Data Processing Agreement

Controller and processor terms for personal data handled by BigStats.email.

Last updated August 4, 2026

1. Introduction and definitions

This Data Processing Agreement ("DPA") is entered into between the customer identified in the applicable services agreement (the "Controller") and BigStats.email, 507 Ft. Pena, San Antonio, TX 78245 USA (the "Processor"). It takes effect on the date the Controller first accepts the Terms of Service or begins using BigStats, whichever is earlier, and forms part of that agreement.

"Personal Data," "Processing," "Data Subject," "Controller," "Processor," "Supervisory Authority" and "Personal Data Breach" have the meanings given in the GDPR; "Personal Information," "Business," "Service Provider" and "Sale" have the meanings given in the CCPA/CPRA. Where a term maps to both, the definition of the law applicable to the relevant processing controls.

2. Scope and nature of processing

  • Subject matter: ingestion of mail transfer agent event notifications and the generation of delivery, ISP and bounce reports, exports, alerts and API access for the Controller.
  • Duration: for the term of the services agreement and any period afterwards in which Processor retains Personal Data, until deletion or return under Section 8.
  • Nature and purpose: collection, storage, structuring, classification, aggregation, retrieval, transmission (exports and API), deletion.
  • Types of Personal Data: recipient email addresses and domains, IP addresses, message, campaign and subscriber identifiers supplied by Controller, engagement events (opens, clicks, unsubscribes, complaints), bounce diagnostics, plus Controller's own user names, emails and authentication data.
  • Categories of Data Subjects: Controller's email recipients and subscribers, and Controller's own personnel who use BigStats.

3. Obligations of the Processor

  • Instructions: Processor processes Personal Data only on documented instructions from the Controller, including the configuration choices the Controller makes in the product, except where required by law — in which case Processor notifies Controller unless the law forbids it.
  • No sale or unauthorised use: Processor does not sell or share Personal Data, and does not retain, use or disclose it for any purpose other than performing the services.
  • Confidentiality: all personnel authorised to process Personal Data are bound by written confidentiality obligations and receive access on a need-to-know basis.
  • Security measures: Processor maintains technical and organisational measures appropriate to the risk, including encryption in transit and at rest, row-level access controls that isolate each workspace, scoped and revocable ingest keys and API tokens, least-privilege administrative access, logging, and regular review of these measures.

4. Subprocessors

  • Prior authorisation: Controller grants general written authorisation for Processor to engage subprocessors for application and database hosting and transactional email delivery. A current list is available at hello@bigstats.email.
  • Flow-down terms: Processor imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains fully liable for its subprocessors' performance.
  • Notification of changes: Processor notifies Controller before adding or replacing a subprocessor and allows a reasonable period to object on reasonable data protection grounds; if the objection cannot be resolved, Controller may terminate the affected service.

5. Data Subject rights and cooperation

  • Assistance with requests: taking into account the nature of the processing, Processor assists Controller by appropriate technical and organisational measures in responding to Data Subject requests for access, correction, deletion, restriction, objection and portability, and promptly forwards any request it receives directly.
  • Regulatory compliance: Processor provides reasonable assistance with data protection impact assessments, prior consultations with Supervisory Authorities, and regulatory inquiries relating to the processing.

6. Incident and breach notification

  • Immediate reporting: Processor notifies Controller without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Controller's Personal Data.
  • Details provided: the notice describes the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information; where details are not all available at once, they are provided in phases without undue delay.
  • Remediation: Processor takes immediate steps to contain the incident, secure affected data, investigate root cause, and cooperate with Controller's own notification obligations.

7. Audit rights

  • Inspection: Processor makes available the information reasonably necessary to demonstrate compliance with this DPA, including descriptions of its security measures and any third-party reports or certifications it holds.
  • On-site audits: no more than once per twelve months (and additionally after a Personal Data Breach or at a Supervisory Authority's direction), Controller or an independent auditor bound by confidentiality may audit Processor's relevant systems and documentation, on at least thirty days' written notice, during business hours, without unreasonable disruption, and at Controller's expense.

8. Data return and destruction

  • End of service: on termination or expiry of the services agreement, processing of Personal Data ceases except for storage pending return or deletion.
  • Choice of action: at Controller's election, made within thirty days of termination, Processor securely deletes or returns all Personal Data in a commonly used machine-readable format; absent an election, Processor deletes it after that period, except where retention is required by law.
  • Certification: Processor provides written confirmation of deletion on request. Backup copies are purged on their ordinary expiry cycle and remain protected by this DPA until purged.

9. General

Where the GDPR requires it, the Standard Contractual Clauses apply to transfers of Personal Data outside the EEA, the UK or Switzerland and are incorporated by reference, with this DPA supplying the required annex details. In the event of a conflict, this DPA prevails over the services agreement with respect to the processing of Personal Data.

BigStats.email, 507 Ft. Pena, San Antonio, TX 78245 USA. Inquiries: hello@bigstats.email.

This document is maintained by BigStats.email and is provided for information; it is not legal advice.