Data Processing Agreement

How Russkinbox processes and protects Subscriber Data on your behalf.

Version
2026-09-01
Effective
1 September 2026

Russkinbox Data Processing Agreement (DPA)

This DPA is a legal agreement between Russkinbox (“Data Processor”, “we”, “us”, or “our”) and you (“Data Controller”, “Customer”, or “you”). It forms part of our Terms of Service and Privacy Policy. This agreement applies whenever we look after personal data for you while providing our online email platform. To do this work, we use strong, professional third-party cloud services.

1. Simple Words and Meanings

To keep this document clear and simple, these words have special legal meanings:

  • “Applicable Data Protection Laws”: All the privacy rules that control how we handle data under this contract, including UK GDPR, the Data Protection Act 2018, the EU GDPR, and the California Privacy Rights Act (CCPA/CPRA).
  • “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach”: Use the exact same definitions found in the main Data Protection Laws.
  • “Subscriber Data”: Any personal details uploaded, added, or sent to our platform by you or for you (such as email addresses, names, custom tags, and campaign tracking numbers).
  • “Sub-processor”: Any outside helper or company we hire to help process your subscriber data.

2. Who Does What and Following the Rules

  • 2.1 Roles: We both agree that when handling Subscriber Data, you act as the Data Controller (the boss of the data), and Russkinbox acts strictly as the Data Processor (the helper).
  • 2.2 What You Promise: As the Data Controller, you promise that:
    • You have collected clear permission from people and have good legal reasons to send Subscriber Data to us under privacy laws.
    • You strictly avoid importing bought, rented, or scraped contact lists into our system, as set out in our rules.
    • Your instructions to us about handling data will follow all real privacy laws.

3. How We Use Data and Rules to Follow

  • 3.1 Strict Boundaries: We will only handle Subscriber Data by following your written instructions, our Terms of Service, this DPA, and the law.
  • 3.2 No Selling: Furthermore, we promise that we do not sell, share, or keep Subscriber Data for our own business reasons outside of running, securing, and fixing our email service.
  • 3.3 Unlawful Instructions: If we think an instruction from you breaks privacy laws, we will tell you right away.

4. Keeping Things Secret and Staff Rules

We make sure that all our staff, developers, and support teams who handle Subscriber Data sign strict secrecy promises. In addition, only team members who truly need to see your data to run the platform, send emails, or fix bugs can access it.

5. Keeping Your Information Safe

  • 5.1 Safety Rules: Thinking about technology costs and risks, we use smart safety rules and technical shields to protect Subscriber Data from loss, theft, damage, or unwanted visitors.
  • 5.2 Platform Shields: Specifically, our platform includes:
    • Safe Moving Data: All information moving across our network uses strong modern encryption (TLS 1.3).
    • Safe Stored Data: All saved Subscriber Data uses top-level AES-256-bit encryption.
    • System Shields: Activity logs, safety limits, and domain tools (SPF, DKIM, and DMARC) to stop fake emails and unauthorised entry.

6. Outside Helpers (Sub-processors)

  • 6.1 General Consent: You give us general permission to hire trustworthy outside helpers to handle cloud storage, infrastructure, and email sending.
  • 6.2 Infrastructure Helpers: Our email delivery network uses large, safe third-party cloud services. As a result, your Subscriber Data is sent safely through secure data centres that follow strict safety rules.
  • 6.3 Helper Promises: We make written agreements with every outside helper that are just as strict as this DPA. Plus, we stay fully responsible to you for the work our helpers do.

7. Sending Data Across Borders

  • 7.1 Transfer Safety: If we need to send Subscriber Data outside the UK or the European Economic Area (EEA) to a country without basic safety rules, we will put proper safety steps in place first.
  • 7.2 Standard Rules: Specifically, these transfers use official UK or EU legal clauses to ensure your Subscriber Data stays safe wherever it is stored.

8. Helping Your Subscribers and Users

  • 8.1 Direct Requests: Subscribers who want to use their rights (like looking at, changing, or deleting their details) should contact you directly as the Controller. However, if a subscriber emails us instead, we will pass their message to your email address without replying to them directly (unless the law says we must).
  • 8.2 Helpful Tools: In addition, we will give you easy platform tools (like CSV data downloads and block lists) so you can answer subscriber requests on time.

9. Handling Data Leaks or Accidents

  • 9.1 Quick Alerts: If a real data leak affects your Subscriber Data, we will email you without unnecessary delay (and within 48 hours of finding out).
  • 9.2 Leak Reports: Our message will explain what happened, how much data was involved, possible problems, and the fixing steps our team has taken or recommends.

10. Keeping, Deleting, and Blocking Data

  • 10.1 Active Accounts: We keep your Subscriber Data only for as long as your Russkinbox account stays open and active.
  • 10.2 Deleting Closed Accounts: When you close your account, we will erase all active lists and content from our main systems within 30 days.
  • 10.3 Automatic Block Lists: However, as required by our Anti-Spam rules, bounced emails, unsubscribes, and spam complaints are permanently added to your account block list. Therefore, this stops those addresses from ever being emailed or added back by mistake.

11. Checking Our Work (Audits)

If you send us a reasonable written request, we will share safety reports or paperwork proving we follow this DPA. Furthermore, if privacy laws require a full check, you can carry one out by giving us 30 days' advance notice, as long as the check happens during normal work hours without breaking our service.

12. Legal Rules and Which Document Wins

  • 12.1 Priority of Terms: If there is any clash between this DPA and our main Terms of Service, then the rules in this DPA win when it comes to privacy and data choices.
  • 12.2 Courts: This agreement follows the laws of the UK and Wales, and both of us agree to use the courts of England to solve any legal issues.

13. How to Contact Our Legal Team

If you have questions about this Data Processing Agreement or need a signed copy, please reach out to our legal team: