Relisend

Legal & data governance

Data Processing Addendum

Version 2026-08-13Effective 13 August 2026

How Relisend processes customer personal data on behalf of our customers.

Launch configuration incomplete. Relisend's verified operator name, service address, and representative must be configured before this addendum is relied upon publicly.
01

Scope and roles

For the mailbox, account, administration and support data you provide, you are the controller and Relisend is the processor. We process personal data only to provide and operate the Relisend service in accordance with your documented instructions and product settings.

Relisend is an independent controller for its own data, including security monitoring, billing, and compliance with legal obligations.

02

Instructions and confidentiality

We process personal data only on your documented instructions or as necessary to provide the service in accordance with your product settings, unless we are required to process the data by law.

Access to customer data is limited to authorised personnel who need it to perform their duties and are subject to confidentiality obligations.

03

Security, assistance and incidents

We implement appropriate technical and organisational measures to protect customer data, including:

Access controlRole-based access and least privilege.
Tenant isolationLogical separation between customers.
Transport encryptionEncryption in transit using industry standards.
LoggingAccess and system activity logging.
Vulnerability managementRegular assessment and remediation.
BackupsRegular, secure backups of customer data.
Attachment scanningScanning for malicious content and other risks.

We will provide reasonable assistance with data subject rights requests, taking into account the nature of the processing and the information available to us.

In the event of a personal data breach affecting customer data, we will notify you without undue delay after confirming the breach and assessing its impact.

04

Subprocessors, transfers and deletion

You authorise the use of the subprocessors listed by Relisend to provide the service. We will give reasonable notice of material changes to our subprocessors and you may object to a change on reasonable grounds.

For transfers of personal data outside the EEA, we use an appropriate mechanism under Chapter V of the GDPR.

We will return or delete customer data in accordance with the retention schedule, unless we are required by law to retain it.

Authorised subprocessorsCarefully selected partnersProtected EEA transfersUsing an appropriate Chapter V mechanismReturn or deletionIn accordance with our retention schedule

Purpose-limited processing

Data is used to provide, secure and administer Relisend.

Protected transfers

EEA transfers require recognised safeguards.

Your data rights

Access, correction, deletion and other rights are supported.