Last updated: 6 June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between SplashSend (“Processor”) and the customer (“Controller”) for the processing of personal data. This DPA applies where the Processor processes personal data on behalf of the Controller in connection with the services provided.
“Personal Data”, “Processing”, “Controller”, “Processor”, and “Data Subject” have the meanings given in the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
The Processor processes Personal Data on behalf of the Controller solely for the purpose of providing the email marketing services described in the Terms of Service. This includes storing contact data, sending marketing emails, tracking email engagement metrics, and managing subscription preferences.
The following categories of personal data are processed: email addresses, names, custom contact properties defined by the Controller, email engagement data (opens, clicks, bounces), subscription preferences, and any additional data the Controller chooses to import or collect via signup forms. Where the Controller has connected Shopify, processing also includes customer purchase history and product catalogue data used solely for audience segmentation, campaign personalisation, and revenue attribution.
Processing continues for the duration of the service agreement. Upon termination, the Controller may export all personal data using the data export feature. All personal data is permanently deleted within 30 days of account closure unless a longer retention period is required by law.
SplashSend shall:
SplashSend uses the following sub-processors to deliver the service:
The Controller is deemed to have given general written authorisation for the use of these sub-processors. SplashSend will notify the Controller before engaging any new sub-processor, giving the Controller the opportunity to object.
Where Personal Data is transferred outside the European Economic Area (EEA), SplashSend ensures that adequate safeguards are in place — including the EU-US Data Privacy Framework (where the receiving provider is certified) and/or Standard Contractual Clauses (SCCs) approved by the European Commission.
SplashSend implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: encryption of data in transit (TLS), access controls and authentication, regular security assessments, and incident response procedures.
SplashSend shall notify the Controller without undue delay after becoming aware of a personal data breach, and in any event within 72 hours. The notification shall describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
For questions about this Data Processing Agreement, please contact us at hello@splashsend.com.