senduler

Standard Contractual Clauses — Annex

Last updated: July 2026
Version: 2026-07-ca-us-v1

This annex forms part of the Data Processing Agreement between the Controller (Senduler customer) and Adam Williams, operating Senduler, as Processor.

When this annex applies

This annex applies when the Controller (or data subjects whose personal data Controller collects) is in the UK or European Economic Area (EEA) and personal data is transferred to Senduler for processing on infrastructure in the United States.

Senduler is operated by Adam Williams from Toronto, Ontario, Canada and hosts data on servers in the United States (application and database on IONOS Cloud VPS, US; uploaded files on IONOS Cloud Object Storage, United States). The transfer chain is: EEA/UK data subject → Controller → Senduler (processor) → US-hosted storage and sub-processors.

Mechanism

The parties agree to the EU Commission Standard Contractual Clauses for the transfer of personal data to third countries, Module Two (Controller to Processor), as adopted by Commission Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum (UK IDTA) issued by the UK Information Commissioner's Office, where UK GDPR applies.

Incorporation: By accepting the DPA (at registration or in Settings → Compliance), Controller and Processor agree that these SCCs and the UK IDTA (where applicable) are incorporated into the DPA as if set out in full. This annex completes Annexes I–III below.


Annex I — List of parties

Data exporter (Controller):
The Senduler customer who accepts the DPA and configures forms. Name and address: as registered in the Senduler account.

Data importer (Processor):
Adam Williams, operating Senduler (sole proprietorship)
Toronto, Ontario, Canada
Contact: privacy@senduler.com

Role: Processor processes personal data on documented instructions from Controller only.


Annex II — Description of transfer

Item Detail
Categories of data subjects Website visitors who submit forms on Controller's sites
Categories of personal data Contact details, messages, file uploads, technical metadata (IP, user agent)
Sensitive data Not intended; Controller must not collect special-category data without lawful basis
Frequency Continuous, as forms are submitted
Nature of processing Receipt, storage, spam filtering, notification, webhooks, export, deletion per Controller settings
Purpose Form submission handling on Controller's behalf
Retention Per Controller's configured retention (default 365 days for accepted submissions; 30 days default for spam/blocked); auto-deletion thereafter
Sub-processors Listed at /legal/sub-processors; primarily US-based

Destination country: United States (primary hosting). Processor administration from Toronto, Ontario, Canada.

Transfer Impact Assessment: Controller is responsible for any Transfer Impact Assessment their organisation requires. Processor provides this annex, the sub-processor list, and security documentation to support that assessment.


Annex III — Technical and organisational measures

Processor implements measures described in DPA section 9 and security documentation, including:

  • TLS for data in transit
  • Access controls for dashboard and API
  • Tenant isolation between customers
  • Rate limiting and origin controls
  • Submission access audit log
  • Retention and erasure tooling (including erase-by-email for data subject requests)
  • Incident response with breach notification to Controller within 72 hours

Sub-processing in the United States

Controller authorises Processor to use US-hosted infrastructure and the sub-processors listed at acceptance. Processor ensures sub-processors are bound by data protection obligations consistent with this annex.


What Senduler does not rely on (v1)

Senduler does not currently rely on the EU-US Data Privacy Framework as a transfer mechanism.


How to use this document

  1. Accept the DPA at registration or in Senduler Settings → Compliance.
  2. Download the acceptance certificate from GET /api/agency/compliance/dpa/certificate if needed for your records.
  3. Retain this annex with your privacy documentation.
  4. Ensure your website privacy notice discloses Senduler, US storage, and international transfers.

Questions: legal@senduler.com