Data Processing Agreement

The contract under which we process your recipients’ data for you. It applies automatically to every account, including free ones.

Version
v1.0
Effective
15 Sep 2026
History
no per-document change log yet
Previous versions
none — v1.0 is the first in force

Notes marked “In plain English” summarise a clause to help you read it. They are not part of the document; where a note and a clause differ, the clause governs.

This Data Processing Agreement (the “DPA”) forms part of the Terms of Service between YS Progress Inc. and the Customer. It follows the terms Article 28(3) of the GDPR requires, in order, so a reviewer can tick them off one by one. Words defined in the Terms mean the same here; “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have their GDPR meanings, and the equivalent terms of other Data Protection Laws apply in the same way. It costs nothing extra on any plan, and it takes effect without a signature.

1. Parties, scope, duration and precedence

This DPA is between the Customer, as controller (or as processor for its own controller), and YS Progress Inc., a corporation registered in Canada, as processor (“YS Progress”). It applies to the personal data that YS Progress processes on the Customer’s behalf in providing the Service (“Customer Personal Data”), under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, PIPEDA and any other data protection law that applies to that processing (“Data Protection Laws”).

It lasts for as long as YS Progress processes Customer Personal Data, including during the wind-down in §12. Where the Customer acts as processor for another controller, the Customer is that controller’s single point of contact, and YS Progress owes its obligations under this DPA to the Customer alone.

If this DPA and the Terms conflict about the processing of Customer Personal Data, this DPA prevails; in every other respect the Terms govern, including their clauses on changes, governing law and disputes.

YS Progress’s liability arising out of or in connection with this DPA, however it arises, is subject to the exclusions and limits of liability in the Terms and counts towards the same aggregate cap. Nothing in this DPA limits liability to data subjects or to supervisory authorities where Data Protection Laws do not allow it to be limited.

IN PLAIN ENGLISHYou decide what happens to your recipients’ data; we process it for you. What we can owe under this DPA is capped the same way as under the Terms.

2. Nature and purpose of processing

YS Progress stores the Customer’s templates; accepts messages from the Customer’s applications through the API or SMTP; queues them and relays them through the Customer’s own Transports (mail servers, or email providers such as Mailgun or Postmark); records delivery attempts and the events those Transports report; keeps an encrypted archive of message content where the Customer’s retention settings allow it; and records pixel fetches and link redirects where the Customer enables tracking on an Application.

To keep a recipient’s opt-out effective, YS Progress adds one-click unsubscribe headers to a message with a single recipient when the Customer has not set its own, and records the resulting unsubscribes as suppressions.

YS Progress processes Customer Personal Data only to provide, secure and support the Service and to comply with law. It does not sell Customer Personal Data, does not use message content to train machine-learning models, and does not use message content for any purpose of its own.

IN PLAIN ENGLISHWe store, queue, relay and record your mail through your own mail servers. We never sell it, train on it, or use it for our own ends.

3. Types of personal data

Email addresses and display names of recipients and senders; message subjects, bodies, headers and attachments, which may contain any personal data the Customer chooses to send (including credentials and account links); template variables; delivery metadata such as timestamps, message identifiers and verbatim responses from mail servers; suppression and bounce history for an address; where tracking is enabled, the time of a pixel fetch or link click, a keyed hash of the IP address and the user agent; and, in the Customer’s audit log, the address of a person the Customer looks up or exports.

The Customer decides what its messages contain. It must not send special categories of personal data or other sensitive data through the Service unless it has a lawful basis to do so and has configured retention and access to match.

IN PLAIN ENGLISHWhatever your emails contain, we technically process. Set retention to 0 for the sensitive ones.

4. Categories of data subjects

The Customer’s end users, customers, prospects and any other recipients of the Customer’s email; people named as senders in it; and the Customer’s own staff where they appear in messages, headers or recipient lists.

5. Controller instructions

YS Progress processes Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless a law to which YS Progress is subject requires otherwise; in that case it informs the Customer of the requirement before processing, unless that law prohibits it.

The Agreement, and the Customer’s API calls, SMTP submissions, templates and panel configuration — such as retention, tracking, suppression, Transport and member settings — are the Customer’s complete documented instructions. Any further instruction needs YS Progress’s written agreement and may be charged for.

The Customer is responsible for the lawfulness of its instructions and of the processing, including having a lawful basis, giving data subjects the information the law requires and obtaining any consent. YS Progress informs the Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is confirmed or changed. YS Progress has no obligation to review instructions for lawfulness.

IN PLAIN ENGLISHYour API calls and settings are the instructions. Whether you are allowed to send the mail you send is yours to answer.

6. Confidentiality

YS Progress ensures that the people it authorises to process Customer Personal Data are bound by an appropriate duty of confidentiality and access it only as needed to operate, secure and support the Service or to comply with law. Its operator tools do not display message bodies or subjects. Within the Customer’s account, access to message content depends on role, and every body view is recorded in the Customer’s audit log.

IN PLAIN ENGLISHOur staff tools don’t show your message bodies. If anyone on your account opens one, your audit log says who and when.

7. Security measures (Art. 32)

YS Progress implements technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. They include: message bodies with the variables sent with them, attachments and Transport credentials encrypted at rest in a versioned envelope (v1.<key_id>.<nonce>.<ciphertext>) that supports key rotation; API keys and access tokens stored only as hashes; TLS on connections to and from the Service, and to Transports unless the Customer configures one without it; tenant isolation enforced by a query scope that fails closed; role-based access within each account, with body views audit-logged; and encrypted backups.

The Security page describes the current measures and forms part of this DPA. YS Progress may change its measures from time to time, provided the overall level of protection is not materially reduced.

The Customer is responsible for the security of its own systems, credentials, API keys, members, Transports and configuration, and for choosing retention and access settings appropriate to its data.

IN PLAIN ENGLISHThe Security page is the technical annex — public, not an appendix you have to request.

8. Processing location and international transfers

YS Progress stores Customer Personal Data at rest on Oracle Cloud Infrastructure in the ca-toronto-1 region, in Canada. Backup snapshots are encrypted before they leave that infrastructure, with keys YS Progress holds, and stored with Cloudflare R2. Traffic to and from the Service passes through Cloudflare’s global network, where TLS is terminated and the traffic re-encrypted to the Canadian origin. The Subprocessor list states where each subprocessor processes data.

Personal data may be transferred from the European Economic Area to YS Progress on the basis of the European Commission’s adequacy decision for Canada (Decision 2002/2/EC), which covers commercial organisations subject to PIPEDA and which the Commission confirmed in its January 2024 review. Transfers from the United Kingdom and Switzerland rely on the adequacy findings for Canada under their own laws, so these transfers need no Standard Contractual Clauses.

Where a subprocessor processes Customer Personal Data in a country without such a finding, YS Progress ensures that the transfer is covered by an appropriate safeguard, such as the subprocessor’s certification under the EU–US Data Privacy Framework (with its UK Extension and the Swiss–US framework) or the Standard Contractual Clauses. The Customer authorises these transfers.

If a transfer mechanism ceases to be valid, the parties will cooperate in good faith to put an alternative in place. YS Progress may suspend the affected transfer meanwhile, and if no alternative is available within a reasonable time, either party may terminate the affected part of the Service as its sole remedy.

IN PLAIN ENGLISHYour data rests in Canada, which the EU, the UK and Switzerland recognise as adequate — no SCC paperwork. Where a provider is in the US, its own certification or the SCCs cover the transfer.

9. Subprocessors

The Customer gives YS Progress general written authorisation to engage subprocessors. Those currently engaged are named on the Subprocessor list, which forms part of this DPA.

YS Progress imposes on each subprocessor, by contract, data protection obligations materially equivalent to those in this DPA as they apply to the service that subprocessor provides, and remains responsible to the Customer for each subprocessor’s performance of them, subject to the limits of liability in the Terms.

YS Progress gives notice of an intended addition or replacement by dating it in the change log on the Subprocessor list and by email to account owners, at least 30 days before the new subprocessor processes Customer Personal Data. Where a replacement is needed urgently for security, for continuity of the Service or to comply with law, YS Progress may give shorter notice, and gives it as soon as reasonably practicable.

The Customer may object in writing to [email protected] within the notice period, on reasonable grounds relating to data protection. The parties will discuss the objection in good faith. If YS Progress does not, in its discretion, resolve it, the Customer’s sole and exclusive remedy is to terminate the affected Service by written notice before the change takes effect, without a refund of fees already paid. A Customer that does not object within the notice period accepts the change.

IN PLAIN ENGLISHWe name every subprocessor and give 30 days’ notice before a new one touches your data. If you object and we can’t resolve it, you can leave.

10. Assistance with data subject rights and compliance

Taking into account the nature of the processing, YS Progress assists the Customer, by appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects exercising their rights.

That assistance is primarily the Service itself: the Message Log search, suppression management, the audit log (and its export, on plans that include it), account erasure and, for an account owner, the tools to look up, export and erase one person’s data. Further assistance — such as an export of the whole archive — is provided on request within a reasonable time, and YS Progress may charge its reasonable costs for it.

If a data subject contacts YS Progress directly about Customer Personal Data, YS Progress directs them to the Customer where it can identify the Customer, and does not respond on the Customer’s behalf unless the law requires it.

YS Progress also gives reasonable assistance with the Customer’s data protection impact assessments and prior consultations with supervisory authorities, to the extent the information needed is not already available to the Customer, and may charge its reasonable costs for it.

IN PLAIN ENGLISH“Find everything about jane@” is a search box, and an account owner can export or erase everything held about one person from the panel. For the rest, we help.

11. Personal data breach notification

YS Progress notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, by email to the account owners. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences and the measures taken or proposed; further information follows as it becomes available.

YS Progress takes reasonable steps to contain and investigate the breach, and gives reasonable assistance to help the Customer meet its own obligations to notify supervisory authorities and data subjects, which remain the Customer’s. Notifying or responding to a breach is not an acknowledgement of fault or liability.

Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data — such as pings, port scans, denial-of-service attempts or failed sign-in attempts — are not personal data breaches.

IN PLAIN ENGLISHIf personal data you gave us is compromised, we tell you without undue delay, with what we know, and help you meet your own duties.

12. Deletion and return

During the term the Customer controls deletion. Its retention settings delete message bodies and attachments when they specify, up to the ceiling of its plan, and message metadata is deleted in monthly batches no earlier than the end of the plan’s metadata retention period.

An account owner can erase one person’s data, or the mail data of the whole account, from the panel. An account erasure starts as soon as it is confirmed: it deletes message bodies, attachments, tracking data, webhook deliveries and bounce history; it replaces recipient addresses, names and subjects in message records with irreversible values; and it keeps suppressions only as hashes, so no one erased is mailed again. It does not close the account: members, API keys, templates, Transports and domains remain until the account is closed.

When the Customer asks YS Progress to close an account, or YS Progress terminates one, the account enters a 30-day wind-down: new sends are refused, the archive stays readable in the panel, and YS Progress provides an export of the account’s data if the Customer asks for one during that period. At the end of the wind-down YS Progress deletes the account and the Customer Personal Data in it, unless the law requires YS Progress to keep it. The Customer is responsible for retrieving anything it needs before the wind-down ends.

A user profile can belong to several accounts, so it is not deleted with an account; the Privacy Policy covers profiles. Audit records written for an account are kept for up to 12 months after they are written.

Deleted data remains in encrypted backups until they expire, within 35 days. Backups are used only to recover from a failure; if a restore brings back data deleted after the backup was taken, YS Progress takes reasonable steps to delete it again.

IN PLAIN ENGLISHErase from the panel and the mail data goes now, and out of backups within 35 days. Closing an account gives you 30 days to take your data first.

13. Audit and information rights

YS Progress makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR: this DPA and the Security page, answers to the Customer’s reasonable questions by email, and a completed written security and data protection questionnaire no more than once in any 12-month period.

If that information is not enough to demonstrate compliance, or a supervisory authority requires it, the Customer may carry out an audit, including an inspection, on these conditions: at least 60 days’ written notice; no more than once in any 12-month period, unless a supervisory authority requires more or a personal data breach has affected Customer Personal Data; during business hours, remotely wherever possible and without disrupting the Service; by the Customer or an independent auditor bound by confidentiality who is not a competitor of YS Progress; limited to the systems and records relevant to Customer Personal Data, with no access to other customers’ data, trade secrets or privileged information; and at the Customer’s sole cost, including YS Progress’s reasonable costs of the time it spends.

Audit results are YS Progress’s Confidential Information. Audits of subprocessors are satisfied by the reports, certifications and information those subprocessors make available.

IN PLAIN ENGLISHAsk in writing and we answer. An inspection happens only when written answers can’t show compliance, or a regulator requires one.

14. Execution

This DPA is incorporated into the Terms of Service and applies to every account automatically, from the moment the Terms are accepted; it needs no signature to take effect. If your procurement process needs a countersigned copy, email [email protected] with your legal entity’s name and signatory, and we return a countersigned PDF of this version.