DORA Statement
Last updated: September 2026
The Digital Operational Resilience Act (Regulation (EU) 2022/2554, “DORA”) applies to financial entities in the EU from 17 January 2025. It requires them to manage the risk of the ICT services they buy, to keep a register of information about their ICT third-party service providers, and to include specific provisions in their contracts with those providers.
Better Email ApS provides email creation software to insurers, banks and other financial entities. This statement sets out what we provide so that a financial entity can meet its own DORA obligations when using Better Email. DORA places its obligations on the financial entity. Better Email is not itself regulated under DORA and claims no certification or compliance with it on its own account.
1. Information for the register of information
Article 28(3) requires financial entities to keep a register of their contractual arrangements with ICT third-party service providers. The following information is available for that register. We provide further fields on request.
| Field | Information |
|---|---|
| Legal entity | Better Email ApS, Italiensvej 2, 5th, 2300 København S, Denmark |
| Registration number | CVR 42361194 (Denmark) |
| Service | Software as a service for planning, building, reviewing, approving and exporting email campaigns and design systems |
| Data location | EU (hosting, storage, backups). Sub-processors outside the EU listed at better.email/legal/subprocessors with transfer mechanism |
| Sub-processors | Published list with purpose, data categories, country and transfer mechanism, 30 days’ notice of changes |
| Availability | 99.9% monthly uptime commitment, public status page at status.better.email |
| Contact for ICT risk questions | [email protected] |
2. Contractual provisions (Article 30)
Article 30 lists the provisions a contract with an ICT third-party service provider must contain. The following are available to financial entities through the enterprise agreement, the Enterprise Service Level Agreement and the Data Processing Agreement:
- •A clear description of the service, its functions and the data it processes.
- •The locations where the service is provided and where data is processed and stored, with notice before any change.
- •Availability commitments and service levels (Enterprise Service Level Agreement), with remedies agreed in the order form.
- •Assistance with ICT-related incidents, including notification within 24 hours for enterprise customers and cooperation during investigation.
- •Audit, information and access rights for the customer, its auditors and competent authorities, with reasonable notice and scope.
- •Transparency on sub-contracting, with a published sub-processor list and 30 days’ advance notice of changes.
- •Termination rights and exit assistance, including export of design systems, assets and campaign HTML, a 60 day transition period, and a 3-month post-termination retention window.
- •Data protection terms under the Data Processing Agreement, including security measures and breach notification.
Where a financial entity classifies Better Email as supporting a critical or important function, we agree the additional provisions of Article 30(3) in the enterprise agreement.
3. ICT incident support
Financial entities must classify and report major ICT-related incidents within set deadlines. To support this, Better Email notifies enterprise customers of incidents affecting their use of the service or their data within 24 hours of becoming aware, provides updates during resolution, and shares a post-incident summary on request. Service-wide incidents are also published on status.better.email.
4. Operational resilience
- •Daily backups of customer data.
- •A documented business continuity and disaster recovery plan, reviewed at least annually.
- •Error and uptime monitoring with a public status page and incident history.
- •DDoS protection at the edge and encryption in transit and at rest.
- •A responsible disclosure policy and vulnerability management prioritised by severity.
Better Email does not send campaigns. Sending stays with the customer's own email service provider, so an outage of Better Email does not stop campaigns that have already been exported from reaching recipients. An outage therefore has a limited effect on the customer's critical functions.
5. Exit and portability
Customers export campaigns as HTML to their sending platform at any time, and Better Email delivers the customer's design systems, configuration and uploaded assets by secure file transfer within 10 business days of a written request. Termination starts a transition period of at least 60 days with full platform access and a named transition contact. After termination, customer data is retained for 3 months to allow migration, then deleted, with written confirmation on request. The full exit plan is available on request as part of the enterprise agreement, and the Enterprise SLA sets out the timelines.
6. Questionnaires and documentation
We complete DORA due diligence questionnaires and provide our security overview, business continuity plan summary and sub-processor details to financial entities under evaluation. Send requests to [email protected]. See also our Security page.
Contact
Better Email ApS, CVR 42361194, Italiensvej 2, 5th, 2300 København S, Denmark, +45 42 48 38 28, [email protected].