Data Processing Agreement
Last updated 26 September 2026
This Data Processing Agreement (“DPA”) forms part of the Sequenzo Terms of Service between you (“Controller”) and Sequenzo (“Processor”). It applies automatically from the moment you create an account — you do not need to sign anything for it to be in force. It governs our processing of personal data contained in Customer Data on your behalf, and satisfies Article 28(3) of the UK and EU GDPR. Capitalised terms not defined here have the meaning given in the GDPR. If you need a countersigned PDF for procurement, email [email protected] and we will return one.
1Roles and scope
You are the Controller of the contact records and recipient data you upload to or generate in Sequenzo. We are your Processor for that data. We are an independent Controller only for your own account, billing, support and security data, which is covered by the Privacy Policy rather than by this DPA.
You warrant that you have a lawful basis for every contact you upload, that you have given any notice and obtained any consent required, and that your instructions to us do not breach data protection law. The Acceptable Use Policy forms part of that warranty.
2Subject matter and details of processing
- Subject matter: provision of the Sequenzo email sequencing platform.
- Duration: for as long as your account is open, plus the retention windows in clause 9.
- Nature and purpose: storing contacts, personalising and sending email from your connected mailboxes, detecting replies and bounces, recording engagement, suppression, reporting, backup and support.
- Types of personal data: name, email address, employer, job title, phone number where you supply it, custom fields you define, message content addressed to the individual, engagement and delivery metadata, and IP or client information from opens and clicks where tracking is enabled.
- Categories of data subject: your prospects, customers, contacts and other recipients, and your own personnel who use the workspace.
- Special category data: none. The service is not designed for it and you must not upload it.
3Our obligations
We will:
- process personal data only on your documented instructions — the Terms, this DPA, and your use of the product’s features — unless required otherwise by law, in which case we will tell you first unless the law forbids it;
- tell you promptly if, in our opinion, an instruction infringes data protection law, and may suspend that instruction until it is resolved;
- ensure everyone authorised to process the data is bound by confidentiality obligations that survive their engagement;
- implement and maintain the security measures in clause 6;
- assist you, taking into account the nature of processing and the information available to us, with data subject requests, security of processing, breach notification, data protection impact assessments and prior consultation;
- make available the information needed to demonstrate compliance with Article 28, and allow audits as set out in clause 8.
4Your obligations
You control what is uploaded and who you email. You are responsible for the accuracy and lawfulness of Customer Data, for responding to your data subjects, for configuring retention, tracking and access within the product, and for keeping workspace credentials secure. You must not use Sequenzo to process data of children or special category data.
5Sub-processors
You give general written authorisation for us to engage sub-processors. Each is bound by written terms no less protective than this DPA, and we remain fully liable for their performance. Our current sub-processors and the function each performs:
- Hosting and database provider — application hosting, managed PostgreSQL and encrypted backups.
- Your own mail provider (Google Workspace, Microsoft 365 or your SMTP host) — actual transmission of the mail you send. You connect these; they act on your instructions.
- Transactional email provider — sending Sequenzo’s own system mail such as verification and password resets.
- Payment gateway — subscription billing. It receives your billing details, not your contacts.
- Error monitoring and log storage — operational diagnostics, with personal data minimised.
We will give you at least 30 days’ notice by email to your workspace owner before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period; if we cannot offer a workaround you may terminate the affected service and receive a pro-rata refund of prepaid fees.
6Security measures
Taking account of the state of the art and the risk, we maintain:
- encryption in transit (TLS 1.2+) and at rest, with mailbox OAuth tokens and app passwords encrypted with a separate key;
- role-based access control, least privilege, and mandatory two-factor authentication for administrative access;
- strict tenant isolation: every query is scoped to a workspace, and admin access to customer content is logged in an immutable audit trail;
- hashed passwords using a memory-hard algorithm, and rotating session credentials;
- rate limiting, abuse detection, sending caps, review queues and per-account kill switches;
- encrypted daily backups with tested restores, and documented recovery objectives;
- patching, dependency scanning, and change control on the production environment;
- staff training, background-appropriate onboarding, and prompt access revocation on exit.
7Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate number of records and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point. We will assist you with any notification you must make to a supervisory authority or to data subjects. We will not notify a supervisory authority or your data subjects on your behalf unless you ask us to or the law requires it of us.
8Data subject requests and audits
The product gives you self-service export, correction, suppression and deletion for any contact, so most requests need no involvement from us. If a data subject contacts us directly we will not respond substantively; we will forward the request to you without undue delay.
On written request, and no more than once in any twelve months (unless a regulator or a breach requires more), we will provide our current security documentation and answer a reasonable security questionnaire. Where that is genuinely insufficient for your Article 28(3)(h) obligation, you may appoint an independent auditor bound by confidentiality, on 30 days’ notice, during business hours, without accessing other customers’ data and at your cost.
9Retention, return and deletion
On termination, or on your written request, we will delete Customer Data within 30 days, except: (a) encrypted backups, which age out on their normal 35-day cycle; and (b) suppression records — the email addresses that unsubscribed, hard-bounced or complained — which we retain indefinitely as a hashed suppression list. Retaining those is necessary to comply with the recipients’ own opt-out rights and with anti-spam law; deleting them would allow those people to be emailed again. Export your data before you close the account: after deletion we cannot recover it.
10International transfers
Where personal data is transferred outside the UK or EEA, that transfer is made under an adequacy decision or, failing that, under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor) together with the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and completed with the details in clause 2, the sub-processors in clause 5 and the measures in clause 6. Where required we carry out a transfer risk assessment and apply supplementary measures such as encryption and minimisation.
11Liability, precedence and changes
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In the event of conflict, this DPA prevails over the Terms in relation to the processing of Customer Data, and the Standard Contractual Clauses prevail over this DPA. We may update this DPA to reflect legal or operational change, with notice to workspace owners; changes will not reduce the protections given to Customer Data.
Questions, audit requests, breach contact and countersigned copies: [email protected] or [email protected].