This Data Processing Agreement ("DPA") applies where Letter Mail, Inc. ("Letter", "Processor") processes personal data on behalf of a business customer ("Controller") in the course of providing the Service. It forms part of our Terms of Service. A signed copy is available to business customers on request.
1. Scope and roles
The Controller determines the purposes and means of processing; Letter processes personal data only on the Controller's documented instructions, including as set out in the Terms and this DPA.
2. Subject-matter and details of processing
- Subject-matter: provision of the Letter email service.
- Duration: for the term of the subscription.
- Nature and purpose: hosting, transmitting, storing and securing email and account data.
- Types of data: account identifiers, email content and metadata, usage logs.
- Data subjects: the Controller's authorised users and their correspondents.
3. Confidentiality
Letter ensures that personnel authorised to process personal data are bound by confidentiality obligations.
4. Security
Letter implements appropriate technical and organisational measures as described on our Security page, taking account of the state of the art and the risks of processing.
5. Subprocessors
The Controller authorises Letter to engage subprocessors (such as cloud hosting and payment providers) under written contracts imposing equivalent data-protection obligations. We will inform the Controller of intended changes and give an opportunity to object.
6. Data-subject requests
Letter will assist the Controller, so far as reasonably possible, in responding to requests from data subjects to exercise their rights.
7. Personal-data breaches
Letter will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, and will provide information reasonably required to meet the Controller's own notification obligations.
8. Audits
Letter will make available information necessary to demonstrate compliance with this DPA and allow for reasonable audits, subject to confidentiality and security safeguards.
9. International transfers
Where the DPA involves transfers of EEA, UK or Swiss data, the parties incorporate the applicable Standard Contractual Clauses.
10. Deletion or return of data
On termination, Letter will, at the Controller's choice, delete or return the personal data and delete existing copies, unless retention is required by law.
Contact
To request a countersigned DPA, email privacy@letter.click.
← Back to letter.click