LegalHisendy

Data Processing Agreement

Last updated 21 September 2026

The short version
You are the controller. Hisendy is your processor. This page is the agreement, already signed by us.
Four sub-processors, all named, with 30 days notice before we add one.
We tell you about a personal data breach within 72 hours of becoming aware of it.
You can ask for an audit once a year, and more often if there has been an incident.

Status of this page

This agreement takes effect when you accept the Terms of Service and forms part of them. It does not need a signature from us and we do not require one from you. If your procurement process needs a countersigned copy, email legal@hisendy.com and we will return one within two working days.

Roles and scope

You are the controller of the personal data you upload and of the people you contact. Hisendy is the processor. We process that data only on your documented instructions, which are: the configuration you set in the product, the campaigns you run, and these terms.

ItemDetail
Subject matterRunning cold email campaigns from mailboxes you connect
DurationWhile your account is open, plus 30 days
NatureStorage, retrieval, sending, receiving, labelling, exporting and deletion
PurposeProviding the service you have configured, and nothing else
Data subjectsYour contacts, your team members, and people who reply to you
CategoriesBusiness contact details, employment details you supply, message content, delivery and reply events
Special categoriesNone. Do not upload special category data. The product does not ask for it and it is a breach of the Terms to put it in.

Our obligations

Process only on your instructions, and tell you if we think an instruction breaks data protection law.
Keep everyone with access under a duty of confidence.
Apply the technical and organisational measures described on the Security page.
Help you answer data subject requests. The product already does most of this through export and delete.
Help you with data protection impact assessments and with prior consultation where you need it.
Delete or return the data at the end, at your choice, and delete existing copies unless the law makes us keep them.

Sub-processors

You give general authorisation for the sub-processors listed on our Sub-processors page. We will give at least 30 days notice by email to every account owner before adding or replacing one, and you may object in that window. If we cannot resolve an objection you may cancel without penalty and we will refund the unused part of the period.

International transfers

Where data leaves the UK or the EEA we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable, and those are incorporated into this agreement by reference. Module Two, controller to processor, applies between you and us.

Breach notification

We will tell you about a personal data breach affecting your data without undue delay and in any event within 72 hours of becoming aware of it. The notice will say what happened, what categories and roughly how many records are affected, what we are doing, and who to contact.

Audit

Once in any twelve months you may audit our compliance with this agreement, on 30 days notice, during business hours, without disrupting the service. Where an incident has occurred you may audit sooner. We will answer a reasonable security questionnaire in place of an on site audit if that suits you better.

Liability

Liability under this agreement is subject to the limits in the Terms of Service. Nothing in it removes either party’s direct liability to a data subject under data protection law.