Data Processing Agreement for Mailsound
Last updated: 2026-09-04
This Data Processing Agreement ("DPA") is part of the Terms of Service between the customer ("Controller") and Virtunet B.V., Dullofsakker 44, 5688VD Oirschot, the Netherlands, KvK 95773444 ("Processor"), and applies whenever the Processor processes personal data on the Controller's behalf through Mailsound. It is available at https://mailsound.virtunet.io/dpa and, signed, on request at support@mailsound.virtunet.io.
1. Subject matter and duration
Processing of personal data contained in the content the Controller submits to Mailsound, for the duration of the Controller's account.
2. Nature and purpose
Storing, analysing, computing and emailing as described in the product documentation, to provide the Service to the Controller. No other purpose.
3. Types of data and data subjects
As determined by the Controller's use. Typically: names and email addresses of the Controller's staff and contacts; identifiers in URLs or email content; counterparty names of contracts. Data subjects: the Controller's staff, customers, suppliers and contacts.
4. Processor obligations (GDPR art. 28(3))
The Processor will: a. process personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of the Service; b. ensure that persons authorised to process the data are bound by confidentiality; c. implement the technical and organisational measures in section 7; d. engage sub-processors only under section 5; e. assist the Controller, as far as possible and taking the nature of the processing into account, in responding to data subject requests, by providing export and deletion functions in the Service; f. assist the Controller with security, breach notification and data protection impact assessment obligations, taking the information available to the Processor into account; g. at the Controller's choice, return the personal data (export function in the Service) and delete it, or delete it, when the Controller deletes it or the account, within 24 hours, except where EU or Dutch law requires storage; h. make available the information necessary to demonstrate compliance and allow audits by the Controller or an auditor mandated by the Controller, once per year, on 30 days' notice, at the Controller's cost, remotely and during business hours, limited to the Service; i. inform the Controller immediately if, in the Processor's opinion, an instruction infringes the GDPR or other EU or Member State data protection law; j. forward to the Controller, without undue delay and without answering on the merits, any request from a data subject that concerns the Controller's data.
5. Sub-processors
The Controller gives general authorisation for the sub-processors listed at https://mailsound.virtunet.io/subprocessors. The Processor will notify account holders by email at least 14 days before adding or replacing a sub-processor; the Controller may object by terminating the account, with a refund of any prepaid, unused period. The Processor imposes on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA, and remains liable to the Controller for the sub-processor's performance of them.
6. International transfers
Personal data is stored in the European Union. Where a sub-processor transfers data outside the EU/EEA, the transfer is covered by the EU standard contractual clauses or an adequacy decision, as documented by that sub-processor.
7. Security measures (Annex II)
- Access control: single-use, time-limited sign-in links, no passwords; where a product offers a calendar feed or API key, it is a random token of at least 32 bytes that the Controller can rotate; operator access limited to one account with hardware-backed authentication where the provider supports it.
- Encryption: TLS 1.2 or higher in transit; encryption at rest by the hosting provider.
- Data location: storage restricted to the EU by configuration.
- Minimisation and retention: retention limits per data class as listed in the Privacy Policy; automatic deletion; salted hashes instead of raw identifiers for abuse counters.
- Availability: provider-level replication and backups within the EU; restore procedure tested before launch and yearly.
- Personnel: the Service is operated by a single operator bound by confidentiality; no personnel other than the operator and the sub-processors listed have access.
- Development: secrets held outside the codebase; dependencies pinned; changes reviewed before deployment; no telemetry or analytics scripts.
- Incident handling: as in section 8 of this DPA.
7a. Description of processing (Annex I)
Subject matter, duration, nature, purpose, data types and data subjects are as set out in sections 1 to 3 above, completed by the product documentation at https://mailsound.virtunet.io.
8. Personal data breach
The Processor will notify the Controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the information available at that time.
9. Liability
The liability provisions of the Terms of Service apply to this DPA. In the event of conflict between this DPA and the Terms of Service on data protection matters, this DPA prevails.
10. Governing law
Dutch law. Disputes as set out in the Terms of Service.
Signed on request; otherwise this DPA applies by acceptance of the Terms.