Mailxify
Legal & Trust

Data Processing Addendum

Effective Date: 2026-09-01
Last Updated: 2026-09-07

DPA — Key Points (Plain English)

This Data Processing Addendum (DPA) governs how Mailxify processes personal data on your behalf as a Data Processor when you use the Service. Please read the full DPA for complete details.

  • Two roles: You (the User/Customer) are the Data Fiduciary (controller) for Recipient data you upload. Mailxify is your Data Processor — processing that data only on your documented instructions.
  • Your responsibility: You are responsible for having lawful grounds to process your Recipients' data and for providing them with appropriate privacy notice.
  • Security: Mailxify implements the technical and organizational measures described in Annex B. These are current, verified measures.
  • Subprocessors: Mailxify uses Vercel (hosting) and Neon (database) as its current infrastructure subprocessors. Both are listed in Annex C.
  • Data deletion: When you close your Account or delete a Workspace, associated Recipient data will be permanently deleted within 30 days.
  • Gmail/AI data: Since Gmail Integration and AI are not yet active, no additional subprocessors process Recipient data at this time.
Data Processing Addendum — Full Text

This Data Processing Addendum ("DPA") is incorporated into and forms part of the Mailxify Terms of Service (/terms) (the "Principal Agreement") between Mailxify ("Processor") and the User or Customer ("Controller") who has accepted the Principal Agreement. Terms defined in the Principal Agreement and not defined herein have the meanings given to them in the Principal Agreement.

1. Definitions

In this DPA:

  • "Applicable Data Protection Law" means the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 (SPDI Rules), and any successor legislation, to the extent applicable to the respective party's processing activities.
  • "Controller" (or "Data Fiduciary" under the DPDPA) means the User or Customer who determines the purposes and means of processing Customer Personal Data. The Controller is the party responsible for the lawfulness of collection, the provision of notice to Data Principals, and the overall compliance of the data processing arrangement.
  • "Customer Personal Data" means all personal data of Recipients (Contacts) uploaded by the Controller into the Service, and any other personal data that the Controller causes to be processed by Mailxify as Processor in connection with the Service. Customer Personal Data does not include personal data that Mailxify processes as a Controller in its own right (e.g., Account registration data of Users), which is governed by the Privacy Policy.
  • "Data Incident" means any confirmed or credibly suspected unauthorized access to, disclosure of, alteration of, or destruction of Customer Personal Data, or any unlawful processing of Customer Personal Data.
  • "Data Principal" means the natural person (Recipient / Contact) to whom Customer Personal Data relates.
  • "Processing" has the meaning given in Applicable Data Protection Law, and "Process" and "Processed" shall be construed accordingly.
  • "Processor" (or "Data Processor" / processing service provider) means Mailxify, acting on the documented instructions of the Controller to process Customer Personal Data.
  • "Security Measures" means the technical and organizational security measures described in Annex B to this DPA.
  • "Subprocessor" means any third-party service provider engaged by Mailxify to carry out processing of Customer Personal Data on behalf of Mailxify in connection with providing the Service.

2. Scope & Applicability

2.1 This DPA applies to all processing of Customer Personal Data carried out by Mailxify in connection with providing the Service to the Controller. It sets out the subject matter, duration, nature, purpose, and categories of personal data processed, as described in Annex A.

2.2 This DPA applies to the processing of Customer Personal Data from the date the Controller first uploads or introduces Customer Personal Data into the Service.

2.3 To the extent that Mailxify processes any personal data of the Controller's personnel or other individuals in connection with managing the commercial relationship (e.g., billing contacts), such processing is governed by the Privacy Policy, not this DPA.

2.4 This DPA does not apply to personal data that Mailxify processes as a Controller in its own right (e.g., Account registration data, session logs, support records). Such processing is governed exclusively by the Privacy Policy.

3. Processing Roles

3.1 Acknowledgement of Roles. The parties acknowledge and agree that:

  • The Controller is the Data Fiduciary for Customer Personal Data;
  • Mailxify is the Data Processor, processing Customer Personal Data only on behalf of and under the documented instructions of the Controller;
  • Where Mailxify engages a Subprocessor, Mailxify acts as a controller of that sub-processing relationship and the Subprocessor is a sub-processor.

3.2 Nature of Mailxify's Processing. Mailxify processes Customer Personal Data only to the extent strictly necessary to provide the Service as described in the Principal Agreement and this DPA. Mailxify does not process Customer Personal Data for its own independent purposes, except as required by Applicable Law.

4. Documented Instructions

4.1 Mailxify shall process Customer Personal Data only on the documented instructions of the Controller. The Controller's instructions are set out in: (a) the Principal Agreement (including these Terms); (b) this DPA; and (c) any additional written instructions provided by the Controller through the Service interface or in writing to Mailxify's support contact.

4.2 The parties agree that the Principal Agreement and this DPA constitute complete documented processing instructions at the date of execution. The Controller may provide additional specific instructions during the term of the Agreement; such instructions must be within the scope of the Service and must not require Mailxify to act in violation of Applicable Law.

4.3 If Mailxify reasonably believes that a Controller instruction would require Mailxify to violate Applicable Data Protection Law, Mailxify shall notify the Controller in writing as soon as reasonably practicable, providing reasonable detail of Mailxify's concern. Mailxify may suspend compliance with the relevant instruction pending the Controller's response, without liability to the Controller for such suspension.

4.4 Mailxify shall not process Customer Personal Data in a manner that is inconsistent with the documented instructions, except where required to do so by Applicable Law, in which case Mailxify will notify the Controller of that legal requirement before processing, unless Applicable Law prohibits such notification on grounds of public interest.

5. Customer / Controller Responsibilities

5.1 The Controller is solely responsible for:

  • The lawfulness of all Customer Personal Data uploaded into the Service, including the manner in which it was collected;
  • Ensuring that a valid legal basis (under Applicable Data Protection Law) exists for the processing of each Data Principal's personal data in the Service;
  • Providing appropriate privacy notices and, where required, obtaining the necessary consents from Data Principals before their personal data is introduced into the Service;
  • Ensuring that Customer Personal Data introduced into the Service is accurate, relevant, adequate, and limited to what is necessary for the stated outreach purpose;
  • Maintaining records of processing activities as required by Applicable Data Protection Law in respect of the Controller's own processing;
  • Complying with all applicable anti-spam, privacy, and consumer protection laws governing outbound communication in each jurisdiction where Recipients are located; and
  • Responding to Data Principal rights requests in respect of Customer Personal Data, with reasonable assistance from Mailxify as described in Section 9.

5.2 The Controller warrants that: (a) it has the authority to instruct Mailxify to process Customer Personal Data on its behalf; (b) its instructions to Mailxify comply with Applicable Data Protection Law; and (c) it will promptly inform Mailxify of any change to the nature of Customer Personal Data or the processing instructions that may affect Mailxify's compliance obligations.

6. Confidentiality of Processing

6.1 Mailxify shall ensure that all personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations, whether by contract, professional rules, or applicable law. Mailxify shall not disclose Customer Personal Data to any unauthorized person.

6.2 The confidentiality obligation in this Section 6 applies to Mailxify's employees, contractors, and service providers who access Customer Personal Data in connection with providing the Service. Mailxify shall ensure that such persons process Customer Personal Data only to the extent necessary to perform their authorized functions.

6.3 The confidentiality obligation survives the termination of this DPA and the Principal Agreement for so long as Customer Personal Data remains in Mailxify's possession.

7. Security of Processing

7.1 Mailxify shall implement and maintain the Security Measures described in Annex B to protect Customer Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. The Security Measures are designed to provide a level of security appropriate to the risk presented by the processing of Customer Personal Data.

7.2 In assessing the appropriate level of security, Mailxify has taken into account the nature, scope, context, and purposes of processing, including the risks to Data Principals of varying likelihood and severity. The current Security Measures are described in Annex B.

7.3 Mailxify may update the Security Measures from time to time, provided that updates shall not result in a material degradation of the security protections provided.

7.4 The Controller acknowledges that it is responsible for implementing appropriate security measures at its own end, including in respect of its access to the Service, the security of its Account credentials, and the security of any data exported from the Service.

8. Subprocessors

8.1 Existing Subprocessors. The Controller authorizes Mailxify to engage the Subprocessors listed in Annex C to this DPA. These are the infrastructure providers that Mailxify uses to provide the Service. Mailxify has entered into (or will enter into before onboarding) data processing agreements with each Subprocessor that impose data protection obligations at least as protective as those in this DPA.

8.2 New Subprocessors. Before engaging any new Subprocessor that will process Customer Personal Data, Mailxify will update the Subprocessors list at /subprocessors and, where reasonably practicable, provide the Controller with not less than fourteen (14) days' prior notice. The current mechanism for such notification is via the published changelog on the Subprocessors page.

8.3 Controller Objection. If the Controller has a legitimate, reasoned objection to the engagement of a new Subprocessor (based on a genuine concern that the new Subprocessor cannot provide the required level of data protection), the Controller must notify Mailxify in writing within fourteen (14) days of the subprocessor notice. Mailxify will use reasonable commercial efforts to accommodate the objection. If the objection cannot be resolved, the Controller may terminate the Service in accordance with the Principal Agreement without penalty.

8.4 Mailxify Responsibility for Subprocessors. Mailxify shall be responsible for the acts and omissions of its Subprocessors in relation to Customer Personal Data to the same extent as if Mailxify had performed the processing directly, subject to the limitations of liability set out in the Principal Agreement.

9. Data Principal Rights Requests

9.1 As the Controller, the Customer is responsible for responding to rights requests from Data Principals in respect of Customer Personal Data. Mailxify, as Processor, will not respond independently to Data Principal requests relating to Customer Personal Data unless instructed to do so by the Controller or required to do so by Applicable Law.

9.2 If Mailxify receives a rights request directly from a Data Principal in respect of Customer Personal Data (e.g., an Unsubscribe request or a data deletion request received by Mailxify), Mailxify will, where reasonably possible, direct the Data Principal to contact the Controller and will promptly notify the Controller of the request.

9.3 Mailxify will provide the Controller with reasonable technical assistance to enable the Controller to respond to Data Principal rights requests, including by:

  • Providing the ability to search and export Contact data from the Workspace;
  • Providing the ability to delete individual Contact records from the Workspace;
  • Providing the ability to suppress specific email addresses from further Campaign sending.

9.4 Any assistance provided by Mailxify under this Section 9 that requires significant engineering effort beyond the standard Service functionality may be subject to reasonable cost reimbursement, which Mailxify will discuss with the Controller in advance.

11. Personal Data Incidents

11.1 Detection & Assessment. Mailxify shall implement reasonable monitoring and detection procedures to identify potential Data Incidents affecting Customer Personal Data.

11.2 Notification to Controller. Upon becoming aware of a confirmed Data Incident affecting Customer Personal Data, Mailxify shall notify the Controller without undue delay and in any event within seventy-two (72) hours of becoming aware of the incident (or within such shorter period as required by Applicable Law). The notification shall include, to the extent then known:

  • A description of the nature of the Data Incident, including the categories and approximate number of Data Principals affected;
  • The categories and approximate volume of Customer Personal Data records affected;
  • The likely consequences of the Data Incident;
  • The measures taken or proposed by Mailxify to address the Data Incident and mitigate its effects;
  • A designated contact point for further information.

11.3 Mitigation. Mailxify shall take reasonable and prompt remediation action to contain, mitigate, and recover from any confirmed Data Incident, and shall cooperate with the Controller and relevant authorities in the investigation and remediation of the incident.

11.4 Controller Notification Obligations. The Controller is responsible for determining whether and how to notify Data Principals and relevant regulatory authorities of a Data Incident affecting Customer Personal Data. Mailxify will provide reasonable assistance to the Controller in preparing any required notifications.

11.5 CERT-In Compliance. To the extent that Mailxify constitutes a "body corporate" under the Information Technology Act, 2000 that is subject to CERT-In incident reporting directions, Mailxify will comply with the applicable CERT-In directions, including the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, as amended. Regulatory incident reporting obligations apply to qualifying security incidents affecting Mailxify's own systems; they do not independently obligate the Controller to report incidents to CERT-In, which is a separate determination the Controller must make based on its own legal position.

12. Assistance & Cooperation

12.1 Mailxify shall provide the Controller with reasonable assistance, taking into account the nature of processing and the information available to Mailxify, to enable the Controller to:

  • Ensure compliance with the Controller's security obligations under Applicable Data Protection Law;
  • Conduct and document data protection impact assessments where required;
  • Consult with the relevant Data Protection Authority where required following a data protection impact assessment; and
  • Respond to Data Principal rights requests as described in Section 9.

12.2 The extent of assistance provided by Mailxify under this Section 12 is limited to what is reasonably achievable within the standard Service functionality, without requiring bespoke development, unless otherwise agreed in writing.

13. Deletion & Return of Data

13.1 Upon termination or expiration of the Principal Agreement, or upon a written request from the Controller, Mailxify shall, at the Controller's election:

  • Permanently delete all Customer Personal Data in Mailxify's possession or control (including copies held by Subprocessors); or
  • Return all Customer Personal Data to the Controller in a portable electronic format (CSV or equivalent) before deletion.

13.2 Deletion shall be completed within thirty (30) days of the termination date or written deletion request, whichever is applicable.

13.3 Mailxify may retain Customer Personal Data beyond the deletion period described in Section 13.2 to the extent and for the duration required by Applicable Law (e.g., security/audit log retention obligations). Mailxify shall inform the Controller of any such retained data and the legal basis for retention.

13.4 Mailxify shall ensure that all Subprocessors are subject to equivalent deletion obligations and shall confirm to the Controller, upon request, that Customer Personal Data held by Subprocessors has been deleted.

14. Audits & Information

14.1 Mailxify shall make available to the Controller, upon written request, reasonable information demonstrating Mailxify's compliance with this DPA. In the first instance, Mailxify will provide responses to written questionnaires, access to documentation, and access to relevant third-party certifications (where available).

14.2 Where the Controller has a genuine, documented concern regarding Mailxify's compliance with this DPA that cannot be resolved through the information provision in Section 14.1, the Controller may request a more detailed audit. Any such audit shall be: (a) limited in scope to Mailxify's processing of Customer Personal Data; (b) conducted at the Controller's own expense; (c) conducted on reasonable notice (not less than thirty (30) days); (d) conducted during normal business hours; and (e) designed to minimize disruption to Mailxify's operations.

14.3 Mailxify may object to a proposed auditor where there is a reasonable basis for concern that the proposed auditor is a competitor of Mailxify or lacks appropriate confidentiality credentials.

15. International Processing

15.1 The Controller acknowledges that Mailxify's infrastructure providers may store or process Customer Personal Data on servers located outside India, including servers located in the United States and other regions. The current infrastructure regions are described in Annex C.

15.2 Mailxify will ensure that any transfer of Customer Personal Data outside India is subject to adequate contractual safeguards as required under the DPDPA and any cross-border data transfer regulations notified by the Central Government. Currently, Mailxify relies on contractual obligations in its agreements with Subprocessors (Vercel Inc. and Neon Inc.) to ensure an appropriate level of protection.

15.3 Mailxify will update this DPA and the Annex C listing if the infrastructure regions change in a manner that materially affects the cross-border transfer picture.

16. Liability & Relationship to Terms

16.1 Each party shall be liable to the other for any damages caused by its breach of this DPA, subject to the limitations and exclusions of liability set out in the Principal Agreement (Terms of Service).

16.2 The aggregate liability of either party under this DPA shall not exceed the aggregate liability cap set out in the Principal Agreement.

16.3 In the event of any conflict between this DPA and the Principal Agreement regarding the processing of Customer Personal Data, this DPA shall prevail. In all other respects, the Principal Agreement governs the relationship between the parties.

16.4 For the avoidance of doubt, any liability arising from the Controller's breach of its obligations under Section 5 (Controller Responsibilities) — including the unlawful collection or processing of Customer Personal Data before it is introduced into the Service — is the Controller's sole liability.

17. Termination

17.1 This DPA shall terminate automatically upon the termination or expiration of the Principal Agreement.

17.2 Sections 4, 6, 7, 11, 13, and 16 of this DPA shall survive its termination for so long as Mailxify retains any Customer Personal Data.


Annex A — Processing Details

A.1 Subject Matter of Processing

The processing of Customer Personal Data by Mailxify as Processor, for the purpose of providing the Mailxify email outreach automation platform and associated services to the Controller.

A.2 Duration of Processing

For the duration of the Principal Agreement, and for such additional period as is necessary to comply with deletion obligations, legal retention requirements, or to resolve subsisting disputes.

A.3 Nature of Processing

Storage, organization, retrieval, display, and (when Gmail Integration is activated) transmission of Customer Personal Data, as required to provide the Service's Campaign management and outreach automation functionality.

A.4 Purposes of Processing

  • Storing and organizing Recipient (Contact) records within the Controller's Workspace;
  • Enabling the Controller to compose, preview, schedule, and execute Campaign Messages;
  • Applying Personalization Variables to Message templates using Contact field data at time of transmission;
  • Enforcing Workspace-level Suppression Lists;
  • When Gmail Integration is activated: transmitting Messages through the Controller's authorized Gmail or Google Workspace account on behalf of the Controller; and
  • Providing technical support and assistance to the Controller in the operation of the Service.

A.5 Categories of Customer Personal Data Processed

  • Email addresses of Recipients (mandatory for sending);
  • First names, last names (where provided by the Controller);
  • Company names and job titles (where provided by the Controller);
  • Any custom fields uploaded by the Controller (which may include additional professional or contextual information about Recipients).

The Controller is responsible for ensuring that custom fields do not contain special category personal data (including health data, financial data, or other sensitive categories of personal data) unless the Controller has a specific lawful basis for processing such data and has disclosed this to Mailxify.

A.6 Categories of Data Principals

The Data Principals are Recipients (Contacts) whose personal data is uploaded by the Controller, typically consisting of business professionals, prospective clients, or other individuals the Controller intends to contact for legitimate B2B outreach purposes.

Annex B — Security Measures

The following security measures are currently in place for Mailxify's processing of Customer Personal Data. These are verified, operational controls as of the Effective Date. Claims of future planned controls are excluded.

B.1 Encryption in Transit

All data transmitted between Users' browsers and the Mailxify application, and between the Mailxify application and its database, is encrypted using TLS (Transport Layer Security) version 1.2 or higher. TLS is enforced by Vercel's infrastructure on all application endpoints and by Neon's database connection requirements (sslmode=require).

B.2 Authentication Security

  • Password Hashing: User passwords are hashed using industry-standard one-way cryptographic hash functions (bcrypt or equivalent) before storage. Plaintext passwords are never stored or transmitted after initial validation.
  • Session Management: Authentication sessions are managed using cryptographically signed, httpOnly cookies (generated by the better-auth authentication framework). Session tokens are stored with expiry timestamps and are invalidated upon logout.
  • Session Database Records: Active sessions are recorded in the database with associated IP address and User Agent for security monitoring and anomaly detection.

B.3 Database Access Control

  • The Mailxify application connects to its database using authenticated credentials managed via environment variables, not hardcoded in source code.
  • The Neon database is not publicly accessible without authentication credentials.
  • Connection to Neon's database requires SSL/TLS (channel_binding=require).

B.4 Application-Level Security

  • SQL Injection Prevention: Database queries are constructed using the Drizzle ORM, which employs parameterized queries and prepared statements, substantially reducing the risk of SQL injection vulnerabilities.
  • Server-Side Authorization: All data access in the application is protected by server-side authorization checks. Client-side role assertions are not trusted; authorization is verified at the API layer on every request.
  • Workspace Isolation: The application enforces workspace-level data isolation. Queries are scoped to the authenticated User's Workspace, preventing cross-workspace data access.
  • Input Validation: Form inputs and API parameters are subject to server-side validation and length limits before database operations.

B.5 Infrastructure Security

  • Hosting: The application is hosted on Vercel, which maintains its own SOC 2 Type II certified infrastructure, including physical and network security controls.
  • Database: The database is hosted by Neon Inc., which maintains its own security controls, including encryption at rest for database storage.

B.6 Future Security Measures

Application-level AES-256-GCM encryption of Gmail OAuth tokens will be implemented before the Gmail Integration is activated. This measure is described here to document the planned security architecture; it is not currently in place and is not counted as an active control.

Annex C — Current Subprocessors

The following is the complete list of Subprocessors currently engaged by Mailxify to process Customer Personal Data in connection with providing the Service.

SubprocessorService ProvidedData LocationPrivacy Reference
Vercel Inc.Application hosting, serverless functions, CDN, and TLS terminationGlobal (US-primary), routed via nearest edge node. Serverless functions may execute in multiple regions.vercel.com/legal/privacy-policy
Neon Inc.Managed serverless PostgreSQL database. Stores User accounts, workspace data, Contacts, Campaigns, and legal request records.ap-southeast-1 (Singapore region, AWS infrastructure)neon.tech/privacy-policy

Note: The following subprocessors are anticipated but are NOT currently active because the relevant features are not yet operational:

  • Google LLC (Gmail API): Will be listed as a subprocessor when Gmail Integration is activated. Not currently processing any Customer Personal Data.
  • AI Provider (To Be Determined): An AI language model provider will be listed and disclosed before any AI Feature is activated. Not currently processing any Customer Personal Data.
  • Payment Processor (To Be Determined): A payment gateway provider will be listed and disclosed before commercial billing is activated. Not currently processing any financial data.