Last updated: July 2026

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Customer”) and Bjørnerås Labs (org.nr. 938 162 336), a Norwegian sole proprietorship operating eusend (“eusend”, “we”, “us”), under our Terms of Service (the “Agreement”). It governs how we process personal data on your behalf when you use the service, and it applies to the extent the GDPR or an equivalent data protection law applies to that processing.

This DPA is incorporated into the Agreement and takes effect automatically when you accept the Agreement — no signature is required, and no separate action is needed to make it binding. If your compliance process requires a counter-signed copy, email [email protected] and we will provide one.

1. Definitions

“GDPR” means Regulation (EU) 2016/679. “Data protection law” means the GDPR and any other applicable law governing the processing of personal data. “Controller”, “processor”, “data subject”, “personal data”, “processing”, and “personal data breach” have the meanings given in the GDPR.

“Customer Personal Data” means personal data that we process on your behalf under the Agreement — principally the recipient addresses, message content, and delivery and engagement events involved in the email you send, together with the audiences, contacts, and templates you store in your account. “Sub-processor” means a third party we engage to process Customer Personal Data.

2. Roles of the parties

For Customer Personal Data, you are the controller and we are your processor. Where you act on behalf of another controller (for example, as an agency sending on behalf of your own client), you warrant that you are authorised to instruct us as that controller’s processor, and references to “you” include that controller.

We act as an independent controller only for the limited data we process to run our business relationship with you — your account and login details, and the usage and billing metadata we need to operate, secure, and bill for the service. That data is governed by our Privacy Policy, not by this DPA. Where this DPA conflicts with the rest of the Agreement on the subject of data processing, this DPA prevails.

3. Details of the processing

Subject matter and nature: processing Customer Personal Data as necessary to provide the eusend email service — accepting, sending, delivering, tracking, and reporting on the email you send, and storing the contacts, audiences, and templates you create.

Purpose: to perform the Agreement and follow your instructions. We do not process Customer Personal Data for our own purposes, and we do not use it for advertising, profiling unrelated to the service, or training AI models.

Duration: for the term of the Agreement, plus the retention and deletion periods described in Section 12 and in our Privacy Policy.

Categories of data subjects: your email recipients and contacts, and the individuals within your organisation who use your account.

Categories of personal data: email addresses; names and other fields you include in messages or contact records; message content, subject lines, and attachments; and delivery and engagement events such as sends, deliveries, bounces, opens, and clicks (which may include IP address, approximate location, and device or client information). You must not send us special categories of personal data (Article 9 GDPR) except where doing so is lawful and you have instructed us accordingly.

4. Your instructions and obligations

We process Customer Personal Data only on your documented instructions. The Agreement, this DPA, your account configuration, and the requests you make through our dashboard and API together constitute your complete and final instructions. You are responsible for the accuracy and lawfulness of the data you send us, for having a valid legal basis for the processing, and for the content of the email you send.

We will inform you if, in our opinion, an instruction infringes data protection law, though we are not obliged to carry out a legal review of your instructions.

5. Our obligations as processor

We will: process Customer Personal Data only as set out in Section 4; not sell it or use it for our own purposes; maintain the records of processing we are required to keep; cooperate with supervisory authorities as required; and, where legally permitted, notify you before disclosing Customer Personal Data in response to a legally binding request from a public authority.

6. Confidentiality

We ensure that the personnel authorised to process Customer Personal Data are bound by confidentiality obligations and are granted access only on a need-to-know basis for the purpose of providing the service.

7. Security

We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art and the risks of the processing, as required by Article 32 GDPR. These measures — including encryption in transit and at rest, access controls, logging, and encrypted backups — are described in our Security Policy, which forms part of this DPA.

8. Sub-processors

You give us general authorisation to engage sub-processors to process Customer Personal Data. Our current sub-processors are listed at eusend.dev/legal/subprocessors. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

We will give at least 30 days’ notice before adding or replacing a sub-processor that processes Customer Personal Data. You may object on reasonable data-protection grounds by emailing [email protected] within that period; if we cannot reasonably accommodate your objection, you may terminate the affected part of the service.

9. Data location and international transfers

We are established in Norway, within the EEA, and we store and deliver Customer Personal Data on infrastructure in the EU/EEA. The processing we carry out for you as your processor does not, in itself, involve a transfer of personal data outside the EEA.

A small number of supporting sub-processors are located outside the EEA, as identified on our sub-processors page. Where Customer Personal Data is transferred to them, that transfer is covered by a valid Chapter V GDPR safeguard — an adequacy decision, the EU–U.S. Data Privacy Framework, or the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures. Any transmission of a message to the external recipient you choose to send it to is carried out on your instruction and is your responsibility as controller.

10. Data subject rights and assistance

If we receive a request from a data subject relating to Customer Personal Data, we will not respond to it directly (except to confirm that the request should be directed to you), and, where the individual identifies you, we will forward it to you without undue delay.

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures — including the access, export, and deletion tools in the dashboard — in responding to data subject requests and in meeting your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), insofar as you cannot reasonably do so yourself.

11. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point for further information. We will provide further details as they become available and will assist you with your own obligations under Articles 33 and 34 GDPR. We will not notify a supervisory authority or data subjects on your behalf unless you instruct us to or we are legally required to.

12. Return and deletion of data

On termination of the Agreement, or on your earlier instruction, we will delete Customer Personal Data in accordance with the retention and termination provisions of the Agreement and our Privacy Policy. You may export your data before deletion, and account data is deleted within 30 days of account closure. Backup copies are overwritten on their ordinary rotation cycle. We may retain Customer Personal Data only to the extent, and for as long as, we are required to by law, in which case we continue to protect it under this DPA and process it only for the purpose that requires its retention.

13. Audits and compliance information

We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 GDPR and this DPA, including through documentation of our security measures and responses to reasonable security questionnaires. Where that information is insufficient, you may audit our compliance no more than once per year, on at least 30 days’ notice, during business hours, subject to confidentiality undertakings and without unreasonable disruption to our operations. We may charge a reasonable fee for audit support that goes materially beyond providing existing documentation.

14. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party’s liability where such limitation is not permitted by data protection law, or affects a data subject’s rights under Article 82 GDPR.

15. Term and survival

This DPA takes effect when you accept the Agreement, or when we first process Customer Personal Data for you if earlier, and continues for as long as we process Customer Personal Data on your behalf. The provisions on confidentiality, audit, deletion, liability, and governing law survive its termination.

16. Changes to this DPA

We may update this DPA to reflect changes in data protection law or in the service. For material changes affecting existing customers we will give at least 30 days’ notice (shorter where an urgent legal or security matter requires it). The date at the top of this page shows when it was last updated. Continued use of the service after a change takes effect constitutes acceptance of the updated DPA.

17. Governing law

This DPA is governed by Norwegian law, and disputes will be resolved in the Norwegian courts, consistent with the Governing Law section of the Agreement. This does not deprive a data subject of the protection of mandatory provisions of the law of their habitual residence, nor affect the jurisdiction of a competent supervisory authority.

18. Contact

For any question about this DPA, or to request a counter-signed copy, email [email protected].