Legal

Data Processing Agreement (DPA)

Last Updated: June 28, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between BigRadar Inc ("cmdsend," "Processor," "we," "us," or "our") and the customer ("Controller," "you," or "your") and applies to the processing of Personal Data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person processed through the Services.
  • "Controller" means the entity that determines the purposes and means of processing Personal Data.
  • "Processor" means the entity that processes Personal Data on behalf of the Controller.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
  • "Services" means cmdsend's email API services as described in the Terms of Service.
  • "Sub-processor" means any third party appointed by the Processor to process Personal Data.

2. Scope and Application

This DPA applies to all processing of Personal Data by cmdsend on behalf of the Customer in connection with the Services. The subject matter, duration, nature, and purpose of the processing, as well as the types of Personal Data and categories of Data Subjects, are specified in Appendix A.

3. Roles and Responsibilities

3.1 Controller Responsibilities

The Controller shall:

  • Ensure that it has the legal basis for processing Personal Data
  • Comply with all applicable data protection laws
  • Provide necessary instructions for processing Personal Data
  • Ensure the accuracy and appropriateness of Personal Data
  • Respond to Data Subject requests and inquiries

3.2 Processor Responsibilities

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure that persons authorized to process Personal Data are subject to confidentiality obligations
  • Implement appropriate technical and organizational measures to ensure data security
  • Assist the Controller in responding to Data Subject requests
  • Assist the Controller with data protection impact assessments when required
  • Notify the Controller of any Personal Data breaches without undue delay

4. Processing Instructions

cmdsend will process Personal Data only in accordance with the Controller's documented instructions, except where required to do so by applicable law. If cmdsend believes an instruction infringes applicable data protection laws, it will promptly notify the Controller.

5. Security Measures

cmdsend implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of Personal Data in transit and at rest
  • Regular security assessments and vulnerability testing
  • Access controls and authentication mechanisms
  • Incident detection and response procedures
  • Regular backup and disaster recovery procedures
  • Employee training on data protection and security

6. Sub-processors

6.1 Authorization

The Controller provides general authorization for cmdsend to engage Sub-processors. A current list of Sub-processors is available at cmdsend.com/legal/subprocessors.

6.2 Notice and Objection

cmdsend will provide at least 30 days' notice before adding or replacing any Sub-processor. The Controller may object to a new Sub-processor on reasonable grounds relating to data protection. If an objection cannot be resolved, either party may terminate the affected Services.

6.3 Sub-processor Obligations

cmdsend will ensure that Sub-processors are bound by written agreements imposing data protection obligations substantially similar to those in this DPA. cmdsend remains fully liable for the acts and omissions of its Sub-processors.

7. Data Subject Rights

cmdsend will assist the Controller in fulfilling its obligations to respond to Data Subject requests, including requests for access, rectification, erasure, data portability, restriction of processing, and objection to processing.

8. Data Breach Notification

cmdsend will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach. The notification will include available information about the breach, its likely consequences, and measures taken or proposed to address it.

9. Data Protection Impact Assessment

cmdsend will provide reasonable assistance to the Controller in conducting data protection impact assessments and prior consultations with supervisory authorities when required by applicable data protection laws.

10. International Data Transfers

Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA). For such transfers, cmdsend implements appropriate safeguards through Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other approved transfer mechanisms.

11. Deletion and Return of Data

Upon termination of the Services, cmdsend will delete or return all Personal Data to the Controller within 30 days, unless applicable law requires continued storage. The Controller may request a copy of their data before deletion.

12. Audit Rights

cmdsend will make available to the Controller information necessary to demonstrate compliance with this DPA. On-site audits may be conducted once per year with reasonable notice and during business hours, subject to confidentiality obligations.

13. Liability and Indemnity

Each party's liability under this DPA is subject to the limitations and exclusions of liability set forth in the Terms of Service. The total liability of each party under this DPA shall not exceed the amount specified in the Terms of Service.

14. Term and Termination

This DPA remains in effect for as long as cmdsend processes Personal Data on behalf of the Controller. Provisions that by their nature should survive termination will continue in effect.

15. Governing Law

This DPA is governed by the same law as the Terms of Service, except where data protection laws require otherwise.

Appendix A: Details of Processing

Subject Matter

Email delivery and related API services

Duration

For the term of the Services agreement

Nature and Purpose

Processing of email communications, including sending, tracking, analytics, and related services as specified by the Controller

Types of Personal Data

  • Email addresses (senders and recipients)
  • Names
  • Email content and metadata (subject lines, timestamps, delivery status)
  • IP addresses
  • Device and browser information (for open/click tracking)

Categories of Data Subjects

  • Email recipients (customers, users, contacts)
  • Controller's employees and representatives
  • Other individuals as determined by the Controller

Need a Signed Copy?

If you require a signed copy of this DPA or have questions about our data processing practices, please contact us at team@cmdsend.com