Legal

Data Processing Agreement (DPA)

Last updated:

Need a signed copy?

Some organizations require a countersigned DPA for their records. Use the form at the bottom of this page to request one.

This Data Processing Agreement (the “DPA”) forms part of the Terms and Conditions, any applicable order form, offer, or other agreement governing the use of the Services (together, the “Agreement”) between the customer identified in the Agreement (“Controller”) and Lettermint B.V., a private limited liability company incorporated under the laws of the Netherlands, registered with the Dutch Chamber of Commerce under number 99337711 and having its registered address at Willemsvaart 16 B, 8019 AB Zwolle, the Netherlands (“Processor” or “Lettermint”). Controller and Lettermint are each a “Party” and together the “Parties”.

This DPA applies automatically whenever Lettermint processes Controller Personal Data in connection with the Services. If the Parties have entered into a separately signed data processing agreement covering the same processing, that agreement prevails to the extent of any conflict.

1. Definitions

1.1 Applicable Data Protection Law means Regulation (EU) 2016/679 (the “GDPR”), Regulation (EU) 2018/1725 where applicable, and any applicable Union law or national law of an EU or EEA Member State relating to the protection of personal data.

1.2 Business Relationship Data means personal data relating to the administration of the commercial relationship between the Parties for which Lettermint determines the purposes and means of processing. It may include account registration and administrator details, business contact details, billing and payment information, subscription and service-usage information, security and fraud-prevention data, and support correspondence. Business Relationship Data does not include personal data contained in support correspondence or other records to the extent that Lettermint processes that data solely on behalf of Controller to provide the Services.

1.3 Controller Personal Data means any personal data that Lettermint processes on behalf of Controller under this DPA. Controller Personal Data excludes Business Relationship Data.

1.4 Email Data means the subset of Controller Personal Data contained in, associated with, or generated through email processed using the Services, including message content, attachments, sender and recipient identifiers, headers, routing information, delivery and engagement events, suppression data, and related technical metadata.

1.5 Personal Data Breach has the meaning given to it in Article 4(12) GDPR and, for the purposes of this DPA, means a personal data breach affecting Controller Personal Data.

1.6 Services has the meaning given in the Agreement and includes Lettermint’s transactional, broadcast, and inbound email services and related platform, API, SMTP, support, security, and operational functionality.

1.7 Subprocessor means a third party engaged by Lettermint to process Controller Personal Data on behalf of Controller.

1.8 The terms personal data, processing, controller, processor, data subject, and supervisory authority have the meanings given to them in the GDPR.

1.9 Where Controller itself acts as a processor on behalf of another controller, references in this DPA to Controller include Controller in that capacity and Lettermint acts as a subprocessor. Controller represents that it is authorised to engage Lettermint and to give the instructions set out in this DPA.

2. Scope, roles, and order of precedence

2.1 This DPA applies only to the processing of Controller Personal Data by Lettermint in connection with the Services.

2.2 Controller determines the purposes and essential means of the processing of Controller Personal Data. Lettermint processes Controller Personal Data as Processor, or as a subprocessor where Section 1.9 applies.

2.3 Lettermint processes Business Relationship Data as an independent controller in accordance with its Privacy Policy. Payment providers, including Stripe, may process Business Relationship Data for billing and payment purposes. They do not receive Email Data or other Controller Personal Data from Lettermint for those purposes and are not Subprocessors under this DPA.

2.4 This DPA forms part of the Agreement. If there is a conflict between this DPA and another part of the Agreement concerning the processing of Controller Personal Data, this DPA prevails. For matters not specifically governed by this DPA, including fees, service levels, general termination rights, liability, and dispute resolution, the Agreement continues to apply, subject always to mandatory Applicable Data Protection Law.

2.5 Any right granted to Lettermint under the Agreement to operate, secure, maintain, or improve the Services does not authorise Lettermint to use Controller Personal Data for unrelated purposes, advertising, unrelated profiling, or the training or fine-tuning of artificial-intelligence models. Lettermint may use information that has been irreversibly anonymised so that it is no longer personal data.

3. Details and duration of processing

3.1 The processing covered by this DPA is described below.

ElementDescription
Subject matterThe provision of Lettermint’s transactional, broadcast, inbound email, and related platform services.
DurationFor the duration of the Agreement and thereafter only until Controller Personal Data has been returned or deleted in accordance with Section 11, unless Union or Member State law requires continued storage.
Nature and operationsCollecting, receiving, recording, organising, structuring, storing, hosting, retrieving, consulting, transmitting, routing, queuing, delivering, making available, matching, analysing, logging, monitoring, suppressing, restricting, backing up, restoring, exporting, returning, and deleting Controller Personal Data.
PurposesProviding the Services; sending, receiving, routing, queuing, and delivering email on Controller’s instructions; processing delivery, bounce, complaint, unsubscribe, suppression, and engagement events; providing operational and deliverability reporting; authenticating requests; protecting accounts, systems, networks, and email reputation; detecting, investigating, preventing, and remediating abuse, fraud, security threats, unlawful use, and violations of the Agreement; providing support; maintaining resilience, backups, disaster recovery, and business continuity; and returning or deleting Controller Personal Data.
Categories of data subjectsController’s customers, users, subscribers, members, contacts, prospects, suppliers, employees, contractors, and representatives; senders and intended recipients of email; persons mentioned in email content, attachments, support cases, or abuse reports; and any other individual whose personal data Controller submits to or causes to be processed through the Services.
Categories of personal dataNames, email addresses, and other sender or recipient identifiers; contact lists, audience attributes, subscription preferences, consent records, and suppression data; email subject lines, bodies, templates, attachments, and inbound message content; message headers, routing data, domain and authentication data, message identifiers, timestamps, and delivery status; engagement and event data, including opens, clicks, bounces, complaints, unsubscribes, and delivery events; IP addresses, device information, browser type, email-client information, webhook data, API or SMTP metadata, and security logs; limited personal data included in support tickets or abuse cases where processed on Controller’s behalf; and any other personal data that Controller elects to submit to or process through the Services.
Special categories and Article 10 dataThe Services do not require special categories of personal data or personal data relating to criminal convictions and offences. Such data may nevertheless be present where Controller elects to include it in email, attachments, inbound content, support cases, or other Controller Personal Data. Where present, the safeguards in Section 6 apply, including encryption, least-privilege access, confidentiality obligations, access logging, and restrictions on onward processing and disclosure.
FrequencyContinuous or as initiated and configured by Controller during its use of the Services.
Processing locationsAs described in Section 8.

3.2 Business Relationship Data, including account-administrator and billing data processed by Lettermint as an independent controller, is not included in the processing description in Section 3.1.

4. Controller obligations and documented instructions

4.1 Controller shall:

(a) comply with Applicable Data Protection Law in relation to Controller Personal Data;

(b) ensure that it has a valid legal basis and all necessary rights, notices, consents, and authorisations for the processing and disclosure of Controller Personal Data to Lettermint;

(c) ensure that its instructions are lawful, documented, and consistent with the Agreement;

(d) determine whether and how to respond to requests from data subjects and supervisory authorities;

(e) implement appropriate measures for the security of its accounts, credentials, integrations, devices, and configurations; and

(f) provide Lettermint with information reasonably necessary for Lettermint to comply with this DPA and Applicable Data Protection Law.

4.2 Controller’s documented instructions consist of this DPA, the Agreement, Controller’s configuration and use of the Services, API or SMTP requests, recipient and destination selections, and other written instructions accepted by Lettermint.

4.3 Additional instructions must be submitted in writing, relate to the Services, and be technically and organisationally feasible. Where an additional instruction requires material work outside the ordinary scope of the Services, Lettermint may treat that work as additional services under the Agreement, provided that this does not prevent either Party from complying with Applicable Data Protection Law.

4.4 Controller shall not provide special categories of personal data within the meaning of Article 9 GDPR or personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR unless Controller has determined that the processing is lawful, necessary, and subject to appropriate safeguards.

4.5 Controller is responsible for selecting the intended recipients and destinations of email and other transmissions made through the Services and for determining whether any resulting disclosure or international transfer is lawful.

5. Processor obligations

5.1 Lettermint shall process Controller Personal Data only on documented instructions from Controller, including with regard to transfers of personal data, unless Union or Member State law requires Lettermint to process the data. In that case, Lettermint shall inform Controller of the legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

5.2 Lettermint shall immediately inform Controller if it considers that an instruction infringes the GDPR, Regulation (EU) 2018/1725 where applicable, or other applicable Union or Member State data-protection law. Lettermint may suspend the affected instruction until Controller confirms, amends, or withdraws it. If Controller persists with an instruction that Lettermint reasonably considers unlawful, Lettermint may terminate the affected processing or affected Services in accordance with the Agreement.

5.3 Lettermint shall ensure that persons authorised to process Controller Personal Data:

(a) are bound by an appropriate contractual or statutory duty of confidentiality;

(b) receive access only to the extent necessary for their duties; and

(c) receive appropriate data-protection and information-security training.

5.4 Lettermint shall promptly inform Controller if it becomes aware that Controller Personal Data processed by Lettermint is materially inaccurate or outdated, where this is apparent from the nature of the Services and the information available to Lettermint.

5.5 Lettermint shall maintain records and documentation required of it as a processor under Applicable Data Protection Law and shall cooperate with competent supervisory authorities as required by law.

5.6 Lettermint shall not sell Controller Personal Data or use it for advertising, unrelated profiling, or any purpose other than the provision, security, maintenance, and lawful operation of the Services in accordance with Controller’s documented instructions.

5.7 Lettermint shall promptly inform Controller if Lettermint is unable to comply with this DPA or can no longer provide the safeguards required by Applicable Data Protection Law.

5.8 Where Lettermint receives a legally binding request from a public authority for access to Controller Personal Data, Lettermint shall, unless prohibited by law:

(a) notify Controller before disclosure;

(b) review the legality and scope of the request;

(c) challenge or seek clarification of a request where Lettermint reasonably considers this appropriate and legally available; and

(d) disclose only the minimum Controller Personal Data legally required.

6. Security of processing

6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, Lettermint shall implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR.

6.2 The main features of the measures maintained by Lettermint for the Services include:

(a) documented information-security governance, risk-management, access-control, incident-response, business-continuity, backup, change-management, and supplier-management processes, together with appropriate personnel training and confidentiality obligations;

(b) individual accounts, role-based access control, least-privilege access, multi-factor authentication for privileged or administrative access, periodic access reviews, prompt revocation or adjustment of access, and logical segregation designed to prevent customers from accessing one another’s data;

(c) encryption of Controller Personal Data in transit using TLS 1.2 or higher where supported by the communicating systems, encryption of Controller Personal Data at rest, and appropriate management of credentials, secrets, and encryption keys;

(d) logging and monitoring of relevant administrative, security, and system events, security-event detection and alerting, and documented incident-response procedures covering triage, containment, investigation, remediation, recovery, and communication;

(e) secure-development, code-review, dependency and vulnerability scanning, security testing, change-management, risk-based vulnerability-remediation processes, and regular testing, assessment, and evaluation of the effectiveness of relevant safeguards;

(f) systems and procedures designed to support the ongoing confidentiality, integrity, availability, and resilience of the Services, including encrypted backups performed at least daily for relevant production systems, restoration procedures, disaster recovery, business continuity, monitoring, alerting, and periodic testing;

(g) data-minimisation, documented retention, access restriction, and secure-deletion processes, including restrictions on the use of Controller Personal Data in support, testing, analytics, and AI-assisted workflows;

(h) security and data-protection due diligence, written data-protection and confidentiality obligations, and ongoing oversight proportionate to the risk of relevant suppliers and Subprocessors; and

(i) physical and environmental safeguards maintained by Lettermint’s infrastructure and data-centre providers within the EU or EEA, consistent with Section 8.

6.3 By entering into the Agreement, Controller approves the main features of the measures described in this Section. Upon request, Lettermint shall make available to Controller through its Trust Center further information concerning the implementation of those measures and relevant supporting evidence, including available certifications, independent assurance information, policy summaries, and security documentation.

6.4 Access to detailed or security-sensitive information may be subject to reasonable identity-verification, confidentiality, and access-control requirements. Lettermint shall provide access or responsive information without undue delay to the extent necessary for Controller to assess the appropriateness of the measures or demonstrate compliance with Article 28 GDPR. Information made available through the Trust Center supports Lettermint’s compliance obligations but does not replace or limit Controller’s rights under Section 12.

6.5 Controller grants prior general approval for Lettermint to modify the implementation of the measures described in this Section from time to time to reflect technical developments, changes to the Services, evolving security threats, or improvements to Lettermint’s security programme, provided that such modifications do not materially reduce the overall level of protection for Controller Personal Data. A modification that would materially reduce that overall level of protection shall be treated as a material amendment to this DPA and is governed by Section 16.

7. Subprocessors

7.1 Controller grants Lettermint general written authorisation to engage the providers identified as Subprocessors on the Subprocessors page as of the date this DPA becomes effective for Controller, but only to the extent that each provider processes Controller Personal Data on Lettermint’s behalf.

7.2 Lettermint shall actively inform Controller in writing, by email or an in-product notice, of an intended addition or replacement of a Subprocessor at least thirty (30) calendar days before the Subprocessor begins processing Controller Personal Data. The notice shall provide information reasonably necessary for Controller to assess the proposed change.

7.3 Controller may object to an intended addition or replacement within the thirty-day notice period on reasonable grounds relating to the protection of Controller Personal Data. Lettermint shall not permit the proposed Subprocessor to process Controller Personal Data before the notice period expires. If Controller does not object within the notice period, the proposed change is deemed authorised.

7.4 If Controller objects in accordance with Section 7.3, the Parties shall work in good faith to address the objection, including by considering reasonable alternative arrangements. If no reasonable resolution is available, either Party may terminate the affected Services with effect before the proposed Subprocessor begins processing Controller Personal Data.

7.5 Lettermint shall enter into a written agreement with each Subprocessor that imposes, in substance, the same data-protection obligations that apply to Lettermint under this DPA, insofar as they are relevant to the services performed by that Subprocessor.

7.6 Lettermint remains fully responsible to Controller for the performance of each Subprocessor’s data-protection obligations, as required by Article 28(4) GDPR.

7.7 Lettermint shall notify Controller without undue delay if it becomes aware of a material failure by a Subprocessor to fulfil its applicable data-protection obligations and that failure affects Controller Personal Data.

7.8 Upon reasonable request, Lettermint shall provide information necessary to demonstrate a Subprocessor’s compliance with this Section. Where necessary to demonstrate compliance, Lettermint shall provide relevant extracts or a suitably redacted copy of the applicable data-protection terms, subject to the protection of confidential information, trade secrets, security information, and personal data relating to other customers.

7.9 A third-party provider that does not process Controller Personal Data is not a Subprocessor for the purposes of this DPA, even if that provider supports Lettermint’s general business operations.

7.10 Unless otherwise specified in the applicable notice or on the Subprocessors page, each Subprocessor processes only the Controller Personal Data necessary to perform the service described for that Subprocessor, for the duration of Lettermint’s engagement of that Subprocessor and any limited period required to return or delete the data in accordance with the applicable subprocessing terms.

8. Processing locations and international transfers

8.1 The hosting, storage, and processing of Email Data within Lettermint’s infrastructure and service-Subprocessor chain shall take place within the European Union (“EU”), subject to the Controller-directed transmissions described in Section 8.3.

8.2 Other Controller Personal Data processed by Lettermint or its Subprocessors on Lettermint’s behalf, including limited information used for support or abuse handling, shall be processed within the EU or European Economic Area (“EEA”), unless Section 8.4 applies.

8.3 At Controller’s instruction, email and other Controller Personal Data may be transmitted to recipients, recipient mail systems, webhooks, integrations, or other destinations selected or configured by Controller, including destinations outside the EU or EEA. Those recipient systems and Controller-selected destinations are not Lettermint Subprocessors merely because Lettermint transmits data to them as part of the Services. Controller is responsible for determining whether the transmission is lawful and for providing any required transfer instructions or safeguards.

8.4 Lettermint shall not otherwise transfer Controller Personal Data, or permit remote access to Controller Personal Data, outside the EEA unless:

(a) Controller has authorised the relevant change in accordance with Section 7 or Section 16;

(b) the transfer complies with Chapter V GDPR, including through an applicable adequacy decision or appropriate safeguards under Article 46 GDPR; and

(c) Lettermint implements any supplementary measures reasonably required by Applicable Data Protection Law, including a transfer impact assessment where required.

8.5 This Section does not apply to Business Relationship Data, which Lettermint processes as an independent controller in accordance with its Privacy Policy.

9. Data-subject rights and other assistance

9.1 If Lettermint receives a request directly from a data subject relating to Controller Personal Data, Lettermint shall forward the request to Controller without undue delay. Lettermint shall not respond to the request except on Controller’s documented instructions or where required by law.

9.2 Taking into account the nature of the processing, Lettermint shall assist Controller by appropriate technical and organisational measures, insofar as possible, with Controller’s obligation to respond to requests under Chapter III GDPR. Assistance may include making available platform functionality for searching, exporting, correcting, suppressing, or deleting relevant data and providing reasonable technical assistance where that functionality is insufficient.

9.3 Lettermint shall provide assistance without undue delay and within sufficient time to allow Controller to meet the applicable statutory deadline after Lettermint has received the information reasonably necessary to identify the relevant data and request.

9.4 Taking into account the nature of processing and the information available to Lettermint, Lettermint shall assist Controller in ensuring compliance with Articles 32 to 36 GDPR, including by:

(a) providing relevant information concerning the security of processing;

(b) providing the assistance concerning Personal Data Breaches described in Section 10;

(c) providing information reasonably necessary for a data-protection impact assessment relating to the Services; and

(d) assisting with prior consultation with a supervisory authority where required.

9.5 Controller remains responsible for assessing the validity of data-subject requests, determining whether a data-protection impact assessment or prior consultation is required, and making any notification or communication required by Articles 33 and 34 GDPR.

9.6 Lettermint may charge reasonable, documented fees agreed in advance for exceptional assistance that is materially outside the standard functionality and ordinary support included in the Services, unless the assistance is required because of Lettermint’s breach of this DPA. Any fee shall be proportionate and shall not prevent Controller from exercising its rights or meeting its obligations under Applicable Data Protection Law.

10. Personal Data Breaches

10.1 Lettermint shall notify Controller without undue delay and in any event within twenty-four (24) hours after becoming aware of a Personal Data Breach.

10.2 The notification shall include, to the extent known at the time:

(a) a description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of affected data subjects and personal-data records;

(b) the name and contact details of a contact point from whom further information can be obtained;

(c) a description of the likely consequences of the Personal Data Breach; and

(d) a description of the measures taken or proposed by Lettermint to address the Personal Data Breach, including measures to mitigate possible adverse effects.

10.3 Where all information is not available at the same time, Lettermint may provide the initial information in phases and shall provide further information without undue delay as it becomes available.

10.4 Lettermint shall promptly take reasonable steps to contain, investigate, mitigate, and remediate the Personal Data Breach and shall cooperate with and assist Controller in meeting its obligations under Articles 33 and 34 GDPR, taking into account the nature of processing and the information available to Lettermint.

10.5 Lettermint shall not notify a supervisory authority or affected data subjects on Controller’s behalf unless Controller instructs Lettermint to do so or Lettermint is independently required by law. Where Lettermint is legally required to notify, it shall inform Controller and provide a copy of the notification unless prohibited by law.

10.6 Controller shall keep its account-owner, security, and legal contact information current. A notification sent to the contact designated by Controller or, if no dedicated contact is available, to Controller’s account owner or primary administrator, constitutes notification under this Section.

11. Return and deletion of Controller Personal Data

11.1 At the end of the provision of Services involving processing, Controller may choose to have Controller Personal Data returned or deleted. Controller may communicate that choice before termination or during the retrieval period in Section 11.2, provided that irreversible deletion has not already begun following an express deletion instruction.

11.2 Subject to Section 11.3, Controller shall have thirty (30) calendar days after the effective termination date to retrieve Controller Personal Data that remains available through the Services or to request its return. This retrieval period does not extend the ordinary retention period applicable to any individual category of Controller Personal Data during the term of the Agreement. Lettermint shall provide data available through standard export functionality in a commonly used, machine-readable format. Assistance with a bespoke export or a specific format may be treated as additional services under the Agreement.

11.3 Where Controller uses account-deletion functionality after being clearly informed that doing so will initiate permanent deletion of the associated Controller Personal Data and end any applicable retrieval period for that data, or otherwise gives Lettermint an explicit written instruction to delete Controller Personal Data, Controller shall be deemed to have chosen deletion rather than return for the affected data. As regards that Controller Personal Data, the thirty-day retrieval period in the Agreement does not apply. Lettermint shall delete the affected Controller Personal Data from active systems without undue delay.

11.4 If Controller does not request return within the period specified in Section 11.2, Controller shall be deemed to have chosen deletion. Lettermint shall initiate deletion when that period expires and shall complete deletion of the remaining Controller Personal Data from active systems without undue delay or, where Controller timely requests return, without undue delay after completing the return, unless Union or Member State law requires continued storage.

11.5 Lettermint shall delete existing copies. Where immediate deletion from backup media is not technically feasible, residual copies may remain in encrypted and access-restricted backups until they are automatically overwritten or deleted in accordance with Lettermint’s documented backup-retention cycle, which shall not exceed fourteen (14) calendar days following deletion from active systems. Such residual copies shall not be accessed, restored, or otherwise processed except where necessary for disaster recovery, security, or compliance with applicable law. If a backup containing affected Controller Personal Data is restored, the applicable deletion instruction and retention periods shall be reapplied without undue delay.

11.6 If Union or Member State law requires Lettermint to retain Controller Personal Data, Lettermint shall inform Controller of that requirement unless prohibited by law, isolate the retained data from further processing, and delete it when the legal retention obligation ends.

11.7 Upon Controller’s reasonable request, Lettermint shall confirm completion of deletion in writing.

12. Compliance information and audit rights

12.1 Lettermint shall make available to Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and Article 28 GDPR and shall respond promptly and adequately to reasonable compliance inquiries.

12.2 Lettermint may satisfy ordinary information requests by providing relevant information through its Trust Center, responses to reasonable questionnaires, independent audit reports, certifications, and other suitable documentation. Controller may take those materials into account when determining the scope and method of any further review or audit.

12.3 Upon Controller’s request, Lettermint shall permit and contribute to audits of the processing activities covered by this DPA at reasonable intervals or where there are indications of non-compliance. Controller may conduct the audit itself or appoint an independent auditor. An audit may include a remote review or, where reasonably necessary, an inspection of premises or physical facilities under Lettermint’s control that are used for the relevant processing.

12.4 The Parties shall cooperate in good faith regarding the timing, scope, duration, and method of an audit, taking account of the purpose of the audit, the information already available, proportionality, and legitimate security and confidentiality concerns. After such consultation, the final choice among audit methods that are reasonably necessary and proportionate to verify compliance remains with Controller.

12.5 Unless a shorter period is justified by indications of non-compliance, a Personal Data Breach, a binding request from a supervisory authority, or another urgent circumstance, Controller shall provide at least thirty (30) calendar days’ written notice. Audits shall, where appropriate:

(a) take place during regular business hours;

(b) be limited to systems, records, personnel, facilities, and processing relevant to Controller Personal Data;

(c) avoid unreasonable disruption to the Services or Lettermint’s operations;

(d) comply with Lettermint’s reasonable security and access procedures; and

(e) protect confidential information, trade secrets, security information, and personal data relating to other customers.

12.6 An external auditor must be appropriately qualified and bound by written confidentiality obligations. Controller shall ensure that audit materials and findings are used solely for compliance, risk-management, and regulatory purposes.

12.7 In the absence of indications of non-compliance, a Personal Data Breach, a material change to the processing, or a request from a supervisory authority, Controller shall ordinarily not request a substantially duplicative audit more than once in any twelve-month period.

12.8 Each Party shall bear its own internal costs of an audit, and Controller shall bear the fees of any auditor it appoints. Where an audit requires material support beyond the compliance information ordinarily made available by Lettermint and is not prompted by indications of non-compliance, a Personal Data Breach attributable to Lettermint, or a supervisory-authority request, Lettermint may charge reasonable and documented additional costs agreed in advance. Such charges shall not be disproportionate, excessive, dissuasive, or used to delay an audit reasonably required under Article 28 GDPR.

12.9 Lettermint shall address substantiated material deficiencies identified by an audit within a reasonable period, taking into account the nature and risk of the deficiency. The Parties shall make relevant compliance information and audit results available to a competent supervisory authority upon request.

13. AI-assisted processing

13.1 Lettermint may use artificial-intelligence-assisted natural-language processing for the limited purposes of support-ticket triage and drafting and the detection, investigation, and handling of suspected abuse of the Services.

13.2 Where an AI provider processes Controller Personal Data for those purposes, that provider is a Subprocessor and is subject to Section 7. The processing location is governed by Section 8.

13.3 Lettermint shall apply data minimisation and submit only the information reasonably necessary for the relevant support or abuse case. Lettermint shall contract and configure the AI provider so that Controller Personal Data and generated output submitted by Lettermint are not used for model training, fine-tuning, research, feedback-based improvement, advertising, or other independent product-improvement purposes. Lettermint shall not use feedback functionality that permits Controller Personal Data or associated output to be used for those purposes.

13.4 Lettermint shall configure provider-side retention in accordance with the principles of data minimisation and storage limitation and shall ensure that Controller Personal Data is retained by the AI provider no longer than necessary for the purposes described in Section 13.1, subject to limited retention reasonably necessary for security, abuse prevention, or compliance with applicable law. Where reasonably available and appropriate for the relevant processing, Lettermint shall use no-retention or reduced-retention settings.

13.5 AI-generated output shall not, by itself, be the sole basis for a permanent account suspension, termination, or another materially adverse action against Controller. Appropriate personnel shall review relevant output before such action is taken. This does not prevent Lettermint from applying temporary automated measures reasonably necessary to contain an imminent security, abuse, deliverability, or legal risk, provided that the measure is subject to prompt human review.

13.6 Lettermint does not use the AI-assisted processing described in this Section to make decisions about individual data subjects that produce legal effects or similarly significantly affect them.

14. Liability

14.1 Subject to mandatory Applicable Data Protection Law, each Party’s liability arising out of or in connection with this DPA is subject to the exclusions, limitations, procedures, and indemnities set out in the Agreement, including its liability provisions.

14.2 Any general exclusion in the Agreement concerning acts or omissions of third parties does not relieve Lettermint of its responsibility for Subprocessors under Section 7.6 and Article 28(4) GDPR. Any limitation of liability that lawfully applies to Lettermint’s own performance may otherwise apply to liability arising from a Subprocessor’s performance.

14.3 Nothing in this DPA limits or excludes:

(a) liability to the extent it cannot lawfully be limited or excluded;

(b) the rights of data subjects under Applicable Data Protection Law;

(c) the investigative, corrective, authorisation, or advisory powers of a supervisory authority; or

(d) any right of recourse or allocation of responsibility between the Parties that applies under Article 82 GDPR or other mandatory law.

15. Term and survival

15.1 This DPA becomes effective when the Agreement becomes effective or when Lettermint first processes Controller Personal Data, whichever occurs first, and remains in effect for as long as Lettermint processes Controller Personal Data.

15.2 Sections that by their nature must continue to apply, including confidentiality, audit and regulatory cooperation, return and deletion, liability, and governing law, survive termination for as long as relevant Controller Personal Data is retained or a related right or obligation remains outstanding.

16. Amendments

16.1 Lettermint may amend this DPA to reflect changes in Applicable Data Protection Law, regulatory guidance, or the Services. A new version may apply immediately to Controllers entering into an Agreement after that version is published. For an existing Controller, Lettermint shall directly notify Controller of a material amendment by email or through the Services at least thirty (30) calendar days before it takes effect, unless Section 16.4 applies.

16.2 If Controller does not agree to a material amendment, Controller may terminate the Agreement or the affected Services with effect from the date on which the amendment would take effect. Controller’s continued use of the affected Services after that date constitutes approval and acceptance of the amended DPA.

16.3 An amendment shall not remove a mandatory right under Applicable Data Protection Law. Lettermint shall not materially reduce the protection of Controller Personal Data without providing the notice and termination right set out in this Section.

16.4 A shorter notice period may be used where reasonably necessary to comply with law or address an urgent security or data-protection risk. Lettermint shall still provide direct notice without undue delay and explain the reason for the shorter period.

16.5 Changes to Subprocessors are governed by Section 7. Changes to the implementation of the security measures that do not materially reduce the overall level of protection are authorised under Section 6.5. Any material reduction is governed by this Section 16.

16.6 Lettermint shall maintain a record of the publication and effective dates of material DPA versions and shall make previous versions available upon reasonable request.

17. Governing law and disputes

17.1 This DPA is governed by the laws of the Netherlands, unless mandatory Applicable Data Protection Law requires otherwise.

17.2 Disputes arising from or relating to this DPA are subject to the dispute-resolution provisions of the Agreement. Nothing in this Section affects the rights of data subjects or the competence of supervisory authorities or courts under mandatory Applicable Data Protection Law.

18. Contact

Questions, notices, instructions, objections, and requests concerning this DPA may be sent to:

Lettermint B.V.
Attn: Legal / Data Protection
Willemsvaart 16 B
8019 AB Zwolle
The Netherlands
Email: legal@lettermint.co


Request a signed DPA

Need a countersigned copy for your compliance records? Click the button below to fill out a short request form and we'll get it to you shortly.