Data Processing Agreement
Last updated: July 19, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and the Processor for the provision of the DMARCguard service (the "Service"), and governs the processing of personal data by the Processor on behalf of the Controller.
1. Parties
- Controller: the customer entity that accepts this DPA (identified in the order / account record).
- Processor: Developer Friendly OÜ, a company registered in Estonia (registry code 16511866), registered address Jõe tn 3-305, Kesklinna linnaosa, 10151 Tallinn, Harju maakond, Estonia, trading as DMARCguard.
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the EU General Data Protection Regulation 2016/679 ("GDPR"). "Data Protection Law" means the GDPR and any other data-protection law applicable to the processing under this DPA.
3. Roles and scope
The Controller is the controller and the Processor is the processor of the personal data described in Annex I. The Processor processes personal data only to provide the Service and only in accordance with this DPA. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I.
4. Controller obligations
The Controller warrants and undertakes that:
- (a) it has, and will maintain, a valid legal basis for the processing of personal data under this DPA and for instructing the Processor to process personal data on its behalf — including for any third-party personal data contained in DMARC forensic (RUF) reports submitted to the Service;
- (b) its documented instructions to the Processor comply with Data Protection Law, and it will not instruct the Processor to process personal data in a manner that would cause the Processor to breach Data Protection Law;
- (c) it is responsible for ensuring that data subjects have been informed of the processing described in this DPA, to the extent required by Data Protection Law.
5. Processor obligations (GDPR Article 28(3))
The Processor shall:
- (a) Documented instructions — process personal data only on the Controller's documented instructions (which comprise this DPA and the Controller's configuration and use of the Service), including with regard to transfers of personal data to a third country or an international organisation, unless required otherwise by applicable law (in which case the Processor informs the Controller unless legally prohibited). The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Data Protection Law, before carrying out the instruction.
- (b) Confidentiality — ensure persons authorized to process the personal data are bound by confidentiality.
- (c) Security — implement the technical and organizational measures set out in Annex II, appropriate to the risk, in accordance with GDPR Article 32.
- (d) Sub-processors — engage sub-processors only under the conditions in Section 6 and Annex III.
- (e) Data-subject rights — taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection), and forward to the Controller without undue delay any data-subject request the Processor receives directly.
- (f) Assistance — assist the Controller in ensuring compliance with GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and the information available.
- (g) Deletion or return — at the Controller's choice, delete or return all personal data at the end of the provision of the Service as set out in Section 9, and on request certify deletion in writing.
- (h) Audits — make available to the Controller the information necessary to demonstrate compliance with this Article and allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor. For proportionality, the Processor may first satisfy this obligation by providing its security documentation and responses to a reasonable security questionnaire. On-site or third-party audits take place on at least four weeks' written notice, no more than once per twelve-month period, during normal business hours, and subject to confidentiality obligations; the Controller bears the cost of the audit unless it reveals material non-compliance by the Processor, and any mandated auditor must not be a competitor of the Processor.
6. Sub-processors
The Controller provides general written authorization for the Processor to engage the sub-processors listed in Annex III. The Processor:
- imposes on each sub-processor, by contract, data-protection obligations equivalent to those in this DPA, except as expressly noted in Annex III (AbuseIPDB, whose vendor data-processing terms are being pursued; pending execution, the applied safeguard is strict data minimization — only the bare IP address queried is transmitted);
- remains fully liable to the Controller for the performance of each sub-processor's obligations;
- gives the Controller 30 days' prior notice — by email to the Controller's account owner (or notified security contact) — of any intended addition or replacement of a sub-processor; the register at https://dmarcguard.io/subprocessors/ reflects the current list. The Controller may object on reasonable data-protection grounds within 15 business days (Estonian working days) of the notice. If the parties cannot resolve a good-faith objection, the Controller may terminate the affected Service on written notice without penalty, with a pro-rata refund of prepaid fees for the terminated period.
7. International transfers
Personal data under this DPA is stored and processed in the EU (primary region: Germany). Storage of the Controller's data with the Processor in the EU is not, of itself, a restricted transfer under GDPR Chapter V. Where any onward processing would transfer personal data outside the EEA (for example, a sub-processor that is a non-EEA entity), the parties rely on an appropriate transfer mechanism — the EU Standard Contractual Clauses (Commission Decision 2021/914, relevant module) or an adequacy decision or approved certification — except as expressly noted in Annex III for AbuseIPDB, pending execution of that vendor's data-processing terms.
For the relationship between an EU-based Processor and a Controller established in Chile, the parties may additionally rely on Chile's transitional Model Contractual Clauses (Cláusulas Contractuales Modelo, Resolución RAEX202503748, 11 December 2025, published in the Diario Oficial on 19 December 2025) as the Chile-side transfer basis, applicable until the Chilean Data Protection Agency approves its own transfer mechanisms under Article 28 of Law 21.719. This DPA does not assert that the European Union is designated as providing an adequate level of protection under Chilean law; the Controller is responsible for confirming its own transfer basis under applicable Chilean law with its own counsel.
8. Personal-data breach
The Processor notifies the Controller without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach affecting the Controller's personal data. The notification includes, to the extent available at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed; where complete information is not yet available, the Processor provides it in phases without undue further delay. The Processor cooperates with the Controller to assist it in meeting its own notification obligations (GDPR Articles 33–34).
9. Retention, return, and deletion
On termination or expiry of the Service, the Controller may retrieve its data during the retrieval window in the main service agreement (at least 30 days). After that window expires, the Processor deletes or, at the Controller's choice, returns the Controller's personal data within a further 30 days, and deletes existing copies unless retention is required by applicable law; copies in encrypted backup archives expire in the ordinary course of backup rotation. During the Service, retention follows the Controller's configured retention settings and the tier retention windows stated in Annex II.
10. Liability, term, and governing law
- (a) Liability. The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the main service agreement (the DMARCguard Terms of Service), and the aggregate liability cap there applies to claims under the main agreement and this DPA together. Nothing in this DPA excludes or limits either party's liability for death or personal injury caused by negligence, for damage caused intentionally or through gross negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot be excluded or limited under applicable law.
- (b) Term and execution. This DPA takes effect when the Controller accepts it — electronically as part of accepting the main service agreement, or by countersigning a copy of this DPA (contact [email protected] to request a countersigned copy) — and remains in force for as long as the Processor processes personal data on the Controller's behalf. Sections 5(b) (confidentiality), 5(g) and 9 (deletion and return), and 10 survive termination until fully performed.
- (c) Governing law and jurisdiction. This DPA is governed by the laws of Estonia. The parties submit to the exclusive jurisdiction of Harju County Court (Harju Maakohus), Tallinn, Estonia, without prejudice to mandatory rights of data subjects and supervisory authorities under Data Protection Law.
11. Notices
Formal notices under this DPA must be in writing; email is a valid means of notice. Notices to the Processor go to [email protected]; notices to the Controller go to the Controller's account owner email address or to a security contact the Controller has notified to the Processor in writing (breach notifications under Section 8 go to that contact where notified). A notice sent by email is deemed given on the date sent, provided no delivery failure is received within 24 hours.
12. Order of precedence
In the event of a conflict between this DPA and the main service agreement, this DPA prevails to the extent of the conflict, in relation to personal-data-processing matters only.
Annex I — Description of Processing
Subject matter
Processing of personal data contained in email-authentication reports (DMARC aggregate and forensic reports, SMTP TLS reports) and in Controller account data, for the purpose of providing the DMARCguard Service.
Nature and purpose of processing
Ingestion, parsing, storage, analysis, alerting, reporting, and visualization of email-authentication data submitted to or on behalf of the Controller, and administration of the Controller's account and users.
Duration
For the term of the service agreement, plus the retention and deletion periods described in the DPA and the Service's published retention settings.
Categories of data subjects
Individuals whose personal data may appear in email-authentication reports — for example senders, recipients, or operators of mail infrastructure whose identifiers appear in report metadata or forensic report content.
Categories of personal data
| Category | Examples | Sensitivity |
|---|---|---|
| DMARC aggregate (RUA) | source IP addresses (predominantly infrastructure), authentication results, message counts, sending/header domains | low |
| DMARC forensic (RUF) | envelope from/to, subject lines, message headers — may contain third-party personal data | higher |
| SMTP TLS reports | reporting-MTA identifiers, receiving-MX hostnames, session counts | low |
Scope note — controller-side data
Account data (user emails, names, credentials), billing and subscription metadata, support communications, and product analytics are processed by Developer Friendly OÜ as an independent controller, as described in its Privacy Policy, and are not within the processor scope of this DPA.
Special categories of data
The Service is not designed to process special categories of personal data (GDPR Article 9). The Controller shall not use the Service to submit special categories of data except as strictly incidental to email-authentication reporting outside the Controller's control.
Frequency of processing
Continuous, for the duration of the Service.
Annex II — Technical and Organizational Measures
The Processor maintains technical and organizational measures appropriate to the risk (GDPR Article 32). These measures describe outcomes and are updated as the Service evolves; specific implementations are managed internally. They include:
Data residency
- Customer service data is stored and processed in the EU (primary region: Germany).
- Product analytics are hosted in the EU.
- Billing is handled by the merchant of record (Polar Software, Inc., USA) as an independent controller — see Annex III.
Encryption
- In transit: TLS 1.2 minimum, with TLS 1.3 supported, for connections to the Service.
- At rest: customer data is encrypted at rest using AES-256; sensitive credentials are additionally encrypted at the application layer (AES-256-GCM).
Access control
- Production access is restricted to authorized personnel on a least-privilege basis.
- Administrative access to production systems is restricted to authorized personnel over key-based SSH from trusted hosts; third-party administrative accounts (hosting, DNS, code, email) enforce multi-factor authentication with hardware-backed passkeys where supported.
- The Service supports single sign-on (SSO/OIDC) and multi-factor authentication for customer users.
- Administrative actions are recorded in an audit log.
Tenant isolation
- Customer data is logically isolated per organization with row-level tenant separation.
Backups and continuity
- Automated, encrypted backups are retained in the EU and are restored and validated on a regular basis (recovery point objective approximately one hour; target recovery time objective one business day, best effort).
Logging and monitoring
- The Service is monitored on self-operated EU infrastructure; monitoring endpoints are private and access-controlled.
Secure development
- Automated dependency and vulnerability scanning, signed release artifacts, and an implementation built against current email-authentication standards (DMARCbis: RFC 9989, RFC 9990, RFC 9991), with documented interoperability accommodations for legacy systems.
Data minimization and retention
- Data is retained per the Controller's configured retention settings and the tier retention windows — Free: 30 days · Pro: 1 year · Enterprise: customer-configurable (including indefinite, at the Controller's instruction) — after which it is deleted.
- Forensic (RUF) report retention is configurable separately per report type by the Controller; RUF payloads are access-controlled and their stored files are deleted together with the database rows by the retention purge.
- The Processor does not sell customer data and does not use customer email-authentication data for third-party advertising or profiling.
Personnel
- All persons with production access are bound by written confidentiality undertakings.
Vulnerability reporting
- Security reports are received at [email protected] (published in
/.well-known/security.txtper RFC 9116) and triaged with priority.
Breach response
- Documented incident-response process, reviewed after every incident and at least annually; notification to affected controllers without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach.
Annex III — Sub-processors
The sub-processor register is maintained at /subprocessors/, which forms Annex III of this DPA.