Refresh

Legal

Data Processing Addendum

This addendum forms part of the Terms of Service. It applies whenever Refresh processes personal data on behalf of an organization. It is pre-signed: accepting the Terms accepts this addendum, and no separate signature is needed.

Effective September 30, 2026

1. Parties and roles

Customer is the organization that holds the account. Processor is Obsidian Heron, 30 N Gould St Ste R, Sheridan, WY 82801. For customer content (Annex 1) Customer is the controller, or a processor acting for its own controllers, and Processor acts on Customer’s documented instructions. For account data Processor is an independent controller under the Privacy Policy.

2. Instructions

Processor processes customer content only to provide the service as described in the Terms and the documentation, as configured by Customer in the console and the API (retention settings, suppression rules, tracking, webhooks, and the messages Customer submits), and as required by law. Providing the service includes screening outgoing messages, automatically and with the AI sub-processor in Annex 3, for phishing, fraud and impersonation, and holding sending while a person reviews a finding (see the Sending policy). If Processor believes an instruction breaks data protection law it will say so before acting. Processor will not sell customer content, use it for its own purposes, or combine it with data from other customers.

3. Confidentiality and personnel

Only named operators of Processor may access production systems. Each is bound by confidentiality, uses multi-factor authentication, and is granted access only for the support Customer asked for, an incident, or maintenance. Before an operator opens a session against production data, the platform writes an operator.access entry with the reason to Customer’s audit log, which Customer’s admins can read in the console. Access is reviewed quarterly and removed the day a person leaves.

4. Security measures

Processor maintains the measures in Annex 2 and will not lower them during the term. The current technical description is the data protection guide.

5. Sub-processors

Customer authorises the sub-processors in Annex 3. Processor will post changes to that list on this page and e-mail Customer’s admins at least 30 days before a new sub-processor processes customer content. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees. Processor remains responsible for its sub-processors’ performance.

6. Assistance

  • Data subject requests. Customer handles requests from its recipients using the console and the API (export, delete, suppress). Processor forwards any request it receives directly to Customer within 5 business days and does not answer it itself unless Customer asks.
  • Impact assessments and consultations. Processor provides the information in Annex 2 and this addendum, and answers reasonable further questions.
  • Records. Processor keeps records of processing for the service and makes the relevant parts available on request.

7. Security incidents

Processor notifies Customer’s admins by e-mail without undue delay, and no later than 72 hours after becoming aware of a personal data breach affecting customer content, with what is known at the time: nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken. Processor updates the notice as facts emerge and cooperates with Customer’s own notifications.

8. Deletion and return

  • During the term Customer deletes customer content itself: message bodies expire on its body retention setting (0 to 90 days), events on its event retention setting, contacts and suppressions on demand, and the whole organization at once from the console.
  • On deletion of an organization, its data is removed from the production database immediately. Its dedicated encryption key is scheduled for deletion and is destroyed after 30 days, after which no remaining copy can be decrypted. Object storage is emptied by a lifecycle rule within 90 days. Backups are overwritten at the end of the database provider’s point-in-time window.
  • Before deleting, Customer may export its data through the console and the API. Processor will confirm deletion in writing on request.

9. Audits

Processor makes available the information reasonably necessary to demonstrate compliance with this addendum: this document, Annex 2, the data protection guide, and answers to a written security questionnaire once per year. Where that is not enough to satisfy a legal requirement, Customer may audit, or appoint an independent auditor bound by confidentiality to audit, no more than once per calendar year, on 30 days’ notice, during business hours, limited to the processing of Customer’s own data, at Customer’s cost.

10. International transfers

The service is hosted in the United States (Annex 3). Where Customer transfers personal data from the European Economic Area, the United Kingdom or Switzerland to Processor, the parties incorporate the European Commission’s Standard Contractual Clauses (Module 2, controller to processor, or Module 3, processor to processor, as applicable), the UK International Data Transfer Addendum, and the Swiss FDPIC amendments, with this addendum supplying the annexes. Where those clauses conflict with this addendum, the clauses prevail.

11. Liability and precedence

Each party’s liability under this addendum is subject to the limitations in the Terms. Where this addendum conflicts with the Terms on the processing of personal data, this addendum prevails. This addendum is governed by the laws of Wyoming, United States.

Annex 1 — Description of processing

Subject matterSending email on Customer’s behalf and reporting on its delivery.
DurationThe term of the account, then the deletion periods in section 8.
Nature and purposeStoring, rendering, signing and transmitting messages; recording delivery, engagement, bounce and complaint events; maintaining contact, topic, segment and suppression lists; receiving replies; calling Customer’s webhooks.
Categories of data subjectsCustomer’s recipients (customers, users, subscribers, correspondents) and Customer’s own staff who use the console.
Categories of personal dataE-mail addresses; names and other contact properties Customer stores; message subject and content; delivery and engagement events with timestamps; IP addresses and user agents where tracking is enabled; the content of inbound replies.
Special categoriesNone intended. Customer must not send special-category data through the service unless its body retention is 0 and it has assessed the transfer to mailbox providers itself.

Annex 2 — Technical and organisational measures

  • Encryption in transit: TLS on every hop; database connections verify the server certificate; requests to AWS are signed.
  • Encryption at rest: AES-256 at the storage layer. Signing keys, webhook secrets and alert targets are additionally encrypted at the application layer (AES-256-GCM) with data keys wrapped by AWS KMS. Each client organization has a dedicated KMS key; deleting the organization destroys it.
  • Tenant isolation: every record carries its organization; every query is scoped by membership; each organization has its own sending reputation unit at the delivery provider.
  • Access control: role-based access in the console (admin, member, viewer); API keys scoped to permission and domain, hashed at rest, shown once; named operators only, multi-factor authentication, quarterly review; operator access written to the customer’s audit log.
  • Logging: every console and API action is recorded in the organization’s audit log, which is not trimmed.
  • Data minimisation: Customer sets body retention (0 to 90 days, 0 = content removed at send) and event retention; the platform removes expired data daily.
  • Resilience: managed database with point-in-time recovery; queued sending with retry; status page.
  • Development: automated tests on every change; independent review before deployment; no production data in development environments.

Annex 3 — Sub-processors

Sub-processorFunctionLocation
Amazon Web Services, Inc.Mail delivery (SES), key management (KMS), object storage (S3), audit loggingUnited States (us-east-1; us-west-2 for failover)
Netlify, Inc.Hosting of the console, the API and this websiteUnited States
Prisma Data, Inc.Database hosting (Prisma Postgres)United States (US East)
Upstash, Inc.Queue and cache (Redis)United States
Cloudflare, Inc.DNS for the platform's own domains and delivery of this websiteUnited States
Stripe, Inc.Billing and payment processingUnited States
Google LLCSign-in (Google OAuth), Postmaster Tools reputation data, and checking links in outgoing mail against Web RiskUnited States
Anthropic, PBCAutomated review of outgoing mail for phishing, fraud and impersonationUnited States

Questions about this addendum: hello@f5send.com.