Data Processing Agreement (DPA)
Pursuant to Art. 28 GDPR
Last updated: 25 July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you as the account holder (“controller”) and Fontemia GmbH as the operator of BgLetter (“processor”). It applies automatically and without separate signature as soon as you have personal data of your recipients processed through the Channel. On request we will provide you with a signed copy.
1. Subject matter, scope and duration
The subject matter of the processing is the execution of the email sends initiated by the controller through the BgLetter Channel. The processor deliberately provides no contact or address management: recipient data is provided by the controller for each send, processed solely for that send, and deleted automatically once the period set out in clause 10 has elapsed. Processing continues for as long as the account exists and ends when the account is deleted, subject to statutory retention obligations.
2. Nature and purpose of the processing
Collection, storage, personalisation, sorting, translation and transmission of recipient data for the purpose of sending the messages created by the controller via the controller’s own email provider; furthermore the recording of delivery, open, click and unsubscribe events, the maintenance of the unsubscribe list, and technical logging for error analysis and the prevention of misuse.
3. Categories of data subjects and data
The data subjects are the recipients of the controller’s messages as determined by the controller. Categories of data processed: email address, name and the personalisation fields provided by the controller, as well as language and country details and event data relating to delivery, opening, clicking and unsubscribing. The controller must not have any special categories of personal data pursuant to Art. 9 GDPR and no data pursuant to Art. 10 GDPR processed through the Channel.
4. Binding instructions
The processor processes personal data exclusively on documented instructions from the controller, unless it is required to process by Union or Member State law; in such a case the processor shall inform the controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Use of the functions of the Channel constitutes an instruction. Individual instructions require text form. The processor shall inform the controller without delay if it considers that an instruction infringes data protection law; it may suspend execution until the matter is clarified.
5. Confidentiality
The processor ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they have been instructed in the relevant data protection provisions. The group of persons with access rights is limited to the minimum necessary to perform the contract.
6. Technical and organisational measures (Art. 32 GDPR)
The processor takes in particular the following measures: encrypted transmission of all data (TLS); encrypted storage of the email account credentials (AES-256) and storage of passwords exclusively as a hash value; strict tenant separation at database level; role-based access control and optional two-factor authentication; logging of security-relevant operations; server hardening, firewall, rate limits and misuse detection; regular backups of system data; data minimisation through automatic deletion after 30 days; server location Germany. The processor may develop these measures further provided the level of protection is not reduced.
7. Sub-processors
The controller grants general authorisation for the use of the following sub-processors: a hosting provider with servers located in Germany for the operation of the infrastructure, and Anthropic for the optional AI functions (translation and assistant), whereby only message content and no recipient addresses are transmitted. Payment processing via PayPal concerns exclusively the controller’s own data and takes place under the controller’s own responsibility. The email provider chosen by the controller is not a sub-processor of the processor but falls within the controller’s responsibility. The processor shall give notice of intended changes at least 30 days in advance in text form; the controller may object on important data protection grounds and, in that case, terminate the contract.
8. Assistance to the controller
The processor shall assist the controller by appropriate technical and organisational measures in responding to requests from data subjects (Art. 12 to 23 GDPR) and in complying with the obligations under Art. 32 to 36 GDPR, insofar as this is proportionate and the necessary information is available to the processor. If a data subject contacts the processor directly, the processor shall forward the matter to the controller without delay. The processor may charge for assistance going beyond the scope provided for in Art. 28 GDPR on a time and materials basis.
9. Notification of personal data breaches
The processor shall notify the controller of any personal data breach that comes to its attention without delay, and at the latest within 48 hours of becoming aware of it, in text form, and shall make available the information at its disposal that the controller requires for its own notification obligations under Art. 33 and 34 GDPR. The obligation to notify the supervisory authority and the data subjects rests solely with the controller.
10. Deletion and return
Recipient data, message content and event data are deleted automatically and irretrievably no later than 30 days after the respective send. After the contract ends, the processor deletes all remaining personal data within 30 days, unless a statutory retention obligation applies; backup copies are overwritten in the course of the regular backup cycles. The controller is obliged to secure any data it requires via the export functions before these periods expire. The only data stored permanently is the unsubscribe list, in order to fulfil the obligations under Art. 21 GDPR.
11. Evidence and audits
The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, as a rule by means of an up-to-date description of the technical and organisational measures and by written information. Where this evidence is not sufficient in an individual case, the processor shall permit an audit after prior notice with reasonable notice periods, during normal business hours, no more than once a year, without disrupting operations, while preserving confidentiality and the rights of other customers, and at the controller’s expense. Audits by third parties require those third parties to be bound to confidentiality; competitors are excluded.
12. Obligations of the controller
The controller is solely responsible for the lawfulness of the processing. In particular, it ensures that a valid legal basis — in particular demonstrable consent — exists for every contact, that it informs recipients transparently, fulfils data subject rights, observes objections and transmits no special categories of personal data. It maintains the record of processing activities for its own processing itself and assesses the need for a data protection impact assessment on its own responsibility.
13. Liability
Liability between the parties is governed by the Terms of Service; Art. 82 GDPR remains unaffected. In the internal relationship, each party bears the share of any damage corresponding to its contribution to the responsibility. The controller shall indemnify the processor against claims based on the data it provided or the instructions it issued having been unlawful.
14. International transfers
Processing takes place on servers in Germany (EU/EEA). The processor is domiciled in Switzerland, for which an adequacy decision of the European Commission exists (Art. 45 GDPR). A transfer to a third country without an adequacy decision takes place exclusively in the context of the optional AI functions and is safeguarded by the European Commission’s standard contractual clauses.
15. Final provisions
Amendments to this DPA require text form. In the event of conflict, the provisions of this DPA take precedence over the Terms of Service in the area of processing on behalf. Should any provision be invalid, the validity of the remaining provisions remains unaffected. The German version is authoritative.
16. Contact
Please direct any questions about this DPA to:
This page is provided for information purposes and does not constitute legal advice.
See also: Terms of Service · Privacy Policy · Impressum / Legal notice