Legal

Data Processing Agreement

Last Updated: February 7, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Slate and Pixel LLC d/b/a GoodPostal ("Processor") and you ("Controller") and governs the processing of personal data by GoodPostal on your behalf. This DPA applies when you use GoodPostal to process personal data of individuals in the European Economic Area (EEA), United Kingdom, or other jurisdictions that require a data processing agreement.

1. Definitions

In this DPA, the following terms have the meanings set out below. Terms not defined here have the meanings given in the GDPR (Regulation (EU) 2016/679) or our Terms of Service.

  • "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject") that is processed by GoodPostal on behalf of the Controller through the Service.
  • "Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
  • "Controller" means you, the GoodPostal user who determines the purposes and means of processing Personal Data (e.g., your contact lists, email campaigns).
  • "Processor" means GoodPostal, which processes Personal Data on behalf of the Controller.
  • "Sub-Processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. Roles and Responsibilities

2.1 Controller (You)

You are the data controller for the Personal Data you upload, import, or input into GoodPostal, including contact email addresses, names, custom fields, and any other data stored in your workspace. You are responsible for ensuring that you have a lawful basis to process this data, that you have obtained necessary consents from Data Subjects, and that you comply with all applicable data protection laws.

2.2 Processor (GoodPostal)

GoodPostal acts as a data processor with respect to the Personal Data you store and process through the Service. We process Personal Data only on your documented instructions (as set out in this DPA and your use of the Service's features), except where required by applicable law.

3. Scope and Purpose of Processing

3.1 Categories of Data Subjects

  • Your email contacts and subscribers
  • Individuals who submit data through your subscription forms

3.2 Categories of Personal Data

  • Email addresses
  • Names (first and last)
  • Custom fields defined by the Controller
  • Subscription and consent status
  • Email engagement data (opens, clicks, bounces, complaints)

3.3 Purpose of Processing

Personal Data is processed for the following purposes:

  • Storing and managing contact lists as directed by the Controller
  • Sending email campaigns through the Controller's chosen email sending service
  • Recording and displaying email engagement analytics
  • Processing subscription form submissions
  • Managing unsubscribe requests and consent records
  • Processing sending service webhook events (delivery, bounce, complaint notifications)

3.4 Duration of Processing

Processing continues for the duration of the Controller's use of the Service, and for 30 days following account termination (to allow data export), after which data is deleted as described in Section 12.

4. Processor Obligations

As a data processor, GoodPostal shall (in accordance with GDPR Article 28):

  • Process Personal Data only on the Controller's documented instructions, unless required by Union or Member State law to which the Processor is subject.
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organizational security measures as described in Section 7.
  • Engage Sub-Processors only with the Controller's authorization and subject to the requirements in Section 6.
  • Assist the Controller in responding to Data Subject requests as described in Section 8.
  • Assist the Controller in ensuring compliance with security, breach notification, data protection impact assessment, and prior consultation obligations.
  • Delete or return all Personal Data to the Controller upon termination, as described in Section 12.
  • Make available all information necessary to demonstrate compliance and allow for audits as described in Section 11.

5. Controller Obligations

As the data controller, you shall:

  • Ensure that you have a valid legal basis for processing all Personal Data you store in GoodPostal.
  • Obtain all necessary consents from Data Subjects before uploading their data to the Service.
  • Comply with all applicable data protection laws when sending emails through the Service.
  • Provide clear privacy notices to your contacts that disclose your use of GoodPostal as a data processor and describe the email tracking mechanisms used.
  • Promptly notify GoodPostal of any Data Subject requests that require our assistance.

6. Sub-Processors

6.1 Authorized Sub-Processors

The Controller provides general authorization for the Processor to engage Sub-Processors. The following Sub-Processors are currently authorized:

Sub-ProcessorPurposeData ProcessedLocation
Stripe, Inc.Payment processingBilling name, email, payment detailsUnited States
Your Email Sending Service*Email deliveryRecipient email addresses, email contentVaries by provider

*Your email sending service (Amazon SES, SendGrid, Mailgun, Postmark, SMTP2GO, Mailtrap, or your SMTP server) is selected and configured by you. You are responsible for reviewing your sending service's data processing practices and entering into a separate DPA with your sending service if required. GoodPostal transmits data to your sending service solely on your instruction when you send a campaign.

6.2 Changes to Sub-Processors

We will notify the Controller by email at least 30 days before engaging a new Sub-Processor or replacing an existing one. The Controller may object to the new Sub-Processor within 30 days of notification. If the Controller objects and we cannot reasonably accommodate the objection, the Controller may terminate the Service by providing written notice.

6.3 Sub-Processor Obligations

We ensure that all Sub-Processors are bound by data protection obligations no less protective than those set out in this DPA, as required by GDPR Article 28(4).

7. Technical and Organizational Security Measures

GoodPostal implements the following measures to protect Personal Data, as required by GDPR Article 32:

7.1 Encryption

  • All data in transit is encrypted using TLS 1.2 or higher (HTTPS).
  • Sensitive data at rest (sending service API keys, SMTP credentials, webhook signing keys) is encrypted using AES-256 via Laravel's built-in encryption.
  • Passwords are hashed using bcrypt and never stored in plaintext.

7.2 Access Controls

  • Multi-tenant architecture with application-level tenant isolation. Each workspace's data is logically separated through scoped database queries (HasTenant trait with TenantScope global scope).
  • Two-factor authentication (TOTP) available for all users.
  • Rate limiting on authentication and sensitive endpoints.

7.3 Application Security

  • CSRF protection on all form submissions.
  • Input validation and sanitization on all user inputs.
  • Parameterized database queries to prevent SQL injection.
  • Regular dependency updates and security patching.
  • Sending service webhook signature verification (HMAC-SHA256 for SendGrid and Mailgun, JSON signature verification for Postmark) to prevent forged webhook events.

7.4 Data Backup and Recovery

  • Regular database backups.
  • Backup data is encrypted and access-restricted.

8. Data Subject Rights

When a Data Subject exercises their rights under GDPR (Articles 15-22), including the right of access, rectification, erasure, restriction, portability, or objection:

  • The Controller is responsible for responding to Data Subject requests directed at their contact data.
  • GoodPostal provides tools for the Controller to fulfill these requests, including the ability to view, edit, export (CSV), and delete contact records within the Service.
  • If GoodPostal receives a Data Subject request directly, we will notify the Controller promptly and will not respond to the Data Subject without the Controller's instruction, unless required by law.
  • GoodPostal will provide reasonable assistance to the Controller in fulfilling Data Subject requests, taking into account the nature of the processing.

9. Data Breach Notification

In accordance with GDPR Article 33:

  • GoodPostal shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Data Breach affecting Personal Data processed on behalf of the Controller.
  • The notification shall include, to the extent available: a description of the nature of the Data Breach (including categories and approximate number of Data Subjects and records affected); the name and contact details of the point of contact for further information; a description of the likely consequences of the Data Breach; and a description of the measures taken or proposed to address the Data Breach.
  • GoodPostal shall cooperate with the Controller and provide reasonable assistance in investigating, mitigating, and remediating the Data Breach.
  • The Controller is responsible for determining whether to notify the relevant supervisory authority and affected Data Subjects, as required by GDPR Articles 33 and 34.

10. International Data Transfers

GoodPostal operates from the United States. Personal Data processed through the Service is transferred to and stored in the United States.

For transfers of Personal Data from the EEA or UK to the United States, we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission (Commission Implementing Decision (EU) 2021/914). The SCCs are incorporated into this DPA by reference and apply as follows:

  • Module Two (Controller to Processor) applies to the transfer of Personal Data from the Controller to GoodPostal.

Where required by applicable law, we will implement additional safeguards (such as encryption and access controls) to protect Personal Data during and after transfer.

11. Audit Rights

The Controller has the right to audit GoodPostal's compliance with this DPA, subject to the following conditions:

  • The Controller must provide at least 30 days' written notice before conducting an audit.
  • Audits shall be conducted during normal business hours and shall not unreasonably disrupt GoodPostal's operations.
  • Audits shall be limited to once per 12-month period, unless a Data Breach has occurred or a supervisory authority requires an audit.
  • The Controller shall bear its own costs of the audit.
  • GoodPostal may satisfy audit requests by providing relevant certifications, audit reports, or other documentation that demonstrates compliance with this DPA.
  • The Controller and its auditors must agree to reasonable confidentiality obligations regarding any information accessed during the audit.

12. Data Deletion on Termination

Upon termination of the Controller's account or upon written request:

  • GoodPostal will provide the Controller with the ability to export all Personal Data in a structured, commonly used, machine-readable format (CSV) for a period of 30 days following termination.
  • After the 30-day export period, GoodPostal will delete all Personal Data from its active systems, including contact lists, email content, templates, campaign data, and analytics.
  • Personal Data in backups will be deleted when the backup rotation cycle completes, not to exceed 90 days from the deletion of active data.
  • GoodPostal may retain anonymized, aggregated data that cannot be used to identify any individual.
  • GoodPostal may retain data where required by applicable law (e.g., billing records retained for tax purposes as described in our Privacy Policy).

13. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection law to the extent such limitation is not permitted by applicable law.

14. Term and Termination

This DPA takes effect when you create a GoodPostal account and remains in effect for as long as GoodPostal processes Personal Data on your behalf. Termination of the Terms of Service automatically terminates this DPA, subject to Section 12 (Data Deletion on Termination).

15. Contact Information

For questions about this DPA or to exercise your rights under this agreement:

Join our newsletter

Keep up with the latest from GoodPostal. No spam, just the good stuff.

We care about your data. Read our privacy policy.