Data Processing Agreement
The terms on which we process personal data on your behalf. You accept this agreement by using the service, and it forms part of the terms of service.
Last updated 24 September 2026
1. Parties, subject matter and duration
This agreement is between you, the customer who opens the account, as controller, and Avelto as processor. It is made under Article 28 of the UK GDPR and forms part of our terms of service.
The subject matter is our processing of personal data contained in the email you send through the service and in the records of that email. It starts when you create an account and ends when your account is deleted or the terms of service end, whichever is later.
The processor under this agreement is the business trading as Avelto, established in the United Kingdom. Registered business details are available on request from [email protected], and will be published on this page once the entity is confirmed.
If your organisation needs this agreement signed, or a copy on your own paper, write to [email protected].
2. Nature and purpose of the processing
We process personal data only to provide the service: accepting an email through the API, queuing it, sending it through our email provider, recording delivery events, showing the record back to you, maintaining your suppression list, and delivering webhook events to the endpoints you configure.
The processing operations are collection, storage, transmission, retrieval, display to your signed-in users and erasure. We also process metadata to enforce plan limits and to prevent abuse, as described in our Acceptable Use Policy.
3. Types of personal data and categories of data subject
Types of personal data, all of them chosen by you:
- Recipient email addresses, and any display name you include with them.
- Sender and reply-to addresses.
- Subject lines, message bodies in HTML and text, and any attachments you send.
- Tags and custom headers you attach to a message.
- Delivery outcomes for each recipient, including bounce and complaint records.
Categories of data subject:
- The people you send email to, such as your users, customers, staff or applicants.
- The people at your organisation named as senders or reply-to contacts.
The service is built for transactional email. Do not send special category data, criminal offence data or children's data through it without telling us first, because we have not designed the service for that.
4. Your instructions and your warranties
We process personal data only on your documented instructions. Your use of the API and the dashboard is your instruction. This agreement, the terms of service and the documentation set out the rest.
We will tell you if we believe an instruction breaks data protection law, and we may refuse to act on it. Where the law requires us to process data for another reason, we tell you first unless the law prevents that.
You confirm that:
- you have a lawful basis under the UK GDPR for every recipient you send to, and can evidence it;
- you have given those recipients the privacy information the law requires, including that a processor sends mail on your behalf;
- your instructions to us comply with data protection law and do not put us in breach of it; and
- you will not send categories of data the service is not designed to hold, as described above.
5. Confidentiality of personnel
Access to customer data is limited to the people who need it to run or support the service. Those people are bound by confidentiality obligations that survive the end of their engagement, and they are trained on the handling rules that apply to this data.
We do not read message content for any purpose other than delivering it, supporting you at your request, or meeting a legal obligation.
6. Security measures
We take appropriate technical and organisational measures under Article 32. The measures in place today, described in full on our security page, are:
- encryption in transit: HTTPS for the API and the dashboard, TLS to the email provider, and HTTPS required for webhook endpoints in production;
- credentials stored as hashes: API keys and magic-link tokens are stored as SHA-256 hashes and compared in constant time, and keys are shown once only;
- per-account isolation: every query is scoped to the account that owns the data, and a domain can be verified on one account only;
- least-privilege access: administrative access is limited to the people who operate the service, and dashboard sessions are short-lived, single-use at issue and revocable on every device;
- redacted logging: authorisation headers, cookies, keys, tokens and message bodies are removed from application logs by field name;
- hardened runtime: application containers run as a non-root user with a read-only root filesystem where possible, and databases are not exposed on a public interface;
- outbound request control: webhook URLs are re-resolved before every delivery and refused when they point at private or internal addresses, and redirects are never followed.
We hold no certification and have not been audited by a third party. This list describes what we run, not a compliance badge. It may change as the service develops, but not in a way that materially weakens security.
7. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, with the purpose and location of each, is on the sub-processors page.
We give at least 30 days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period by writing to [email protected]. If we cannot resolve the objection, you may terminate the affected part of the service without penalty and receive a refund of fees paid for the unused period.
We impose data protection obligations on each sub-processor that are no less protective than this agreement, and we remain liable to you for their performance.
8. Assistance with data subject requests
The dashboard and the API let you export everything held for the account, erase a single recipient across your emails, events and stored message content, remove suppression entries, and delete the whole account. In most cases that lets you answer a data subject request yourself, without waiting on us.
Where it does not, we help you, taking account of the nature of the processing. If a data subject contacts us directly about data we hold for you, we do not answer it ourselves. We pass it to you without undue delay and wait for your instruction.
Message bodies are in any case deleted at the end of your plan's retention window, which is 1 day on Free and up to 90 days on Enterprise, as set out in our privacy policy.
9. Assistance with impact assessments
We help you with data protection impact assessments and with prior consultation of the Information Commissioner's Office, so far as the information is ours to give and relates to this processing.
In practice that means answering written questions about our processing, our security measures and our sub-processors. Send them to [email protected].
10. Personal data breaches
We notify you of a personal data breach affecting your data without undue delay, and in any event within 72 hours of becoming aware of it. We notify by email to your account address, so keep it current.
The notification describes the nature of the breach, the categories and approximate number of records affected so far as we know, the likely consequences, and the measures taken or proposed. Where we cannot give it all at once, we give it in stages without further undue delay.
Reporting the breach to the Information Commissioner's Office and, where required, to the affected individuals is your responsibility as controller. We help you do it.
11. Deletion or return of data
You can delete your account at any time from the dashboard. Deleting it removes the emails, domains, keys, webhook endpoints and suppression entries held for that account, and releases your domains from our sending provider.
When this agreement ends, we delete the personal data we hold for you unless you ask us in writing to return it first. We keep billing records for the period stated in our privacy policy, because the law requires it. Backups are overwritten on their normal cycle.
12. Audit
We make available the information needed to show that we meet our Article 28 obligations. In the first instance an audit is satisfied by our published documentation and by written answers to your questions, sent to [email protected].
Where that is genuinely not enough, you may audit us, or appoint an independent auditor who is not our competitor, on 30 days' written notice, no more than once in any 12 months, during business hours, without disrupting the service, and at your cost. More frequent audits may follow a confirmed breach affecting your data.
13. International transfers
We process personal data in the European Economic Area, and email is sent through a provider in the eu-north-1 region in Sweden. The United Kingdom benefits from an adequacy decision covering transfers of personal data from the EU to the UK.
We will not transfer personal data outside the EEA to a country without an adequacy decision unless the transfer is covered by the UK International Data Transfer Agreement, or by the EU Standard Contractual Clauses with the UK Addendum, along with a transfer risk assessment. Any such change follows the sub-processor notice above.
14. Order of precedence and contact
If this agreement conflicts with the terms of service on a data protection point, this agreement wins. A DPA signed separately with you wins over both.
To ask a question, raise an objection or request a signed copy, write to [email protected].