senduler

Data Processing Agreement (DPA)

Last updated: July 2026
Version: 2026-07-ca-us-v1 (bump LegalVersions.Dpa in code when this document changes)

This Data Processing Agreement ("DPA") forms part of the agreement between Adam Williams, operating Senduler ("Processor"), sole proprietorship based in Toronto, Ontario, Canada, and the customer ("Controller") who uses the Senduler form-backend service, together with the Terms of Service.

1. Subject matter

Processor provides a form submission service. Controller embeds forms on websites; visitors submit data that Processor receives, stores, and routes per Controller's configuration.

2. Duration

This DPA applies for the term of the service agreement and until all submission data is deleted or returned.

3. Nature and purpose of processing

Item Detail
Categories of data subjects Website visitors who submit forms
Categories of personal data Names, contact details, messages, files, and technical metadata (IP address, user agent, referer, origin)
Processing operations Receipt, storage, spam filtering, notification, webhook delivery, export, deletion, audit logging
Purpose To receive, store, and deliver form submissions on Controller's behalf
Retention Per Controller's client settings (default 365 days for accepted submissions; shorter default for spam/blocked)

3a. Documented instructions

Controller's instructions are documented through:

  • Form and client settings in the Senduler dashboard (retention, origins, notifications, webhooks, captcha, spam rules)
  • API calls authenticated as Controller's users
  • Use of export, erasure, and compliance tools

Processor will not process submission data for purposes other than providing the Service except where required by law (in which case Processor will inform Controller unless prohibited).

4. Controller obligations

Controller shall:

  • Determine lawful basis for collecting submission data
  • Provide appropriate privacy notices on websites using Senduler forms, including disclosure that data is processed and stored in the United States (see section 8)
  • Not collect special-category data unless legally permitted and technically appropriate
  • Configure retention, access controls, and allowed origins responsibly
  • Honour data subject requests and use Senduler's erasure tools where applicable
  • Accept this DPA (or a superseding version) before processing live visitor submissions — acceptance is required at account registration and again when the DPA version changes
  • Ensure webhook URLs, Slack incoming webhooks, and notification recipients are appropriate; data sent there is under Controller's responsibility

5. Processor obligations

Processor shall:

  • Process personal data only on documented instructions from Controller (including via the Senduler dashboard and API)
  • Ensure personnel with access to personal data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (see section 9)
  • Assist Controller with data subject requests where reasonable, using Senduler's export and erase-by-email tools; Processor responds to Controller within 30 days of a documented request unless a shorter statutory deadline applies to Controller
  • Notify Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Controller's submission data
  • Delete or return submission data at end of service within 30 days after account closure (export available before deletion), subject to legal retention requirements and configured retention periods
  • Make available information necessary to demonstrate compliance with this DPA
  • Maintain a list of sub-processors and notify material changes

6. Sub-processors

Controller authorises Processor to engage the sub-processors listed at the time of acceptance. Processor will:

  • Impose data protection obligations on sub-processors substantially similar to this DPA
  • Notify Controller of intended changes to sub-processors at least 30 days before engagement where practicable (email or in-app notice)
  • Allow Controller to object to new sub-processors on reasonable grounds relating to data protection within 14 days of notice; if the parties cannot resolve the objection, Controller may terminate the affected Service or the agreement

7. International transfers

Processor is based in Toronto, Ontario, Canada. Primary infrastructure and submission data are hosted in the United States.

Where Controller or data subjects are in the UK or European Economic Area (EEA), transfers of personal data to Processor (and its US-hosted infrastructure) are subject to appropriate safeguards, including:

Processor does not rely on the EU-US Data Privacy Framework unless Processor's legal structure changes and certification is obtained.

Where Controller or data subjects are in Canada, Processor remains accountable under PIPEDA for personal information transferred outside Canada and implements contractual and technical safeguards.

8. Data location

Data Location
Form submissions (field data), account data United States — IONOS Cloud VPS (application and PostgreSQL database)
Uploaded files United States — IONOS Cloud Object Storage
Processor operations (support, administration) Toronto, Ontario, Canada

Multi-region hosting options may be offered separately in future.

9. Security

Processor maintains measures including:

  • Encryption in transit (TLS)
  • Encryption at rest for databases and stored files where supported by infrastructure
  • Access controls and authentication for dashboard users
  • Per-form origin allowlists and rate limiting
  • Audit logging for submission access (view, export, download, delete)
  • Webhook HMAC signatures for outbound integrations

Further detail is in the security documentation.

10. Audits

Upon reasonable written request, Processor will provide information about compliance with this DPA. Onsite audits may be conducted no more than once per year with reasonable notice, subject to confidentiality and security restrictions.

11. Liability

Liability is as set out in the Terms of Service, without prejudice to data subjects' rights under applicable law.

12. Acceptance

Controller accepts this DPA by:

  1. Registration — checking the DPA acceptance box when creating an account (acceptDpa: true), recorded with version, timestamp, and accepting user; or
  2. Re-acceptance — clicking Accept DPA in Settings → Compliance when the DPA version changes.

Live form ingestion is blocked until the current DPA version is accepted. A JSON acceptance certificate is available via GET /api/agency/compliance/dpa/certificate.

Acceptance of the DPA incorporates the SCC annex where UK/EEA transfers apply.

Questions: legal@senduler.com

Related documents: Terms of Service · Standard Contractual Clauses annex · Sub-processors · Privacy policy