Data processing agreement
Last updated 2026-09-10
This agreement under article 28 GDPR is concluded when you create a Veltic Send account. You are the controller; Veltic Send is the processor.
Subject, duration and purpose
The processor accepts email messages from the controller and delivers them to the recipients the controller names. Processing lasts for the duration of the contract. The purpose is the delivery of the controller's own messages and nothing else.
Categories of data and data subjects
Data: email addresses of senders and recipients, message identifiers, timestamps, delivery status and diagnostic codes returned by receiving servers.
Data subjects: the recipients the controller sends to, and the controller's own staff whose addresses appear as senders.
Message subjects and bodies are not stored by the processor.
Instructions
The processor processes personal data only on documented instructions from the controller. The use of the API constitutes such an instruction. The processor informs the controller if, in its opinion, an instruction infringes data protection law.
Confidentiality
Every person authorised to process the data is bound to confidentiality and, additionally, to telecommunications secrecy under section 3 TDDDG. That obligation continues after the activity ends.
Technical and organisational measures
The processor maintains at least the following measures under article 32 GDPR:
- Transport encryption for all API traffic and opportunistic TLS on outbound mail.
- API keys stored only as SHA-256 hashes; a key is displayed once and cannot be recovered.
- Data minimisation by design: subject lines and message bodies are never written to storage.
- Retention limits: delivery events are deleted after 90 days.
- Separation by tenant: each customer is an isolated Amazon SES tenant with its own reputation and suppression list.
- Hard sending limits enforced before any message is handed to the sub-processor.
Sub-processors
The controller grants general authorisation for the following sub-processors: Amazon Web Services EMEA SARL, Luxembourg for mail delivery, and Cloudflare Germany GmbH for hosting and storage. Processing takes place in AWS eu-north-1, Stockholm, Sweden and in the European Union respectively.
The processor informs the controller at least 30 days before adding or replacing a sub-processor. The controller may object; if the objection cannot be resolved, the controller may terminate.
Assistance and breach notification
The processor assists the controller with requests from data subjects and with obligations under articles 32 to 36 GDPR. A personal data breach is reported to the controller without undue delay and at the latest within 24 hours of becoming aware of it.
Deletion and audit
On termination the processor deletes all personal data within 30 days unless a legal obligation requires retention. The processor makes available the information necessary to demonstrate compliance and permits audits, which may be satisfied by documentation and self-assessment where that is sufficient.