
Typical personal data: names, email addresses, message content and attachments, IP addresses, device/client metadata, delivery/engagement events, authentication records, and support communications.
5. Documented instructions and purpose limitation
The Processor shall process personal data only for the specific purposes set out in this DPA and Annex II, and only on documented instructions from the Controller. If the Processor believes an instruction infringes the GDPR or other Union/Member State data-protection law, it shall inform the Controller without undue delay.
6. Confidentiality
The Processor shall ensure that persons authorised to process personal data are bound by confidentiality (contractual or statutory) and grant access only to personnel who need it to perform the contract.
7. Security of processing
Taking into account the state of the art, implementation costs, nature, scope, context, and purposes of processing, as well as risks to data subjects, the Processor shall implement appropriate technical and organisational measures as summarised in Annex III, including measures to protect against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
Confirmed EU hosting regions / data centres: [TO BE COMPLETED]
8. Sub-processors
The Processor shall not engage a sub-processor without the Controller’s prior general or specific written authorisation as selected below. Where a sub-processor is engaged, the Processor shall impose equivalent data-protection obligations and remain liable to the Controller for the sub-processor’s performance.
Authorisation model: [TO BE COMPLETED: prior specific / general written authorisation]
Advance notice period for changes: [TO BE COMPLETED]
Authorised sub-processors are listed in Annex IV.
9. International transfers
Barrzen Email is designed for 100% EU hosting and processing of customer mail data. Any transfer of personal data to a third country shall occur only on documented instructions from the Controller or where required by Union/Member State law, and only with an appropriate Chapter V transfer mechanism (for example Standard Contractual Clauses).
Transfer mechanism / notes: [TO BE COMPLETED — typically “no transfers outside the EEA” or named SCCs]
10. Assistance with data-subject rights
Taking into account the nature of processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise data-subject rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection, and related rights).
11. Personal data breach assistance
In the event of a personal data breach concerning data processed by the Processor, the Processor shall notify the Controller without undue delay after becoming aware of the breach, and cooperate so the Controller can meet Articles 33 and 34 GDPR where applicable.
Breach notification target / contact: [TO BE COMPLETED]
Target timeframe: [TO BE COMPLETED]
12. Audits and compliance information
The Processor shall make available information necessary to demonstrate compliance with this DPA and contribute to audits or inspections by the Controller or an auditor mandated by the Controller, at reasonable intervals and with reasonable notice, subject to confidentiality and security requirements.
13. Deletion or return of data
At the end of the provision of services, the Processor shall, at the choice of the Controller, delete or return all personal data processed on behalf of the Controller, and delete existing copies unless Union or Member State law requires storage. Retention defaults are documented in Annex II.
Default retention schedule: [TO BE COMPLETED]
14. Termination
Without prejudice to any provision of the GDPR, if the Processor is in breach of its obligations under this DPA, the Controller may instruct the Processor to suspend processing until compliance is restored, or terminate the processing aspects of the service agreement in line with the Commission controller–processor clauses.
Annex I — List of parties
Controller
- Name: [TO BE COMPLETED]
- Address: [TO BE COMPLETED]
- Contact person / DPO: [TO BE COMPLETED]
- Signature / accession date: [TO BE COMPLETED]
Processor (Barrzen)
- Name: [TO BE COMPLETED]
- Address: [TO BE COMPLETED]
- Contact person / DPO: [TO BE COMPLETED]
- Signature / accession date: [TO BE COMPLETED]
Annex II — Description of the processing
- Categories of data subjects: [TO BE COMPLETED]
- Categories of personal data: [TO BE COMPLETED]
- Sensitive data (if any) and safeguards: [TO BE COMPLETED]
- Nature of processing: hosting, transmission, logging, support, deletion/return
- Purpose(s): provision of Barrzen Email on Controller instructions
- Duration: service term + [TO BE COMPLETED]
Annex III — Technical and organisational measures
Concrete measures to be confirmed for the production environment (examples of categories required under Decision (EU) 2021/915 Annex III):
- Encryption of personal data in transit and at rest: [TO BE COMPLETED]
- Access control, authentication, and authorisation: [TO BE COMPLETED]
- Logging, monitoring, and incident response: [TO BE COMPLETED]
- Backup, restore, and resilience: [TO BE COMPLETED]
- Physical security of processing locations: [TO BE COMPLETED]
- Data minimisation, retention, and erasure: [TO BE COMPLETED]
- Regular testing/assessment of security measures: [TO BE COMPLETED]
Annex IV — List of sub-processors
The Controller authorises the following sub-processors (update before signature; notify Controllers of changes per Section 8):
- Name / address / contact: [TO BE COMPLETED]
Processing description / location: [TO BE COMPLETED] - Name / address / contact: [TO BE COMPLETED]
Processing description / location: [TO BE COMPLETED]
15. Related documents
See also ourPrivacy Policyand theBarrzen Email service page. To request a completed and signed DPA, contactsales.
