Data Processing Agreement

Last updated: September 2026 · Version 2026-09

How to execute this DPA

This Data Processing Agreement applies automatically to every Better Email customer as part of the Terms of Service. No signature is needed for it to be in force.

If your organisation needs a countersigned copy, email your legal entity name, registration number, address and signatory to [email protected]. You receive a signed PDF within 5 working days. A PDF version of this page is also available on request.

1. Parties

This Data Processing Agreement (“DPA”) is entered into between the customer named in the order form, subscription or account (the “Customer”, the controller) and Better Email ApS, CVR 42361194, Italiensvej 2, 5th, 2300 København S, Denmark (“Better Email”, the processor). Together the “Parties”.

2. Definitions

“GDPR” means Regulation (EU) 2016/679. “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Customer Data” means all data, including Personal Data, that the Customer or its users upload to or create in the Better Email platform. “Services” means the Better Email platform and related services described in the Terms of Service. “Sub-processor” means a third party engaged by Better Email to process Customer Data. “SCCs” means the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the UK International Data Transfer Addendum issued by the UK Information Commissioner.

3. Scope and roles

  1. 1.This DPA governs Better Email’s processing of Personal Data contained in Customer Data on behalf of the Customer in connection with the Services.
  2. 2.The Customer is the Controller (or, where the Customer acts for its own clients, a Processor with the authority to appoint Better Email as a Sub-processor). Better Email is the Processor.
  3. 3.For Personal Data Better Email processes for its own purposes (account administration, billing, website analytics, marketing), Better Email is an independent Controller and the Privacy Policy applies.
  4. 4.Where this DPA and section 8 of the Terms of Service overlap, this DPA prevails. Where this DPA and a signed enterprise agreement conflict, the enterprise agreement prevails unless it states otherwise.

4. Details of processing

The subject matter, duration, nature, purpose, categories of Data Subjects and categories of Personal Data are set out in Annex 1.

5. Processor obligations

  1. 1.Instructions. Better Email processes Personal Data only on the Customer’s documented instructions, including with regard to transfers, unless required by EU or Member State law. In that case Better Email informs the Customer before processing, unless the law prohibits it. The Terms of Service, this DPA and the Customer’s use of the Services’ features constitute the documented instructions. Better Email informs the Customer if it considers an instruction to infringe the GDPR.
  2. 2.Confidentiality. Better Email ensures that persons authorised to process Personal Data are bound by confidentiality, contractually or by statute.
  3. 3.Security. Better Email implements the technical and organisational measures in Annex 2 and keeps them under review. It may update them provided the overall level of protection does not decrease.
  4. 4.Sub-processors. The Customer gives general authorisation for the Sub-processors listed at better.email/legal/subprocessors (Annex 3). Better Email gives customers with this DPA at least 30 days’ notice before adding or replacing a Sub-processor. The Customer may object in writing within that period on reasonable data protection grounds. If the Parties cannot resolve the objection, the Customer may terminate the affected Services in accordance with the Terms. Better Email imposes data protection obligations on each Sub-processor equivalent to this DPA and remains liable for their performance.
  5. 5.Data Subject requests. Taking into account the nature of the processing, Better Email assists the Customer with appropriate technical and organisational measures to respond to Data Subject requests. Requests received directly by Better Email are forwarded to the Customer without undue delay.
  6. 6.Assistance. Better Email assists the Customer in meeting its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to Better Email.
  7. 7.Personal Data Breach. Better Email notifies the Customer without undue delay, and within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notification describes the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, and is supplemented as information becomes available.
  8. 8.Deletion or return. On termination of the Services, Better Email deletes Customer Data 3 months after the termination date unless the Customer requests return of the data or EU or Member State law requires storage. Customers can export their data within 7 working days of a request made before that date.
  9. 9.Audits and information. Better Email makes available the information necessary to demonstrate compliance with Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are limited to once per 12 months unless required by a Supervisory Authority or following a Personal Data Breach, are agreed at least 30 days in advance, take place during business hours, and are subject to confidentiality. Better Email may first satisfy an audit request with its security documentation and questionnaire responses.

6. Customer obligations

  1. 1.The Customer is responsible for the lawfulness of the Personal Data it puts into the Services, including having a legal basis and providing information to Data Subjects.
  2. 2.The Customer is responsible for configuring access, roles and integrations in the Services and for the security of its users’ credentials.
  3. 3.The Customer does not upload special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions unless agreed in writing.

7. International transfers

  1. 1.Customer Data is stored and processed in the EU. Better Email does not transfer Personal Data outside the EU/EEA except to the Sub-processors identified in Annex 3 as located outside the EU/EEA.
  2. 2.Such transfers are made under the SCCs (Module 2, controller to processor, or Module 3 where the Customer is a processor), incorporated by reference, with Better Email or the Sub-processor as data importer, supplemented by transfer impact assessments. For Personal Data subject to UK law, the UK Addendum applies.
  3. 3.The Customer may restrict transfers by disabling AI features for its workspaces or by running AI inference under its own provider account in an EU region, as described at better.email/security.

8. Liability

Each Party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service or the signed enterprise agreement, except where the GDPR does not permit such limitation. Nothing in this DPA limits liability towards Data Subjects under Article 82 GDPR.

9. Term

This DPA takes effect when the Customer first uses the Services and remains in force until Better Email has deleted or returned all Customer Data in accordance with clause 5.8. Better Email may update this DPA to reflect changes in law or the Services and gives notice of material changes at least 30 days before they take effect.

10. Governing law and venue

This DPA is governed by Danish law. Disputes are settled by the City Court of Copenhagen or the Maritime and Commercial Court, without prejudice to the rights of Data Subjects and Supervisory Authorities under the GDPR.

Annex 1: Details of processing

Subject matter
Provision of the Better Email platform for planning, building, reviewing, approving and exporting campaigns and design systems.
Duration
The term of the Customer's subscription plus the 3-month deletion window after termination.
Nature and purpose
Hosting, storage, display, editing, collaboration, AI-assisted generation and translation, email client previews, export to the Customer's sending platform, backup, support and security monitoring.
Categories of Data Subjects
The Customer's employees and contractors who use the platform. The Customer's subscribers and recipients, only to the extent their Personal Data appears in campaign content, dynamic content samples or test sends.
Categories of Personal Data
Names, work email addresses, roles and usage data of users. Any Personal Data contained in content the Customer uploads or creates. No special categories of data unless agreed in writing.

Annex 2: Technical and organisational measures

AreaMeasure
EncryptionTLS 1.2 or higher for all data in transit. AES-256 encryption for data at rest, including backups.
Identity and accessSSO via SAML and OIDC through WorkOS. Multi-factor authentication enforced through the customer’s identity provider. SCIM provisioning, so accounts are created and removed when staff join or leave.
AuthorisationRole-based access (Admin, Designer, Editor, Reviewer) with folder-based and group-based business-unit isolation.
AuditabilityOrganisation-wide audit log covering sign-ins, permission changes, role changes, design system pushes, exports and approvals.
SecretsIntegration credentials are stored in an encrypted secret vault and never shown in the user interface.
Production accessLeast-privilege access to production systems limited to named engineers, reviewed on personnel change.
Availability and recoveryDaily backups. DDoS protection through Cloudflare. Error and uptime monitoring. Public status page at status.better.email. 99.9% monthly uptime commitment.
Data locationCustomer data stored and processed in the EU. Transfers to sub-processors outside the EU/EEA only under the safeguards in clause 9.
Vulnerability managementDependency and vulnerability monitoring, a public responsible disclosure policy, and remediation prioritised by severity.
Incident responseDocumented incident process. Notification of affected customers without undue delay and within 72 hours of Better Email becoming aware of a personal data breach (24 hours for customers with an Enterprise SLA addendum).
PersonnelStaff and contractors are bound by confidentiality and receive security and data protection instruction.
DeletionCustomer data deleted 3 months after termination unless the customer instructs otherwise. Export available within 7 working days of request.

Annex 3: Sub-processors

The authorised Sub-processors, with purpose, data categories, location and transfer mechanism, are listed at better.email/legal/subprocessors and form part of this DPA. Optional sending-platform integrations are engaged only on the Customer's instruction when an export is triggered.

Contact

Data protection questions and countersignature requests: [email protected]. Better Email ApS, CVR 42361194, Italiensvej 2, 5th, 2300 København S, Denmark, +45 42 48 38 28.