Data processing agreement
Last updated October 9, 2026
Template: fill in the highlighted details and have a lawyer familiar with Hungarian and EU law review this page before launch.
This agreement applies whenever you (the controller) upload personal data to SqueakEmail, operated by [Company legal name] (the processor). It meets the requirements of Article 28 of the GDPR and forms part of our terms of service. It applies automatically to every account; to receive a countersigned copy, email privacy@squeakemail.com.
1. Subject, nature and purpose
The processor verifies email addresses submitted by the controller: checking their format and domain, and querying the responsible mail server about the mailbox, without sending any message. Results are returned to the controller.
2. Data and data subjects
- Data: email addresses, and the verification result for each. Other columns in uploaded files are discarded on upload.
- Data subjects: the people whose addresses the controller submits (typically its contacts, customers or leads).
- No special categories of personal data are processed.
3. Duration
For as long as the controller uses the service. Lists and results are deleted automatically after the plan’s retention period (Free 7 days, Starter 30 days, Growth 60 days, Pro 90 days, Business 180 days, Scale 365 days), when the controller deletes them, or when the account is deleted. Backups roll over within 14 days.
4. Processor obligations
- Process the data only on the controller’s documented instructions, which are given by using the service.
- Ensure everyone with access is bound by confidentiality.
- Apply the security measures in section 6.
- Help the controller respond to data subject requests and meet its obligations under Articles 32 to 36 GDPR.
- Notify the controller without undue delay, and within 48 hours, after becoming aware of a personal data breach.
- Delete the data at the end of the service, as described in section 3.
- Make available the information needed to demonstrate compliance, and allow reasonable audits with 30 days’ notice.
5. Sub-processors
The controller authorises these sub-processors:
- OVH Hosting Inc. (OVHcloud), Beauharnois, Canada: hosting of the service and database in Canada (covered by an EU adequacy decision).
- Stripe Payments Europe, Ltd. (Ireland): payments (account data only, no uploaded lists).
- [Email provider, e.g. Resend or Postmark]: account emails (account data only, no uploaded lists).
The processor will give 30 days’ notice of a new sub-processor by email, and the controller may object. Each sub-processor is bound by data protection terms at least as protective as these. Transfers outside the EEA rely on the Standard Contractual Clauses or an adequacy decision.
6. Security measures
- All connections to the service use TLS (HTTPS).
- Each account can access only its own lists; access is enforced on every request by the API.
- Passwords, session tokens and API keys are stored only as one-way hashes.
- The database is not reachable from the internet; only the application server can access it.
- Production access is limited to the people who operate the service.
- Daily backups, retained for at most 14 days.
- Automatic deletion according to the retention periods in section 3.
7. Controller responsibilities
The controller confirms it has a lawful basis to process the addresses it submits and to have them verified, and that it will use the results in line with data protection and anti-spam law.