SendVeilBack to SendVeil

DATA PROCESSING AGREEMENT · VERSION 1 · 8 OCTOBER 2026

Data Processing Agreement (Art. 28 GDPR)

This agreement is available in English (binding) and German.

This agreement applies when the customer processes personal data of other people through SendVeil. It is accepted together with the SendVeil Terms and needs no separate signature. The English text is binding; translations are for convenience.

1. Parties

2. Subject matter and nature

The Processor hosts and delivers the files, transfer metadata (titles, file names, expiry, download events), brand assets, file-request submissions and workspace user data (email, role, sessions, audit events) that the Controller places in its SendVeil workspace. Operations: receipt of resumable uploads, storage of original bytes, signed-link delivery, optional email notification, expiry, purge and export. Purpose: providing the SendVeil service to the Controller. Categories of data subjects: the Controller's workspace members, recipients and uploaders. Data categories: those the Controller chooses to upload (may include special categories; the Controller is responsible for its legal basis).

3. Duration

For as long as the workspace exists. Transfers follow the Controller's chosen expiry (from 1 day up to the plan maximum of 7–365 days; no fixed expiry with the Infinity add-on, 30-day tail when it ends). Audit events are deleted after 365 days. A workspace without an active paid subscription is deleted after 180 days without account activity. The agreement ends with deletion of the workspace.

4. Processor obligations (Art. 28(3))

  1. Processes only on the Controller's documented instructions (use of the product and its settings are the instructions); tells the Controller if an instruction appears unlawful.
  2. Persons with access are bound to confidentiality. The Processor is currently the sole person with administrative access.
  3. Implements the measures in section 5.
  4. Sub-processors only under section 6; the Controller is informed of changes.
  5. Assists with data-subject requests (owner export and deletion in the Settings app; other requests via privacy@sendveil.link) and with Art. 32–36 obligations.
  6. Notifies the Controller without undue delay after becoming aware of a personal data breach.
  7. Provides information needed to demonstrate compliance and allows reasonable audits on prior notice, preferably by documentation first.

5. Technical and organisational measures (as implemented)

Encryption at rest is provided by the storage providers; any stronger claim (e.g. customer-managed keys) is not made here.

6. Sub-processors

Cloudflare, Inc. is the only sub-processor for workspace content: Workers, R2 and Durable Objects under EU jurisdiction, outbound email and Turnstile. Storage is in the EU; network and operational data may be processed outside the EU under Cloudflare's own data processing terms.

Stripe (Managed Payments) processes payment, billing and tax data as an independent controller, not as a sub-processor.

Support correspondence sent to hello@sendveil.link or privacy@sendveil.link, including its copy in Google Gmail and optional AI reply suggestions via Mistral AI, is not workspace content and is described in the privacy notice.

The Processor will inform the Controller of intended additions by email or in the product at least 30 days in advance; the Controller may object or close the workspace.

7. International transfers

Customer content stays in the EU storage configuration. Where Cloudflare processes operational data outside the EU, Cloudflare's own data processing terms apply.

8. Deletion and return on account closure

On account deletion by the owner, or automatic deletion after inactivity, the Processor removes the workspace registry, all file objects in R2, sessions, branding, memberships, application database tables and Durable Object storage including alarms; public and guest links return not-found as soon as deletion starts. Before deleting, the owner can export account metadata; the Controller is responsible for downloading its files beforehand. Records held by Cloudflare (mail delivery or suppression logs) or Stripe (payment and tax records), copies of support correspondence and records the Processor must keep by law are retained under their own periods and are not removed by account deletion.

9. Liability, governing law

Liability follows the SendVeil Terms; this agreement adds no separate cap, and Art. 82 GDPR remains unaffected. Austrian law applies, excluding its conflict-of-law rules. The courts competent for Graz have jurisdiction unless mandatory law provides otherwise.