Data processing agreement
Effective [not yet set]
To keep a copy, print this page or save it as a PDF from your browser’s print dialog.
This data processing agreement (“DPA”) is part of the agreement between your business, as controller, and [not yet set], CVR [not yet set], as processor, for the Corresso service. It governs all personal data we process on your behalf. It is concluded in writing when you accept our terms of service; GDPR art. 28(9) allows that to be done electronically.
1. The standard contractual clauses
The standard contractual clauses in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (OJ L 199, 7.6.2021, p. 18) — “the Clauses” — are incorporated into this DPA by reference and form its body. The Commission has decided that they meet the requirements of GDPR art. 28(3) and (4) for contracts between controllers and processors.
We do not modify the Clauses. This page makes the choices they leave open and fills in their Annexes, as Clause 2(a) allows, and adds a few terms of its own — about notice, objections, transfers and the end of the agreement — which Clause 2(b) allows because they do not contradict the Clauses. If anything on this page, in our terms of service or in any other agreement between us contradicts the Clauses, the Clauses prevail (Clause 4).
2. The choices the Clauses leave open
- Regulation: in Clause 1(a), and wherever else the Clauses offer the choice (for example in Clauses 8(c)(4), 9.1 and 9.2), the option referring to Regulation (EU) 2016/679 (the GDPR) applies.
- Clause 5 (docking clause): not included.
- Clause 7.7(a), sub-processors: Option 2, general written authorisation. The agreed list is the one in Annex II below and on our sub-processors page on the day you accept this DPA. We inform you in writing of any intended addition or replacement at least 30 days in advance, by email to your organisation’s owners, and on that page.
Some sub-processors give us less time than that when they change their own sub-processors: Postmark gives us 7 days and Anthropic gives us 15 days to object. When such a notice reaches us, we pass it on to you as soon as we receive it, and you may object within the time it leaves.
If you object on reasonable grounds relating to data protection, we look for a solution with you. If there is none, you may end the agreement for the affected part of the service, without penalty, before the change takes effect.
3. Transfers outside the EU and EEA
Corresso runs in the EU, at Hetzner in Germany. Where each sub-processor handles the data, and on what basis:
- Hetzner Online GmbH, Germany (EU): None needed: the data stays in the EU
- AC PM, LLC, USA (Deft’s data centre outside Chicago, and Amazon Web Services): EU-U.S. Data Privacy Framework (AC PM LLC is covered by ActiveCampaign, LLC’s certification), with the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as the alternative
- Anthropic Ireland, Limited, and Anthropic, PBC, USA (Anthropic, PBC): EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Anthropic is not certified under the EU-U.S. Data Privacy Framework. Not yet active: it receives no data until it is engaged (see Annex II).
By accepting this DPA you instruct us to make these transfers (Clause 7.8(a)). Where a sub-processor relies on the Commission’s standard contractual clauses for a transfer, we and it use them as Clause 7.8(b) provides.
This DPA does not itself cover transfers of personal data from us to you; the Clauses say as much of themselves (Clause 1(f)). If your business is established outside the EU and EEA, tell us before you accept it, so that the right transfer clauses can be added.
4. Your instructions
Your documented instructions (Clause 7.1) are our terms of service, this DPA, and what your people do in Corresso: the settings they choose and the messages they send. We tell you immediately if we think an instruction infringes data protection law (Clause 7.1(b)).
5. Personal data breaches
We notify you of a personal data breach concerning your data without undue delay after we become aware of it, with the information Clause 9.2 lists, by email to your organisation’s owners.
6. When the agreement ends
At your choice, we delete your personal data and confirm to you that we have done so, or return it to you and delete our copies, within 30 days after the agreement ends — unless Union or Danish law requires us to keep it — and delete it from our backups within one further backup cycle (Clause 10(d)). Until then, the Clauses continue to apply.
Annex I — List of parties
Controller
- Name and address: the business that accepts our terms of service, as named in its order or its Corresso account.
- Contact person: the owner of the business’s Corresso account, or another person the business names to us.
- Data protection officer: the business’s, if it has appointed one and names them to us.
- Signature and accession date: acceptance of the terms of service, electronically, on the date of acceptance.
Processor
- Name: [not yet set], CVR [not yet set]
- Address: [not yet set]
- Contact: [not yet set]
- Data protection officer: [not yet set]
- Signature and accession date: by offering the terms of service, on the date the controller accepts them.
Annex II — Description of the processing
Categories of data subjects
- People who write to, or receive email from, the mailboxes you connect to Corresso — typically your customers, and people who want to become customers.
- People named or described in those messages.
- Your staff who use Corresso.
- Your customers whose details are shown from your Shopify store, if you connect one.
Categories of personal data
- Names and email addresses.
- The content of messages: subject, text, and the message identifiers that keep a conversation together.
- What your staff write in Corresso: replies, internal notes and draft replies, and who assigned what to whom.
- Your staff’s accounts: name, email address, role and time zone.
- From your Shopify store, if connected: customer and order details such as names, order numbers, items, shipping addresses and tracking information. These are read when a person opens a conversation and are not stored by Corresso, apart from a value a person copies into a reply and a reference to the customer and order a person links a conversation to.
- What happened to each message sent: delivered, bounced, or marked as spam; and the addresses that bounced, complained or unsubscribed, kept on a suppression list so they are not written to again.
Sensitive data
The processing is not intended for special categories of personal data or for data about criminal offences. Messages contain whatever their senders write, however, and may include such data. The safeguards in Annex III apply to every message alike: access only for your own staff, through their own accounts; access by us only as Annex III describes; and no use for any purpose of ours.
Nature of the processing
Storing, displaying, organising, searching and deleting messages and notes; sending the messages your people approve through our email delivery sub-processor, and recording what happened to them; showing information from services you connect; and, once AI drafting is switched on with notice, writing draft replies for your people to review.
Purpose
To provide Corresso to you: so your staff can read, organise, assign and answer your business’s email, and send the replies and service messages they approve.
Duration
For as long as the agreement lasts, and afterwards for the up to 30 days needed to return or delete the data, and one further backup cycle for backups.
Receiving email into Corresso from your mailboxes is not yet switched on. When it is, we will update this Annex and, where it involves a new sub-processor, give you notice as section 2 describes.
Processing by sub-processors
For each, the subject matter and nature of the processing are the purpose and the personal data shown, and its duration is that of the agreement.
Hetzner Online GmbH
Active- Purpose
- Hosting: the servers that run Corresso and hold its database
- Personal data
- Everything Corresso stores: accounts, conversations, notes and drafts
- Where
- Germany (EU)
- Address
- Industriestr. 25, 91710 Gunzenhausen, Germany
- Transfer safeguard
- None needed: the data stays in the EU
AC PM, LLC (Postmark)
Active- Purpose
- Delivering the email a person sends from Corresso, and reporting back what happened to it
- Personal data
- Outgoing messages (sender, recipients, subject and text) and whether each was delivered, bounced or marked as spam
- Where
- USA (Deft’s data centre outside Chicago, and Amazon Web Services)
- Address
- 1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA
- Transfer safeguard
- EU-U.S. Data Privacy Framework (AC PM LLC is covered by ActiveCampaign, LLC’s certification), with the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as the alternative
- Keeps data
- Keeps sent messages for up to 45 days (its default), and addresses that bounced, complained or unsubscribed on a suppression list until they are removed
Anthropic Ireland, Limited, and Anthropic, PBC
Not yet activeEngaged only when this service is switched on, and not before every customer has had 30 days’ notice.
- Purpose
- Writing draft replies for a person to review, edit and send
- Personal data
- The text of the conversation a draft is written for, and the draft it returns
- Where
- USA (Anthropic, PBC)
- Address
- Anthropic Ireland, Limited: 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland. Anthropic, PBC: 548 Market St, PMB 90375, San Francisco, CA 94104, USA
- Transfer safeguard
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Anthropic is not certified under the EU-U.S. Data Privacy Framework.
Annex III — Technical and organisational measures
Encryption
- All connections to Corresso use HTTPS, and browsers are told to use nothing else (HSTS).
- Credentials for the services you connect, such as your Shopify store, and for email delivery are encrypted in the database (Active Record Encryption, AES-256-GCM).
- Passwords are stored only as bcrypt hashes.
Separation between customers
- Every database table that holds customer data has a required organisation column with a foreign key. Every read made for a signed-in person goes through that person’s own organisation; background tasks and delivery reports from our email provider work on one organisation at a time.
- Automated tests check that the pages and actions they cover read customer data only through the organisation.
Access and identification
- Every person has their own account; roles (owner, admin, agent) decide who may assign work and change settings.
- A sign-in ends after 30 days, a password-reset link works for 15 minutes, and resetting a password ends every sign-in of that account.
- Sign-in and password-reset attempts are limited to 10 per 3 minutes from one IP address.
- Only the people who run Corresso for us have access to its servers, only as far as their work needs, and each has committed to confidentiality (Clause 7.4(b)).
A person sends every message
- No message leaves your mailboxes unless a signed-in person of yours pressed send. There is no automatic and no bulk approval of drafts. Automated tests fail the build if background tasks or maintenance scripts refer to the code that sends, and that code refuses to run without a signed-in person.
Data minimisation and retention
- Order and customer details from connected stores are read live and not stored, apart from the references and copied values Annex II names.
- Open and link tracking is always off: no tracking pixels, no rewritten links.
- The text of a message being sent is kept in its sending record only until the outcome is known; the sent message stays in the conversation.
- A sign-in record is deleted by a daily clean-up once the sign-in has ended, 30 days after it began, or at once when the person signs out; records of failed background tasks are deleted after 30 days, and backups after at most 30 days.
- In the lines Corresso itself writes to its request log, each request’s parameters — passwords, and the email addresses, message text and search terms that forms and links carry — are filtered first. The rest of each page’s address is logged as it is, so the one-off token in a password-reset link, and the token that routes our email provider’s delivery reports to your organisation, appear in it. Two web servers pass each request on to Corresso, and neither filters anything: each logs the full address of each request — searches, and the customer email addresses some inbox links carry, included. The inner one writes into Corresso’s own request log, next to Corresso’s own lines; the outer one, in front of Corresso, keeps a single file of at most 10 MB that starts afresh when full.
Availability and restore
- Corresso and its database run at Hetzner in Germany; the physical security of the data centres is Hetzner’s, under its data processing agreement with us.
- Database backups, made as our operations runbook prescribes, are kept for at most 30 days.
Testing and review
- Every change runs through the automated test suite, static security analysis (Brakeman) and audits of known vulnerabilities in the libraries Corresso uses.
Logging
- Each request is logged with its IP address, time, page address and browser (user agent); each outgoing message is recorded with who sent it and when.
Helping you (Clauses 8 and 9)
- We forward any request we receive from a data subject about your data to you promptly, and do not answer it ourselves unless you authorise us to.
- We notify you of a personal data breach without undue delay, with the information in Clause 9.2, and give you what we know to help with your own notifications.
- We give you the information we have to help with data protection impact assessments and prior consultations (Clause 8(c)).
- When a request or a breach involves a sub-processor, we obtain what is needed from it under our agreement with it, and pass it on to you.