Data Processing Addendum
Last updated: 19 July 2026
This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the agreement between Valkari Limited trading as Sendblox ("Sendblox") and the customer that is party to the applicable agreement for the Services ("Customer").
This DPA applies where and to the extent Sendblox processes Customer Personal Data on behalf of Customer as a processor in connection with the Services.
1. Definitions
In this DPA, unless the context requires otherwise:
“Agreement" means the agreement between Sendblox and Customer governing Customer's use of the Services.
"Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the UK GDPR, the EU GDPR, the Data Protection Act 2018 and any implementing or supplementary legislation.
"Customer Personal Data" means any Personal Data contained in Customer Content that Sendblox processes on behalf of Customer in connection with the Services.
"Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates.
"Data Subject Request" means a request made by a Data Subject to exercise rights under Applicable Data Protection Laws.
"EU GDPR" means Regulation (EU) 2016/679.
"GDPR" means, as applicable, the EU GDPR and/or the UK GDPR.
"Personal Data", "Controller", "Processor", "Process" and "Processing" have the meanings given to them in the GDPR.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data processed by Sendblox.
"Restricted Data" means:
- special category personal data;
- criminal convictions or offences data;
- children's data;
- payment card data;
- government-issued identification numbers;
- passwords or highly sensitive access credentials;
- health or medical information; or
- other highly sensitive personal data not reasonably required for the Services,
unless expressly agreed in writing by Sendblox and supported by appropriate safeguards.
"Services" means the Sendblox Platform and related services provided under the Agreement.
"Sub‑Processor" means any third party appointed by or on behalf of Sendblox to process Customer Personal Data on behalf of Customer in connection with the Services.
"UK GDPR" means the EU GDPR as it forms part of the law of the United Kingdom.
"UK Transfer Tool" means the UK International Data Transfer Agreement and/or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
Any capitalised term not defined in this DPA has the meaning given to it in the Agreement.
2. Scope and roles
2.1 Scope
This DPA applies only to the processing of Customer Personal Data by Sendblox as a processor on behalf of Customer.
2.2 Roles
The parties acknowledge and agree that:
- Customer is the controller of Customer Personal Data, except where Customer acts as a processor on behalf of another controller; and
- Sendblox is the processor of Customer Personal Data.
2.3 Sendblox controller activities excluded
This DPA does not apply to personal data that Sendblox processes as a controller for its own business purposes, including for:
- website operations;
- account administration;
- billing and contract management;
- support relationship management;
- service security and fraud prevention;
- legal and regulatory compliance;
- Sendblox's own business analytics and service improvement.
3. Customer instructions
3.1 Documented instructions
Sendblox will process Customer Personal Data only:
- on Customer's documented instructions, including as set out in the Agreement, this DPA and Customer's use and configuration of the Services; or
- as required by applicable law, in which case Sendblox will inform Customer of that legal requirement before processing unless prohibited by law.
3.2 Lawfulness of instructions
Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Laws.
3.3 Unlawful instructions
If Sendblox reasonably believes that an instruction infringes Applicable Data Protection Laws, Sendblox may notify Customer and suspend the affected processing until Customer confirms or modifies the instruction.
4. Confidentiality
Sendblox will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
5. Security
5.1 Security measures
Sendblox will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the nature of the processing and the risks involved.
5.2 Annex 2
The categories of technical and organisational measures maintained by Sendblox are described in Annex 2.
5.3 Updates
Sendblox may update its security measures from time to time, provided that such updates do not materially reduce the overall level of security of the Services.
6. Sub-processing
6.1 General authorisation
Customer generally authorises Sendblox to engage Sub‑Processors in connection with the provision of the Services.
6.2 Sub-processor list
Information about Sendblox's Sub‑Processors, including their functions and processing regions, is available on Sendblox's Sub‑processor page.
6.3 Changes to Sub-Processors
Sendblox may add, replace or remove Sub‑Processors from time to time. Sendblox will provide notice of material changes by updating the Sub‑processor page and/or by other reasonable means, such as account notice, email or subscription notification.
6.4 Objections
If Customer reasonably objects to a new Sub‑Processor on genuine data protection grounds, Customer must notify Sendblox in writing within 14 days of the relevant notice.
6.5 Sendblox response to objections
If Customer raises a reasonable objection, Sendblox may:
- provide additional information about the Sub‑Processor and safeguards in place;
- use commercially reasonable efforts to offer an alternative configuration, workaround or replacement service that avoids the objected-to Sub‑Processor where feasible; or
- suspend the affected feature or functionality.
6.6 Termination right
If Sendblox cannot reasonably accommodate Customer's objection, Customer may terminate the affected Services, or the Agreement if the affected Services cannot reasonably be separated. This is Customer's sole and exclusive remedy in relation to objections to a new Sub‑Processor.
6.7 Flow-down obligations
Sendblox will impose data protection obligations on its Sub‑Processors that are no less protective, in substance, than those set out in this DPA to the extent applicable to the services performed by those Sub‑Processors.
6.8 Liability
Sendblox remains responsible for the acts and omissions of its Sub‑Processors to the extent required by Applicable Data Protection Laws.
7. Assistance with data subject rights
Taking into account the nature of the processing, Sendblox will provide reasonable assistance to Customer to help Customer respond to Data Subject Requests relating to Customer Personal Data.
If Sendblox receives a Data Subject Request relating to Customer Personal Data, Sendblox will promptly notify Customer and will not respond directly except on Customer's documented instructions or as required by law.
8. Personal Data Breaches
8.1 Notification
Sendblox will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 Information provided
To the extent available, Sendblox will provide information reasonably necessary to help Customer understand the nature of the Personal Data Breach and meet its own obligations under Applicable Data Protection Laws.
8.3 No admission
Notification of a Personal Data Breach does not constitute an admission of fault or liability.
9. Assistance with compliance
Taking into account the nature of the processing and the information available to Sendblox, Sendblox will provide reasonable assistance to Customer with:
- security of processing obligations;
- breach notification obligations;
- data protection impact assessments; and
- consultations with supervisory authorities,
to the extent required under Applicable Data Protection Laws and relevant to Sendblox's processing of Customer Personal Data.
10. Audits and information
10.1 Information rights
Sendblox will make available to Customer such information as is reasonably necessary to demonstrate compliance with this DPA.
10.2 Audit rights
Where reasonably required, Customer may request an audit or inspection relating to Sendblox's processing of Customer Personal Data, subject to reasonable prior notice, confidentiality obligations and appropriate scope limitations.
10.3 Alternatives
Sendblox may satisfy audit obligations by providing recent third-party audit reports, certifications, summaries or equivalent assurance materials where these reasonably address the subject matter of the request.
11. International transfers
Sendblox will not transfer Customer Personal Data to a country outside the UK or EEA unless the transfer is protected by an appropriate lawful transfer mechanism under Applicable Data Protection Laws, including where applicable:
- an adequacy decision;
- the EU Standard Contractual Clauses;
- the UK Transfer Tool; or
- another valid transfer mechanism.
To the extent required, the relevant transfer terms are incorporated by reference into this DPA.
12. Deletion and return
Upon termination or expiry of the Agreement, Sendblox will, at Customer's choice and subject to the Agreement:
- return Customer Personal Data to Customer; or
- securely delete Customer Personal Data,
unless applicable law requires retention.
Where immediate deletion from backup systems is not technically feasible, Sendblox may retain Customer Personal Data in backups until routine deletion or overwrite occurs, provided the data remains protected and is not actively processed except as required for backup or legal purposes.
13. Customer responsibilities
Customer is responsible for:
- the legality of Customer Personal Data and the means by which it was obtained;
- determining the lawful basis for processing Customer Personal Data;
- providing any required notices to Data Subjects;
- obtaining any required consents;
- ensuring its instructions comply with Applicable Data Protection Laws;
- ensuring Restricted Data is not submitted unless expressly agreed by Sendblox.
14. Liability
This DPA is subject to the exclusions and limitations of liability set out in the Agreement, unless Applicable Data Protection Laws require otherwise.
15. Changes to this DPA
Sendblox may update this DPA from time to time to reflect changes in law, regulation, guidance or the Services, provided that such changes do not materially reduce Customer's rights in relation to the processing of Customer Personal Data.
Annex 1 – Details of Processing
A. Subject matter
Processing of Customer Personal Data in connection with the provision of the Sendblox Platform and related services.
B. Duration
For the duration of the Agreement and any period thereafter during which Sendblox retains Customer Personal Data in accordance with the Agreement, this DPA and applicable law.
C. Nature and purpose of the processing
The processing may include collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission, alignment, analysis, restriction, deletion and destruction of Customer Personal Data as necessary to provide the Services.
Purposes may include:
- providing customer-requested outreach and communication workflows;
- enabling uploads, integrations and connected data use;
- supporting campaign delivery, tracking and reporting;
- customer support, troubleshooting and service administration;
- service security, integrity and operational support.
D. Categories of Data Subjects
Depending on Customer's use of the Services, Data Subjects may include:
- prospects, leads and recipients of customer communications;
- Customer's employees, users, administrators and contractors;
- Customer's clients, business contacts, suppliers and other professional contacts;
- individuals whose personal data is included in Customer Content.
E. Categories of Customer Personal Data
Depending on Customer's use of the Services, Customer Personal Data may include:
- names;
- business contact details;
- email addresses;
- job titles and employer information;
- CRM and account data;
- message content and communication metadata;
- campaign settings and response data;
- usage and service records connected to Customer's use of the Services;
- other personal data submitted by or on behalf of Customer.
Annex 2 – Security Measures
Sendblox implements and maintains technical and organisational measures designed to protect Customer Personal Data, including measures in the following categories:
1. Organisational measures
- internal security and access governance;
- staff confidentiality obligations;
- role-based access allocation;
- security awareness and relevant training.
2. Access controls
- authentication measures for relevant systems;
- least-privilege access principles;
- access review and revocation processes.
3. Systems and network security
- network and infrastructure protections;
- logging and monitoring;
- vulnerability management and patching processes;
- malware protection and related safeguards.
4. Data protection measures
- encryption in transit where appropriate;
- encryption at rest or equivalent safeguards where appropriate;
- logical separation of customer data;
- secure deletion practices.
5. Incident response and resilience
- incident detection and response procedures;
- breach escalation and investigation processes;
- backup, resilience and business continuity measures.
6. Physical and vendor security
- use of reputable infrastructure and service providers;
- physical and environmental protections at hosted environments as applicable through Sendblox or its infrastructure providers.