Data Processing Addendum
Effective September 20, 2026 · Astra Innovations LLC, Sanford, Florida, USA
Version 2026-09-20. This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between Astra Innovations LLC, a Florida limited liability company of Sanford, Florida, USA (“InBuzzed”, “Processor”) and the customer that accepts those Terms (“Customer”, “Controller”). It governs the processing of Personal Data by InBuzzed on Customer’s behalf in connection with the InBuzzed email operations platform (the “Service”).
By accepting the Terms, Customer accepts this DPA. No signature is required; Customer may request a countersigned copy by emailing support@inbuzzed.com.
Contents
- 1. Definitions
- 2. Roles of the parties
- 3. Details of the processing
- 4. Processor obligations
- 5. Security
- 6. Subprocessors
- 7. Data subject requests, DPIAs and consultation
- 8. Personal Data Breach
- 9. Deletion and return
- 10. Audits and evidence of compliance
- 11. International transfers
- 12. California and other US state terms
- 13. Liability, precedence and term
- 14. Annex 1 — Processing details
- 15. Annex 2 — Technical and organisational measures
- 16. Annex 3 — Subprocessors
1. Definitions
1.1 “Data Protection Laws” means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as incorporated into United Kingdom law by the European Union (Withdrawal) Act 2018 together with the UK Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and comparable US state privacy laws.
1.2 “Personal Data”, “personal information”, “processing”, “controller”, “processor”, “business”, “service provider”, “data subject”, “consumer”, “sell”, “share” and “supervisory authority” have the meanings given in the applicable Data Protection Laws.
1.3 “Customer Personal Data”means Personal Data contained in Customer Data that InBuzzed processes on Customer’s behalf under the Terms.
1.4 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by InBuzzed or a Subprocessor. It does not include unsuccessful attempts or activity that does not compromise the security of Customer Personal Data, such as pings, port scans, failed logins or denial-of-service attempts.
1.5 “SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
1.6 “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
1.7 “Subprocessor” means a third party engaged by InBuzzed to process Customer Personal Data.
1.8 Capitalised terms not defined here have the meaning given in the Terms of Service.
2. Roles of the parties
2.1 With respect to Customer Personal Data, Customer is the controller (or, where Customer is itself a processor for a third party, a processor) and InBuzzed is the processor (or subprocessor). Where the CCPA or a comparable US state law applies, Customer is the business and InBuzzed is the service provider or processor.
2.2 Customer is responsible for the lawfulness of the collection and use of Customer Personal Data, for having a valid legal basis and, where required, valid consent, for providing required privacy notices to data subjects, and for the accuracy and provenance of the data it submits.
2.3InBuzzed acts as an independent controller for data it processes about Customer’s account holders and team members for account administration, authentication, billing, security, support and its own communications, and for aggregated, de-identified statistics. That processing is described in the Privacy Policy and is outside the scope of this DPA except where expressly stated.
2.4Where Customer is a processor acting for a third-party controller, Customer warrants that it is authorised to appoint InBuzzed as subprocessor and to agree this DPA on the controller’s behalf, and that the controller’s instructions are reflected in Customer’s instructions to InBuzzed.
3. Details of the processing
3.1 The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subjects are described in Annex 1.
3.2 Customer may not submit to the Service special categories of personal data within the meaning of GDPR Article 9, criminal-conviction data, government identifiers, payment card numbers, financial account credentials, or data subject to HIPAA, GLBA or PCI-DSS, unless InBuzzed has agreed in writing to receive them and appropriate additional measures are in place.
4. Processor obligations
4.1 Documented instructions.InBuzzed will process Customer Personal Data only on Customer’s documented instructions, which comprise the Terms, this DPA, the configuration and use of the Service by Customer and its team members, and any further written instructions the parties agree. InBuzzed will not process Customer Personal Data for its own purposes, and in particular will not use it for advertising, profiling, resale, or to train generally available machine-learning models.
4.2 Required by law. InBuzzed may process Customer Personal Data where required by applicable law to which it is subject; in that case InBuzzed will inform Customer of the legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.
4.3 Unlawful instructions. InBuzzed will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is amended or confirmed.
4.4 Confidentiality. InBuzzed will ensure that personnel authorised to process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, receive data-protection and security training, and are granted access only on a need-to-know, least-privilege basis.
4.5 Abuse prevention. Customer acknowledges and instructs that InBuzzed processes Customer Personal Data as necessary to detect and prevent spam, phishing, malware, fraud and abuse, to enforce the Acceptable Use Policy, to maintain suppression lists, and to protect the security and deliverability of the platform, including after suspension or termination where necessary for those purposes.
5. Security
5.1 InBuzzed will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by GDPR Article 32. The measures in place as at the effective date are described in Annex 2.
5.2 InBuzzed may update the measures from time to time provided the updates do not materially reduce the overall level of security of the Service.
5.3 Customer is responsible for its own security configuration and practices, including password strength, multi-factor authentication, team-member access management, protection of API keys and SMTP credentials, securing webhook endpoints, and deciding what Personal Data to submit to the Service.
6. Subprocessors
6.1 General authorisation. Customer grants InBuzzed general written authorisation to engage Subprocessors for the provision of the Service. The Subprocessors engaged as at the effective date are listed in Annex 3.
6.2 Flow-down.InBuzzed will impose on each Subprocessor, by written contract, data-protection obligations that are substantially the same as and no less protective than those in this DPA, and will remain fully liable to Customer for the performance of each Subprocessor’s obligations.
6.3 Notice of changes. InBuzzed will give notice of the addition or replacement of a Subprocessor by updating Annex 3 on this page at /dpa and, where Customer has subscribed to subprocessor notifications by emailing support@inbuzzed.com, by email to the address Customer nominates. Notice will be given at least thirty (30) days before the new Subprocessor begins processing Customer Personal Data, except where a shorter period is required to address an urgent security, legal or continuity need, in which case notice will be given as early as reasonably practicable.
6.4 Objection. Customer may object on reasonable data-protection grounds by written notice to support@inbuzzed.comwithin thirty (30) days of notice. The parties will discuss the objection in good faith. If InBuzzed cannot provide a commercially reasonable alternative within a further thirty (30) days, Customer may terminate the affected part of the Service, or the subscription, on written notice, and InBuzzed will refund prepaid fees for the unused remainder of the then-current term. Termination on this basis is Customer’s sole remedy for an objection.
7. Data subject requests, DPIAs and consultation
7.1 Self-service. The Service provides functionality enabling Customer to access, correct, export, restrict, suppress and delete Customer Personal Data, which Customer will use in the first instance to respond to data subject requests.
7.2 Assistance.Taking into account the nature of the processing, InBuzzed will assist Customer by appropriate technical and organisational measures, insofar as possible, to fulfil Customer’s obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR and equivalent rights under other Data Protection Laws.
7.3 Requests received by InBuzzed.If InBuzzed receives a request from a data subject relating to Customer Personal Data, it will not respond substantively except to confirm that the request relates to Customer, will promptly forward the request to Customer, and will act on it only on Customer’s instructions or where required by law.
7.4 DPIAs and prior consultation. InBuzzed will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities under GDPR Articles 35 and 36, taking into account the nature of the processing and the information available to InBuzzed.
7.5 Costs. Assistance under this Section is provided at no charge where the effort is reasonable and proportionate; InBuzzed may charge its reasonable costs, notified in advance, for assistance that is repetitive, excessive, or requires material engineering work.
7.6 Government access requests. If InBuzzed receives a legally binding request from a public authority for disclosure of Customer Personal Data, it will, unless legally prohibited, notify Customer, challenge requests that appear unlawful or overbroad, seek to redirect the authority to Customer, and disclose only the minimum permissible.
8. Personal Data Breach
8.1 InBuzzed will notify Customer of a Personal Data Breach without undue delay and in any event within seventy-two (72) hours after confirming the breach.
8.2 The notification will describe, to the extent known and as information becomes available: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information. Where information cannot be provided at once, it will be provided in phases without further undue delay.
8.3InBuzzed will take reasonable steps to contain, investigate and remediate the breach, and will cooperate with Customer’s reasonable requests for information needed for Customer to meet its own notification obligations to supervisory authorities and data subjects. Notification is not an acknowledgement of fault or liability.
8.4Notice will be given to the Workspace owner’s account email address and to any security contact Customer has registered with InBuzzed. Customer is responsible for keeping those addresses current and monitored.
9. Deletion and return
9.1 During the term, Customer may export Customer Personal Data using the export functionality of the Service at any time.
9.2On termination or expiry, InBuzzed will make Customer Personal Data available for export for thirty (30) days, except where termination results from Customer’s breach of the Acceptable Use Policy or from unlawful activity. After that period InBuzzed will delete Customer Personal Data from active systems, and it will age out of encrypted backups within the backup retention cycle, which does not exceed thirty-five (35) days.
9.3 InBuzzed may retain Customer Personal Data to the extent required by applicable law, or as necessary to prevent abuse of the platform (including suppression records of unsubscribes, complaints and hard bounces), to maintain billing and tax records, or to establish, exercise or defend legal claims. Retained data remains subject to this DPA and is processed only for those purposes.
9.4 On written request made within the export window, InBuzzed will certify in writing that deletion has been carried out in accordance with this Section.
10. Audits and evidence of compliance
10.1 InBuzzed will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and GDPR Article 28.
10.2Customer’s audit right is satisfied in the first instance by InBuzzed providing: any third-party audit report, certification or attestation it holds (such as a SOC 2 Type II report or an ISO/IEC 27001 certificate), and, where it holds none, written responses to a reasonable security questionnaire, together with a summary of its technical and organisational measures and of any material findings from its own testing.
10.3Where the information provided under Section 10.2 is genuinely insufficient to demonstrate compliance, Customer may conduct an audit, subject to the following: no more than once in any twelve (12) month period, except where required by a supervisory authority or following a confirmed Personal Data Breach; on at least thirty (30) days written notice; during business hours; without unreasonable disruption to InBuzzed’s operations; limited in scope to systems and records relevant to the processing of that Customer’s Personal Data; conducted under confidentiality obligations; not involving access to other customers’ data, to multi-tenant infrastructure internals, or to InBuzzed trade secrets; not involving penetration testing or vulnerability scanning without separate written agreement; and at Customer’s cost, including InBuzzed’s reasonable time and expenses at its then-current rates.
10.4 An auditor appointed by Customer must not be a competitor of InBuzzed and must execute a confidentiality agreement with InBuzzed before the audit begins. Audit findings are the Confidential Information of both parties.
11. International transfers
11.1 InBuzzed processes Customer Personal Data in the United States and may process it in other countries where its Subprocessors operate.
11.2 EEA transfers. Where Customer Personal Data protected by the GDPR is transferred to InBuzzed in a country that has not received an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. Customer is the data exporter and InBuzzed is the data importer. Clause 7 (docking) applies. Clause 9 option 2 (general written authorisation) applies with the notice period in Section 6.3. Clause 11 optional independent dispute-resolution wording does not apply. Clause 17 selects the law of the Republic of Ireland, and Clause 18 selects the courts of Ireland. Annex I is completed by Annex 1and the parties’ details in the Terms; Annex II is completed by Annex 2; Annex III is completed by Annex 3.
11.3 UK transfers. For Personal Data protected by the UK GDPR, the UK Addendum is incorporated and applies to the SCCs as set out above. In Table 4 of the UK Addendum, neither party may end the Addendum as set out in Section 19 of the Mandatory Clauses, other than the importer.
11.4 Swiss transfers. For Personal Data protected by Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority being the Swiss Federal Data Protection and Information Commissioner, and the term member state not preventing data subjects in Switzerland from bringing proceedings in their place of habitual residence.
11.5 InBuzzed does not currently claim certification under the EU-US, UK Extension or Swiss-US Data Privacy Framework. It applies supplementary measures including encryption in transit and at rest, access controls, data minimisation, and a policy of challenging overbroad government access requests.
11.6 If the SCCs or UK Addendum are invalidated, replaced or amended, the parties will work in good faith to implement the replacement mechanism, which will apply automatically on its effective date to the extent it covers the transfers described here.
12. California and other US state terms
12.1This Section applies where InBuzzed processes personal information of a California consumer on Customer’s behalf. Customer is the business; InBuzzed is a service provider.
12.2 InBuzzed will not: (a) sell or share personal information as those terms are defined in the CCPA; (b) retain, use or disclose personal information for any purpose other than the business purposes specified in the Terms and this DPA, or as otherwise permitted by the CCPA, including retaining, using or disclosing it for a commercial purpose other than providing the Service; (c) retain, use or disclose personal information outside the direct business relationship between InBuzzed and Customer; or (d) combine personal information received from Customer with personal information received from or on behalf of another person, or collected from its own interaction with the consumer, except as permitted by the CCPA to detect security incidents or to protect against fraudulent or illegal activity.
12.3 InBuzzed certifies that it understands the restrictions in Section 12.2 and will comply with them.
12.4 InBuzzed will provide the same level of privacy protection required of Customer by the CCPA, will notify Customer if it determines it can no longer meet its obligations, and will permit Customer, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of personal information.
12.5InBuzzed will assist Customer in responding to verifiable consumer requests to know, delete, correct and opt out, and in meeting Customer’s obligations regarding security and breach notification.
12.6Where other US state privacy laws apply and designate InBuzzed as a processor, InBuzzed will comply with the equivalent processor duties under those laws, including adhering to Customer’s instructions, assisting with consumer rights requests and security obligations, and engaging subcontractors under written contract.
13. Liability, precedence and term
13.1 Liability.Each party’s liability arising out of or related to this DPA, whether in contract, tort or any other theory, is subject to the exclusions and limitations of liability in the Terms of Service, and all claims under the Terms and this DPA together are subject to the aggregate cap stated there. This does not limit any liability of either party to a data subject under the SCCs or under mandatory Data Protection Laws.
13.2 Precedence. In the event of conflict, the order of precedence is: (a) the SCCs and UK Addendum; (b) this DPA; (c) the Terms of Service; (d) any other agreement between the parties relating to the Service. The SCCs prevail only in respect of the transfers they govern.
13.3 Term. This DPA takes effect when Customer accepts the Terms and continues until InBuzzed ceases to process Customer Personal Data. Provisions that by their nature should survive, including Sections 4, 5, 8, 9, 10, 11 and 13, survive termination.
13.4 Changes. InBuzzed may update this DPA where necessary to reflect a change in law, a new transfer mechanism, a change in Subprocessors, or a change to the Service, provided the update does not materially reduce the protections afforded to Customer Personal Data. Material changes are notified in accordance with Section 27 of the Terms.
14. Annex 1 — Processing details
14.1 Subject matter. The provision of the InBuzzed email operations platform to Customer, including transactional email delivery via API and SMTP relay, marketing broadcasts, funnels and automations, contact lists and segmentation, forms, templates, open and click analytics, webhooks, and hosted business mailboxes.
14.2 Duration. For the term of the Terms, plus the export and deletion periods described in Section 9, plus any retention required by Section 9.3.
14.3 Nature and purpose. Storage, hosting, structuring, retrieval, transmission, delivery and delivery retries, rendering, tracking of opens and clicks where enabled, segmentation and automation execution, analytics and reporting, backup, abuse and spam prevention, suppression management, support, and deletion.
14.4 Categories of data subjects.Customer’s contacts, subscribers and message recipients; individuals who submit Customer’s forms; senders and recipients of mail in Customer’s hosted mailboxes; and Customer’s own personnel, team members and administrators to the extent their data appears in Customer Data.
14.5 Categories of Personal Data.
- Identifiers and contact data — email address, name, salutation, company, job title, telephone number, postal address where supplied.
- List and consent data — list and segment membership, tags, custom fields defined by Customer, subscription status, consent source, timestamp and IP address, unsubscribe and suppression status.
- Message content — the content of messages, templates, attachments and form submissions, which may contain Personal Data chosen by Customer.
- Engagement and delivery data — sends, deliveries, deferrals, bounces, complaints, opens and clicks, with timestamps, message identifiers, destination URLs, recipient IP address, user-agent, device or client type, and approximate location derived from IP address.
- Mailbox data — messages, attachments, folders, contacts, settings and connection logs for hosted business mailboxes.
- Technical data — sending domain, tracking domain, authentication results, API and SMTP request metadata.
14.6 Special categories. None are intended or permitted, per Section 3.2.
14.7 Frequency of transfer. Continuous, for the duration of the Terms.
14.8 Competent supervisory authority.For SCC purposes, the supervisory authority of the EEA member state in which Customer is established, or, where Customer is not established in the EEA, the supervisory authority of the member state in which Customer’s EU representative is established or in which the relevant data subjects are located.
15. Annex 2 — Technical and organisational measures
- Encryption — TLS for data in transit across public networks, including opportunistic and, where supported, enforced TLS for SMTP; encryption at rest for databases, object storage and backups; password hashing with a modern, salted algorithm.
- Access control — unique named accounts for personnel, role-based access, least privilege, multi-factor authentication for administrative access, prompt revocation on role change or departure, and periodic access review.
- Tenant isolation — logical separation of customer workspaces, with authorisation checks on every data access path and scoped API keys.
- Network security — segmented networks, restricted administrative interfaces, firewalling, DDoS mitigation, web application firewall and bot protection.
- Logging and monitoring — centralised application, access and security logging, alerting on anomalous activity, and retention of security logs for twelve months.
- Vulnerability management — dependency and image scanning, timely patching prioritised by severity, and secure development practices including code review.
- Change management — version-controlled infrastructure and application code, separated environments, and tested deployment and rollback procedures.
- Resilience — encrypted automated backups with a retention cycle of up to thirty-five days, restoration testing, and documented recovery procedures.
- Incident response — a documented process covering detection, triage, containment, eradication, recovery, notification and post-incident review.
- Personnel — written confidentiality obligations, security and data-protection training, and access granted only as required by role.
- Vendor management — security and privacy review before engaging a Subprocessor, and contractual data-protection terms with each.
- Data minimisation and deletion — retention schedules, suppression-list management, and deletion routines as described in Section 9 and the Privacy Policy.
16. Annex 3 — Subprocessors
The following Subprocessors process Customer Personal Data as at the effective date of this DPA. Changes are notified in accordance with Section 6.3.
- Amazon Web Services, Inc. (United States) — cloud hosting, compute, storage, databases and backups.
- Cloudflare, Inc. (United States) — DNS, CDN, TLS termination, web application firewall, DDoS mitigation and bot protection including Turnstile; processes IP address and request metadata for the web application and tracking endpoints.
- Stripe, Inc. (United States) — payment processing and subscription billing; processes billing contact and payment data of Customer’s own personnel rather than recipient data.
- Outbound mail-transfer and delivery infrastructure providers — acceptance, queuing, delivery and bounce and feedback-loop processing of Customer messages.
- Hosted mailbox provider — provisioning and hosting of workspace inbox mailboxes, including storage of mailbox contents and connection logs.
- Operational tooling providers — error monitoring, log aggregation and support ticketing, which may incidentally process Personal Data contained in diagnostic data or support correspondence.
The current named list, including the identity of the delivery and mailbox providers in use, is available on request from support@inbuzzed.com. Email the same address to subscribe to advance notice of subprocessor changes.
Astra Innovations LLC, Sanford, Florida, USA — support@inbuzzed.com. See also the Terms of Service, the Privacy Policy and the Acceptable Use and Anti-Spam Policy.
Questions: support@inbuzzed.com · Terms · Privacy · Acceptable Use · DPA · Cookie Policy