Data Processing Agreement
Last updated 2026-10-04
1. Parties and scope
This agreement is between the customer ("Controller") and Mario Portilho, Portugal ("Processor") and forms part of the Terms of Service. It applies to personal data of the Controller's contacts that the Processor processes to provide Zynlo (Article 28 GDPR).
2. Details of processing
Subject and purpose: storing contact profiles, events and consent records, building segments, and sending and measuring email on the Controller's behalf.
Data subjects: the Controller's customers, subscribers and website visitors.
Categories of data: identifiers and contact details (email, name, phone), consent records, order and browsing events, email engagement data and any custom properties the Controller adds. The Controller must not send special categories of data.
Duration: for the term of the Terms of Service plus up to 30 days for deletion.
3. Processor obligations
Process personal data only on the Controller's documented instructions, including through use of the service's features.
Ensure people authorised to process the data are bound by confidentiality.
Implement appropriate technical and organisational measures, including encryption in transit, encrypted secrets at rest, access control, logical separation between customer accounts, and backups.
Help the Controller respond to data subject requests: the service provides profile export and deletion.
Notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data.
Assist with data protection impact assessments and consultations where reasonably required.
4. Subprocessors
The Controller gives general authorisation for the subprocessors listed on the Subprocessors page. The Processor will give at least 30 days' notice by email of any new subprocessor, during which the Controller may object and, if no solution is found, terminate the service. The Processor imposes the same data protection obligations on each subprocessor.
5. International transfers
Data is hosted in the EU. Any transfer outside the EEA is subject to an adequacy decision or the Standard Contractual Clauses.
6. Deletion and return
When the service ends, the Controller can export its data. The Processor deletes the Controller's personal data within 30 days, and from backups within 90 days, unless EU or member state law requires storage.
7. Audits
The Processor makes available the information needed to demonstrate compliance with this agreement and allows audits by the Controller or an auditor it mandates, with reasonable notice, at the Controller's cost, no more than once a year unless required by a supervisory authority.