Parties

This data processing agreement ("Agreement") is part of the service agreement ("Main Agreement") between:

  1. The Customer: the natural or legal person who holds an account with Xendy and makes use of the Service, hereinafter "Controller" or "Customer"; and
  2. Xendy BV, established at Oostervelden 62, 6681 WZ Bemmel, the Netherlands, registered with the Chamber of Commerce under number 72086416, hereinafter "Processor" or "Xendy".

Recitals

  • Xendy provides an email marketing platform that enables the Customer to manage contacts, send email campaigns and automations, and measure results ("Service").
  • In providing the Service, Xendy processes personal data of the Customer's contacts on behalf of the Customer. The Customer is the Controller; Xendy is the Processor within the meaning of Article 4(8) of the General Data Protection Regulation ("GDPR").
  • The parties hereby record their arrangements regarding this processing, as required by Article 28(3) GDPR.

Article 1 - Definitions

Terms such as "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them by the GDPR. "Annex" refers to the annexes to this Agreement, which form an integral part thereof.

Article 2 - Subject Matter and Duration

2.1. Xendy processes personal data on behalf of the Customer as described in Annex 1, solely for the purpose of providing the Service.

2.2. This Agreement remains in force for as long as the Main Agreement is in force and, additionally, for as long as Xendy holds personal data of the Customer.

2.3. In the event of a conflict between this Agreement and the Main Agreement, this Agreement shall prevail to the extent that it concerns the processing of personal data.

Article 3 - Instructions and Scope of Processing

3.1. Xendy processes personal data solely on the basis of written instructions from the Customer. Use of the Service (including the creation of campaigns, automations, segments, and integrations via the dashboard or the API) constitutes such an instruction.

3.2. Xendy does not use personal data for its own purposes and does not disclose it to third parties, except to sub-processors in accordance with Article 8, at the initiative of the Customer itself (Article 8.4), or where a legal obligation so requires. In the latter case, Xendy shall inform the Customer in advance of that obligation, unless prohibited by law.

3.3. If Xendy considers that an instruction infringes the GDPR or other privacy legislation, it shall notify the Customer thereof without delay and may suspend execution of the instruction until it has been amended or confirmed.

Article 4 - Confidentiality

4.1. Xendy shall keep the personal data confidential. Access is restricted to employees and auxiliary persons for whom access is necessary for the provision of the Service.

4.2. Everyone who has access to the personal data under the authority of Xendy is bound by a duty of confidentiality pursuant to a contractual or statutory obligation.

Article 5 - Security

5.1. Xendy shall implement appropriate technical and organisational measures as referred to in Article 32 GDPR to protect personal data against loss and against unlawful processing. The current measures are described in Annex 2.

5.2. Xendy may adapt the measures to keep pace with the state of the art, provided that the level of protection does not deteriorate.

5.3. The Customer is solely responsible for the secure use of the Service on its end, including the management of user accounts, passwords, API keys and integrations activated by the Customer.

Article 6 - Personal Data Breaches

6.1. Xendy shall inform the Customer without undue delay, and no later than 48 hours after discovery, of a personal data breach that (potentially) relates to the Customer's personal data.

6.2. The notification shall contain at least: the nature of the breach, the (presumably) affected categories of data subjects and data, the likely consequences, and the measures taken or proposed. Information that is not yet available shall be provided by Xendy afterwards without undue delay.

6.3. The Customer shall assess independently whether notification to the supervisory authority and/or data subjects is required and shall carry out such notification itself. Xendy shall provide reasonable cooperation in this regard.

6.4. Xendy shall document personal data breaches in accordance with Article 33(5) of the GDPR.

Article 7 - Assistance and Obligations of the Customer

7.1. Xendy shall provide the Customer with reasonable assistance in responding to requests from data subjects (access, rectification, erasure, objection, portability). Where possible, the Service facilitates this directly, including through unsubscribe links, contact management, and export.

7.2. If Xendy receives a request directly from a data subject, it shall refer the data subject to the Customer, except in the case of unsubscribe requests for email, which the Service processes automatically.

7.3. Xendy shall provide reasonable assistance with data protection impact assessments (DPIAs) and prior consultations, to the extent that these relate to the Service.

7.4. The Customer warrants that it has a valid legal basis for the processing, that data subjects have been informed, and that the provision of personal data to Xendy is lawful.

Article 8 - Sub-processors

8.1. The Customer grants Xendy general authorisation to engage sub-processors. The current sub-processors are listed in Annex 3.

8.2. Xendy imposes obligations on each sub-processor that offer at least the same level of protection as this Agreement.

8.3. Xendy remains fully liable to the Customer for the performance of its sub-processors.

8.4. The following are not sub-processors: parties that receive or provide data on the initiative of the Customer itself, such as e-commerce integrations (including Lightspeed, WooCommerce, Shopify, Magento), webhooks configured by the Customer, and AI assistants that the Customer connects to their own account via the MCP integration (including Claude, ChatGPT, Cursor). The Customer is responsible for their choice of and arrangements with those parties.

Article 9 - Transfer Outside the EEA

9.1. Xendy processes personal data principally within the European Economic Area. Processing outside the EEA takes place only via a sub-processor listed in Annex 3 and exclusively on the basis of a valid transfer mechanism within the meaning of Chapter V GDPR (adequacy decision, EU-US Data Privacy Framework, or standard contractual clauses), supplemented by additional safeguards where necessary.

Article 10 - Audit and Accountability

10.1. Xendy shall, upon request, make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including Annex 2 and the current sub-processor overview.

10.2. The Customer may, at most once per year, with a notice period of 30 days, have an audit conducted by an independent expert bound by confidentiality. The audit is limited to the processing under this Agreement, disrupts business operations as little as possible, and does not provide access to data of other customers. Each party bears its own costs; disproportionate efforts on the part of Xendy may be charged at reasonable cost.

Article 11 - Liability

11.1. Starting point: the limitation of liability from the Main Agreement also applies to this Agreement, without prejudice to the mandatory allocation of liability under Article 82 GDPR.

Article 12 - Return and Deletion

12.1. During the term, the Customer may export the personal data at any time via the Service.

12.2. Following the termination of the Main Agreement, Xendy will delete all personal data of the Customer within 90 days, unless a statutory retention obligation precludes this. Upon request, made prior to the expiry of that period, Xendy will first provide an export.

12.3. Back-ups in which the data still appear will be overwritten within 90 days in accordance with the regular rotation schedule; the data will no longer be restored from back-ups.

Article 13 - Final Provisions

13.1. This Agreement is governed by Dutch law. Disputes shall be submitted to the competent court as designated under the Main Agreement.

13.2. Xendy may amend this Agreement in the event of changes in legislation or the Service; material amendments will be announced at least 30 days in advance.

Annex 1 - Description of the processing

Subject and purpose: the provision of email marketing services: storing and managing contacts, composing and sending email campaigns and automations, measuring results (including opens, clicks and revenue) and facilitating integrations activated by the Customer.

Nature of the processing: storing, structuring, consulting, using for sending, analysing (statistics), transferring to sub-processors, erasing.

Duration: the term of the Main Agreement, plus the deletion period of Article 12.

Categories of data subjects:

  • Contacts/subscribers registered or imported by the Customer
  • Customers of the Customer (in the case of e-commerce integrations)
  • Visitors to the Customer's website or webshop (in the case of shopping cart and visitor tracking)

Categories of personal data:

  • Identification and contact data: name, email address and any additional fields provided by the Customer (for example telephone number or address)
  • Interaction data: open and click behaviour, sending and delivery status, bounces, complaints, unsubscribes
  • Order data (in the case of e-commerce integrations): ordered products, amounts, order dates
  • Website interaction (in the case of tracking): IP address, pages viewed, shopping cart contents, browser data
  • Segment and preference data recorded by the Customer

Annex 2 - Technical and Organisational Measures

  • Encryption of personal data in transit (TLS); encryption of data at rest
  • Daily backups
  • Access security: role-based access within the application, two-factor authentication for user accounts, personal accounts for employees
  • Network segregation: databases are not directly accessible from the internet
  • Logging of API and account activity (activity log); audit logging with masking of sensitive parameters
  • Security principles: security-by-design and security-by-default; application of ISO 27001 standards
  • Rate limiting and abuse detection on public endpoints
  • Confidentiality obligations for all employees with access
  • Deletion procedures upon termination of the Agreement (Article 12)

Annex 3 - Sub-processors of Xendy

Xendy BV (Chamber of Commerce no. 72086416) engages the sub-processors listed below for the provision of its email marketing services. Arrangements have been made with each sub-processor that offer at least the same level of protection as the data processing agreement (DPA) between you and Xendy. Where processing takes place outside the European Economic Area (EEA), this is done on the basis of a valid transfer mechanism (adequacy decision, EU-US Data Privacy Framework, or standard contractual clauses).

Sub-processorRegistered officeServicePersonal dataProcessing location
TransIP B.V.Vondellaan 47, 2332 AA Leiden, the NetherlandsHosting of the Xendy application and databasesAll data in your Xendy account: contact data, order data, delivery and interaction statisticsthe Netherlands (EEA)
Amazon Web Services EMEA SARL, Dutch BranchMr. Treublaan 7, 1097 DP Amsterdam, the NetherlandsSending of email campaigns (Amazon SES) and processing of bounce and complaint notifications (Amazon SNS)Email address and name of recipients, sender data, email content, bounce/complaint statusAWS region Frankfurt, Germany (eu-central-1, EEA)
DigitalOcean, LLCNew York, United StatesStorage and delivery of uploaded images (media library, email images, logos)Images and files uploaded by youData center Amsterdam, the Netherlands (AMS3); vendor established in the US
OpenAIOpenAI Ireland Ltd., Dublin, Ireland (EEA contracting party)AI-assisted features: analysis of aggregated revenue statistics, generation of segment descriptions, website and brand identity analysisAggregated statistics, segment rules and website content; no email addresses or contact data of your contactsUnited States
Google Ireland Ltd. (Google Fonts)Gordon House, Barrow Street, Dublin, IrelandLoading of fonts in the email editor and when rendering emailsIP address and browser data of users and email recipients when loading fontsEU / United States

Transfers at your own initiative (not sub-processors)

Some data flows arise because you yourself activate an integration. Xendy is not a sub-processor in such cases; the party of your choosing receives the data on your instructions:

  • E-commerce integrations (Lightspeed, WooCommerce, Shopify, Magento, product feeds): Xendy retrieves customer, order and product data from your own system using the access credentials provided by you.
  • Webhooks: Xendy sends events to URLs that you configure yourself.
  • AI assistants via MCP (Claude, ChatGPT, Cursor): if you connect your Xendy account to an AI assistant, the requested data flows to the provider of that assistant.

Changes

Xendy will announce the addition or replacement of sub-processors at least 30 days in advance via the helpdesk and/or email. You may raise a written objection within that period; Article 8 of the data processing agreement (DPA) describes the procedure.

Joeri Ras

Written by

Joeri Ras

Founder & co-owner @ Xendy

Prefer to talk directly?

Related articles