We value your privacy. We use cookies and similar technologies for analytics and performance tracking in accordance with the DPDP Act 2023. We will only track your usage if you provide explicit consent.
Data Processing Agreement

Data Processing Addendum

Version: DPA-2026-07-08
Last updated: July 8, 2026.

Note: This Data Processing Addendum forms part of the Sendvrel Terms of Service where agreed by the parties or otherwise incorporated by reference. Enterprise customers may request an executed copy where required.

1. Scope and Applicability

This Data Processing Agreement ("DPA") is incorporated into the Terms of Service and applies to the processing of personal data by Sendvrel on behalf of our enterprise customers. By using Sendvrel's SMTP infrastructure to transmit personal data, you agree to these data processing terms.

2. Roles of the Parties

Depending on the applicable law, the Customer acts as the Data Fiduciary or Data Controller, and Sendvrel acts as the Data Processor processing personal data on the Customer's documented instructions.

3. Processing Activities

Sendvrel processes personal data (such as email addresses, recipient names, and email metadata) strictly for the purpose of providing SMTP delivery services, monitoring delivery health, preventing abuse, and generating operational metrics and improving service reliability. Email bodies are retained only temporarily (up to 30 days) to facilitate delivery, debugging, and security screening.

4. Security Measures

Sendvrel implements robust technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These include TLS encryption in transit, strict access controls, and continuous infrastructure monitoring.

5. Subprocessors

Sendvrel may engage third-party subprocessors to assist in providing the service (e.g., cloud infrastructure hosting). A current list of subprocessors is available at our Subprocessors page. We ensure all subprocessors are bound by written agreements providing equal or greater data protection standards.

6. Data Subject Rights & Deletion

Sendvrel will assist the Customer in responding to data principal requests (e.g., rights of access, correction, erasure, and other applicable data principal rights). Upon termination of the Service, or upon written request, Sendvrel will securely delete or return all personal data within a maximum of 30 days, except where retention is required by law.

7. International Data Transfers

Sendvrel primarily processes data within India. If personal data is transferred internationally, Sendvrel ensures such transfers comply with applicable data protection laws, relying on adequacy decisions or standard contractual clauses where legally required.

© 2026 Sendvrel. All rights reserved.