Data Processing Addendum
For customers whose own users’ personal data passes through us. Part of the Terms of Service.
Last updated 2026-09-06
Roles
When you send mail through SendSlice, the personal data of your recipients is yours. You are the controller and decide what is sent to whom. We are your processor and act on your instructions. This addendum forms part of the agreement between you and [TO BE SETTLED: registered legal entity name and address].
What we process for you
- Subject matter — delivering transactional email you ask us to send.
- Duration — for as long as your account is open, plus the deletion window in the privacy policy.
- Categories of data subject — the recipients of your mail: your users, customers or staff.
- Types of personal data — email addresses, subject lines, and whatever personal data you choose to merge into a message. Message bodies are not retained; the addresses and subject lines are.
What we commit to
- To process personal data only on your documented instructions, which the API calls you make are.
- To keep it confidential and to bind our people to the same.
- To hold the security measures set out below, and not to weaken them.
- To engage only the sub-processors listed in the privacy policy, and to give notice before adding one, so you can object.
- To help you answer a data subject's request for access, correction or deletion, and to help with a data protection impact assessment if you need one.
- To tell you without undue delay, and in any event within 72 hours of becoming aware, if personal data we hold for you is breached.
- To delete or return the personal data when the agreement ends, apart from suppression records, which we keep so that your former recipients are not mailed again.
- To make available the information you reasonably need to verify all of this.
Security measures
- Everything in transit is over TLS, on the API and to the delivery network.
- Stored data is encrypted at rest by the managed services holding it.
- API keys are stored as hashes, never in a form we could read back.
- Message bodies are never written to disk.
- Access to production runs through short-lived, least-privilege credentials scoped to the specific services in use — no standing administrator keys.
- Deployment is automated from version control and gated on the test suite passing, so a change reaching production has been reviewed and tested.
International transfers
Processing takes place in the United States. If you are in the UK or the EU and transferring personal data to us, that transfer needs an approved mechanism. [TO BE SETTLED: standard contractual clauses — needs counsel]