Skip to content
Legal

Data processing addendum

For customers who need a processor agreement on file. This addendum forms part of the terms of service.

Last updated 13 September 2026

Draft

This document has not yet been reviewed by counsel and is not binding. It is published so you can see the shape of our terms before they are final. The reviewed version will replace it, and the change will appear in the changelog.

Roles

You are the controller of the personal data contained in the mail you send and the contacts you import. Martin Business Consultants, operating OutSend, is the processor. We process that data only on your documented instructions, which for ordinary use means: the actions you take in the product and the API calls you make.

Scope of processing

  • Categories of data — email addresses, names, phone numbers, message content, custom contact properties you define, and delivery event metadata.
  • Categories of data subject — your customers, users, subscribers, and anyone else you send to.
  • Nature and purpose — transmitting email on your behalf and recording what happened to it.
  • Duration — your plan's retention window, or until you delete the data, whichever comes first.

Sub-processors

We use Amazon Web Services for sending and event ingestion, in the region you select per domain, and a payment processor for billing. We will give notice before adding a sub-processor, and you may object. The current list lives here and changes are recorded in the changelog.

Security measures

TLS in transit for the API and the SMTP relay, scoped API credentials with usage timestamps, per-endpoint HMAC webhook signing, per-workspace data isolation, revocable sessions, and rate limiting. The security page describes each of these concretely, and the open-source core lets you verify them rather than take our word.

International transfers

You choose the AWS region each of your domains sends from, which determines where processing happens. Where transfers require a lawful mechanism, standard contractual clauses apply.

Sub-processor incidents and breach notice

We will notify you without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting your data, with what we know at the time and what we are still finding out. Consistent with everything else we publish, you will get the incomplete honest version first rather than a complete late one.

Assistance and audits

We will help you respond to data subject requests and to regulators. For audit rights, the open-source core is the first and best answer: you can read exactly how sending, event storage, and suppression work. For anything that requires more,ask us.

Deletion

On termination we delete your data within 30 days, except where we are legally required to retain records. Export first — contacts and segments export to CSV from inside the product without needing us.