data processing agreement
last updated 2026-08-24 · mittera.eu
This Data Processing Agreement (the “DPA”) applies whenever your use of the mittera Service involves personal data governed by Regulation (EU) 2016/679 (the “GDPR”). It forms part of the Terms of Service and takes effect automatically — you do not need to sign anything. If your organisation needs a signed, negotiated DPA on your own paper, write to legal@mittera.eu.
1. Parties and roles
You (the “Customer”) are the controller of the personal data contained in the emails you send, your contacts and your templates. flndrn Limited (the “Operator”, “we”), registered at Arch. Makariou III 171, Vanezis Business Center 4th floor, 3027 Limassol, Cyprus, with day-to-day operations in Flanders, Belgium, is the processor. The Operator is a separate controller for the small amount of data it needs to run the business — your account email, sign-in events and audit entries — which is described in the Privacy Policy and outside this DPA.
2. Subject matter and duration
The subject matter is the provision of the hosted mittera Service: transmitting the Customer’s email, running the dashboard and the management API, and reporting delivery events. The processing lasts as long as the Customer has an account, and ends on closure plus the retention windows in §11.
3. Nature and purpose of the processing
The Operator stores, hosts and transmits whatever the Customer sends, and performs the operational tasks needed to keep it available: applying security updates, writing audit records, and responding to support requests. The Operator does not read, mine, profile, sell or train models on Customer data, and does not use it for any purpose other than providing the Service and complying with law.
4. Types of personal data and data subjects
The Customer determines, as controller, which types of personal data and which categories of data subject the Service processes on its behalf. By way of illustration: the content of the emails you send, the contacts and audiences you upload, and their identifiers and contact details.
5. Obligations of the processor
The Operator will: process personal data only on documented instructions from the Customer; ensure persons authorised to process are committed to confidentiality; implement the measures in §7; assist the Customer in responding to data subject requests and, where relevant, data protection impact assessments; and delete or return data as set out in §10.
6. Sub-processors
The Customer authorises the sub-processors listed at mittera.eu /subprocessors. The Operator will notify of material changes at least 30 days in advance, and the Customer may object or close its account within that window.
7. Security
TLS on every public endpoint; AES-256-GCM for stored credentials at rest; memory-hard password hashing; SHA-256 for API key hashes compared in constant time; key-only SSH access; weekly dependency updates.
8. Breach notification
The Operator will notify the Customer without undue delay — aiming for 72 hours — after becoming aware of a personal data breach affecting the Customer’s data, and provide what it knows at the time.
9. Assistance
The Operator will reasonably assist the Customer in meeting its GDPR obligations, including responding to data subject rights requests and, where applicable, consulting on data protection impact assessments.
10. Deletion and return
On termination, the Operator will delete or return the personal data it processes under this DPA, unless EU or Member State law requires storage. Deletion follows the retention windows in the Privacy Policy.
11. Retention
The email log and delivery events are kept for 13 months, audit logs for 13 months, and account data for a 30-day soft-delete window after closure. These windows exist so an invoice can be reconstructed and a late security incident investigated.
12. Audits and information
The Operator will make available the information necessary to demonstrate compliance with Article 28. To be plain: flndrn Limited is a small, independent company and holds no SOC 2 report, no ISO 27001 certificate and no third-party audit report of any kind. There is nothing to send you in place of an audit. What the Operator does offer is: answers to reasonable written questions, the published pages at /trust and /subprocessors, and reasonable access on reasonable notice, at most once a year, at the Customer’s expense and under confidentiality.
13. International transfers
The Service is operated from within the EU/EEA. Where a sub-processor is established outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Three, with supplementary measures (TLS in transit, AES-256 at rest, minimisation). The current position of every sub-processor is listed at /subprocessors.
14. Liability
Liability under this DPA is subject to the limitations and exclusions in Section 12 of the Terms of Service. Nothing limits a data subject’s rights under Article 82 of the GDPR.
15. Governing law
This DPA is governed by Belgian law, with exclusive jurisdiction of the courts of Antwerp, Belgium. Where this DPA conflicts with the Terms of Service, this DPA prevails on matters of personal-data processing.