JustEmails
PricingSign inStart free trialStart free
Legal

Data Processing Agreement

This Data Processing Agreement forms part of the Terms of Service between you (Data Controller or Customer) and Velocity Digital Labs LLC (Data Processor or Company), operator of the JustEmails platform. It is entered into to ensure compliance with the GDPR (EU) 2016/679 and other applicable data-protection laws.

Effective Last reviewed

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.

"Processing" means any operation performed on Personal Data, including collection, recording, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.

"Sub-processor" means any third party engaged by the Data Processor to process Personal Data on behalf of the Data Controller.

"Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

2. Scope and Purpose of Processing

2.1 The Data Processor processes Personal Data on behalf of the Data Controller solely for the purpose of providing the Service, which includes:

  • Receiving, storing, and delivering email messages
  • Managing email accounts and domain configurations
  • Providing spam and virus filtering
  • Managing user authentication and account security
  • Providing email migration services

2.2 The categories of data subjects include the Customer's employees, contractors, clients, and any other individuals who send or receive email through the Service.

2.3 The types of Personal Data processed include names, email addresses, email content and attachments, IP addresses, and authentication credentials, and — only where the Data Controller switches on open and click tracking (2.4) — when a recipient opened a Transactional API message and which of its links they followed.

2.4 Open and click tracking. Open and click tracking is available only for messages the Data Controller sends through the Transactional API. It is off by default and is switched on by the Data Controller, for the account or for an individual message. It is never applied to mail sent or received through mailboxes (webmail, IMAP/SMTP clients, forwarding). When it is on for a message, the Data Processor adds a 1×1 image to the message's HTML part and replaces the http(s) links in that part with links to its redirect service on justemails.app, which forwards the reader to the original link; the plain-text part is not changed. For each open (the image being loaded) and each click, the Data Processor records the message identifier, the time and, for a click, the link followed. These records do not include the recipient's IP address or device information; the network portion of the IP address is used transiently to rate-limit requests and is not stored with them. Neither the image nor the redirect sets a cookie. The records are kept with the message's delivery history while the Data Controller's account exists, are deleted with it, and are made available only to the Data Controller (dashboard, API, and any webhooks it configures). Opens are approximate: some mail clients and privacy features load images without the recipient opening the message, and others block them. The Data Controller decides whether to use this feature and is responsible for having a lawful basis for it, including any notice or consent the law applicable to its recipients requires.

3. Data Processor Obligations

The Data Processor shall:

  • Process Personal Data only on documented instructions from the Data Controller, unless required to do so by applicable law.
  • Ensure that persons authorised to process Personal Data have committed themselves to confidentiality.
  • Implement appropriate technical and organisational security measures as described in Section 5.
  • Assist the Data Controller in fulfilling data-subject requests (access, rectification, erasure, portability, etc.).
  • Assist the Data Controller in ensuring compliance with data-protection impact assessments and prior consultations with supervisory authorities where required.
  • Delete or return all Personal Data to the Data Controller upon termination of the Service, at the Controller's choice, unless retention is required by applicable law.
  • Make available to the Data Controller all information necessary to demonstrate compliance with this DPA and allow for audits.

4. Sub-processors

4.1 The Data Controller provides general authorisation for the Data Processor to engage Sub-processors. The Data Processor maintains the list of current Sub-processors below.

4.2 The Data Processor shall notify the Data Controller of any intended changes to Sub-processors at least 30 days before the change takes effect. The Data Controller may object to such changes within 14 days of notification.

4.3 The Data Processor shall impose data-protection obligations on Sub-processors that are no less protective than those set out in this DPA.

4.4 The Data Processor remains fully liable for the acts and omissions of its Sub-processors.

4.5 Current Sub-processors:

Sub-processorRoleLocation
RailwayWeb + API hostingUnited States
DigitalOceanMail server + object storage (email bodies, attachments)United States (SFO3, NYC3)
StripeBilling + payment processingUnited States
CloudflareEdge / DNS / Turnstile CAPTCHAGlobal anycast
ResendTransactional email fallbackUnited States
JustAnalyticsFirst-party product analytics (consent-gated)European Union (Frankfurt)
Twilio Inc.SMS delivery for two-factor authentication (only if you enable SMS 2FA)United States
Google LLCOAuth for the external-account bridge (only if you connect a Gmail account; scoped tokens stored)United States
Microsoft Corp.OAuth for the external-account bridge (only if you connect an Outlook / Microsoft 365 account)United States

5. Technical and Organisational Security Measures

The Data Processor implements the following security measures to protect Personal Data:

  • Encryption in transit — TLS 1.2 or later is required for every connection users and applications make to the Service (HTTPS, IMAP, POP3 and SMTP submission). Mail exchanged with other mail servers is encrypted with TLS whenever the other server supports it, as is standard for email.
  • Encryption at rest — credentials and keys held on the Data Controller's behalf (DKIM private keys, webhook signing secrets, two-factor secrets, and the credentials of connected external mailboxes and migrations) are encrypted by the Data Processor with AES-256-GCM before they are stored. Message bodies and attachments are stored on DigitalOcean Spaces and managed PostgreSQL, both of which encrypt data at rest at the platform level; the Data Processor relies on that platform encryption for this data and does not add an application-layer cipher of its own.
  • Data exports — an export requested by the Data Controller is delivered as a ZIP archive (mail as .mbox files, account data as JSON) that the Data Processor does not encrypt. It is uploaded over TLS to DigitalOcean Spaces, where it is covered by the same platform-level encryption at rest; made available only through a signed HTTPS link sent to the account's email address and valid for 7 days; and deleted from storage by a daily clean-up once it is more than 8 days old. Anyone holding the link can download the archive until the link expires. Passwords, two-factor secrets, API key secrets, DKIM private keys, webhook signing secrets and connected-account credentials are never included in an export.
  • Access controls — role-based access controls with principle of least privilege. Multi-factor authentication (TOTP + WebAuthn passkeys) required for administrative access.
  • Network security — a default-deny firewall on the mail server that admits only the mail, web and administrative SSH ports, and rate limits on sign-in, the API and mail submission.
  • Monitoring — continuous monitoring of systems and automated alerting for security events (autoheal on daemon death for critical mail-server processes).
  • Backups — regular automated backups, stored separately from the systems they protect. Nightly database dumps are encrypted by the Data Processor (OpenPGP, to a key held offline) before they are uploaded; mailbox backups and server snapshots rely on the platform-level encryption described above.
  • Incident response — documented incident-response procedures with defined roles and escalation paths.

Corrected 1 October 2026: earlier versions of this section said that data exports were encrypted with AES-256-GCM, which they were not, and described transport encryption and backup storage less precisely. The measures above describe what is actually done.

6. International Data Transfers

6.1 The Data Processor shall not transfer Personal Data outside the European Economic Area (EEA) unless appropriate safeguards are in place as required by Chapter V of the GDPR.

6.2 Where transfers to third countries are necessary, the Data Processor shall ensure they are covered by:

  • An adequacy decision by the European Commission
  • Standard Contractual Clauses (SCCs, Module Two: Controller → Processor) as approved by the European Commission
  • The UK IDTA Addendum for UK-origin transfers
  • Other legally recognised transfer mechanisms under the GDPR

6.3 The Data Processor shall conduct transfer impact assessments where required and implement supplementary measures as necessary.

7. Data Breach Notification

7.1 The Data Processor shall notify the Data Controller without undue delay after becoming aware of a Data Breach, and in any event within 72 hours per Article 33 GDPR.

7.2 The notification shall include:

  • The nature of the Data Breach, including categories and approximate number of data subjects and records affected
  • The name and contact details of the Data Processor's data-protection point of contact
  • A description of the likely consequences of the Data Breach
  • A description of the measures taken or proposed to address the breach, including mitigation measures

7.3 The Data Processor shall cooperate with the Data Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.

8. Audits and Inspections

8.1 The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and the GDPR.

8.2 The Data Controller may conduct audits, including inspections, to verify the Data Processor's compliance. Audits shall be conducted with reasonable prior notice (at least 30 days) and during normal business hours, and shall not unreasonably disrupt the Data Processor's operations.

8.3 The Data Processor may provide the Data Controller with relevant certifications or audit reports from independent third parties to satisfy audit requirements.

9. Duration and Termination

9.1 This DPA shall remain in effect for the duration of the Data Processor's processing of Personal Data on behalf of the Data Controller.

9.2 Upon termination of the Service, the Data Processor shall, at the Data Controller's choice, delete or return all Personal Data within 30 days, unless retention is required by applicable law.

9.3 The Data Processor shall provide certification of deletion upon request.

10. Governing Law

This DPA shall be governed by and construed in accordance with the same governing law as the Terms of Service (Delaware, USA), without prejudice to the mandatory provisions of the GDPR.

11. Contact Information

For questions about this DPA, contact us at:

Velocity Digital Labs LLC
Email: dpa@justemails.app
Website: velocitydigitallabs.com