Legal

Data processing agreementDraft

How we process the personal data of the people you email, on your instructions, as your Data Processor under the DPDP Act.

Draft — pending legal review. This text has not been reviewed by a lawyer and is not yet in force. Last edited 22 Sep 2026.

1. Parties and roles

This agreement is part of the terms of service between you, the customer, and the company to be named at legal review (“Refiremail”, “we”). For the personal data you send through the service, you are the Data Fiduciary and we are your Data Processor, as the Digital Personal Data Protection Act, 2023 (the DPDP Act) uses those words. Section 8(2) of the Act lets a fiduciary engage a processor only under a valid contract. This is that contract.

If you are an agency processing your clients’ data, you act for your clients and we act as your sub-processor. You confirm that your agreement with each client allows this.

2. What we process, and why

Subject matter
Providing Refiremail to you.
Duration
The term of the agreement, plus the deletion period in section 11.
Nature
Collecting (through your forms, imports and API calls), storing, organising, sending, receiving, recording delivery and engagement, reporting, and deleting.
Purpose
To send the email you instruct us to send, receive email addressed to your inbound addresses, and keep the records the service needs to work lawfully, such as the suppression list and consent records.

3. Whose data, and what data

Data principals

  • your contacts and subscribers;
  • people who fill in your signup forms;
  • people who email your inbound addresses;
  • your users who receive your transactional email;
  • your team members, as far as they appear in your content.

Personal data

  • email addresses, names, and any other contact properties you choose to store;
  • topic subscriptions and segment membership;
  • consent records: the notice shown, the source, the time, and the IP address and user agent;
  • message content and attachments;
  • delivery and engagement events (delivered, bounced, opened, clicked, complained), with IP address and user agent where available;
  • inbound email content, headers and authentication results;
  • form submissions.

Store only what you need. Do not put identity numbers such as Aadhaar or PAN, bank or card details, or health information into contact properties unless you have a clear need and a lawful basis for it.

4. Processing only on your instructions

We process your personal data only to provide the service, as instructed by the terms, your settings, and the actions you take in the dashboard and through the API. If we believe an instruction breaks the law, we will tell you. If the law requires us to process your data in some other way, we will tell you first, unless the law forbids that.

5. Confidentiality

Everyone at Refiremail who can access your personal data is bound by a duty of confidentiality, and gets access only when their work needs it.

6. Security safeguards

We maintain reasonable security safeguards to prevent personal data breaches, as section 8(5) of the DPDP Act requires, including those on our security page. These are built into the product:

  • API keys stored only as SHA-256 hashes
  • DKIM private keys encrypted at rest with AES-256-GCM
  • Every tenant table is keyed by team, and the database refuses a reference that crosses teams

7. Sub-processors

We use other companies to help run the service, such as email delivery and DNS. The current list, with what each one does and where, is in our privacy policy. We bind each of them to data protection terms at least as protective as this agreement, and we remain responsible for their work.

We will email you at least 30 days before we add or replace a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may end the affected service, and we will refund the unused part of any fees you paid in advance.

8. Helping with requests from data principals

The service gives you the tools to answer your contacts’ requests yourself: look up, correct, export or delete a contact, and see its consent history. If a request about your data reaches us directly, we pass it to you and do not answer it ourselves unless you ask us to. Where you need more help to meet a request, we will give it.

9. Personal data breaches

If we become aware of a breach affecting your personal data, we will tell you without undue delay, and in any case within a deadline set at legal review. We will share what we know: what happened, the data and people affected, the likely consequences, and what we are doing about it. We will keep you updated and help you meet your own duty to inform the Data Protection Board of India and the people affected under section 8(6) of the DPDP Act.

10. Where the data is processed

  • Contacts and message content are stored in IndiaComing
  • Mail is sent from the ap-south-1 (Mumbai) region

We will not transfer your personal data outside India except to the sub-processors listed for that purpose, and never to a country the Central Government has restricted under section 16 of the DPDP Act.

11. Deletion and return

While the agreement runs, sent email records are deleted 90 days after sending, and you can export your contacts and other data at any time.

When you delete your team, or the agreement ends, we keep your data for 30 days so it can be restored, then delete it. Copies in backups are removed as those backups expire, within a further 30 days. We keep only what the law requires us to keep, such as tax invoices, which hold no data about your contacts.

12. Information and audits

We will give you the information you reasonably need to show that this agreement is being followed. Once a year, with 30 days’ notice, you may have an independent auditor who is bound by confidentiality check our compliance, at your cost and in a way that does not expose other customers’ data.

13. If documents disagree

Where this agreement and the terms of service disagree about personal data, this agreement applies. Questions about it: [email protected]. It is a draft and takes effect only after legal review, when the Draft label comes off this page.