Amino Engine← All legal documents

Data Processing Addendum

Last updated 5 September 2026

Data Processing Addendum

Last updated: 5 September 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Amino Engine ("Processor", "we") and the customer named on the account ("Controller", "you"). It applies whenever we process personal data on your behalf.

If anything in this DPA conflicts with the Terms, this DPA wins on data protection.

How to accept it. Accepting the Terms accepts this DPA. If your organisation needs a signed copy, email support@aminoengine.com and we will countersign one.


1. Roles

You are the controller. You decide whose data goes into your account, why, and what is sent to them. We are the processor. We hold and transmit that data on your documented instructions and for no purpose of our own.

For US state privacy laws, you are the business and we are the service provider / processor. We do not sell or share personal information, and we do not retain, use or disclose it outside the direct business relationship with you.

Where you are yourself a processor for somebody else, this DPA applies between us as processor and sub-processor, and you confirm you have the authority to enter it.

2. Subject matter and details of the processing

Subject matter. Provision of the Amino Engine email marketing platform.

Duration. For as long as your account is open, plus the deletion window in section 11.

Nature and purpose. Storing, organising, segmenting, transmitting, analysing and deleting personal data so that you can send email to your subscribers and see what happened to it.

Categories of data subject. Your subscribers, customers and website visitors; and the people you invite into your account.

Categories of personal data.

  • Contact details: email address, and where you supply them, name, phone number, and any attributes, tags or notes you add.
  • Consent records: whether a person agreed to marketing, when, and the exact wording they were shown.
  • Message data: which messages were sent, and their delivery, bounce, complaint, open, click and unsubscribe outcomes.
  • Commerce data: orders, order value, line items, cart contents.
  • Website behaviour, if you install our tracker: an anonymous visitor id, page and referrer URLs, UTM parameters, time zone, and a derived device word (mobile, tablet, desktop, bot). We do not store the raw User-Agent string.
  • Suppression data: a one-way hash of an email address on the never-send list.

Special category data. None is required and none is expected. You must not upload special category data — including health, medical or diagnostic information about a person — into contact records, attributes, notes or event payloads. See the Acceptable Use Policy.

3. Our obligations (GDPR Article 28(3))

We will:

(a) Process on instructions only. We process personal data only on your documented instructions — which include your use of the app and its features — unless required by law, in which case we tell you first unless the law forbids it. We will tell you if we think an instruction breaks data protection law.

(b) Keep it confidential. Everyone we authorise to process your data is bound by confidentiality obligations.

(c) Secure it. We maintain appropriate technical and organisational measures under Article 32, described in Annex A below.

(d) Control sub-processors. As set out in section 5.

(e) Help you answer data subjects. As set out in section 6.

(f) Help you with Articles 32–36. We will give you reasonable assistance with security, breach notification, data protection impact assessments and prior consultation, taking into account what we know and what you can see in the app.

(g) Delete or return the data. As set out in section 11.

(h) Let you verify. As set out in section 8.

4. Your obligations

You warrant that:

  • you have a lawful basis for every person in your account, and valid consent where consent is the basis;
  • your privacy notice tells your subscribers that a processor sends your email, and how to exercise their rights;
  • you will not upload special category data or data about children;
  • your instructions to us will not put us in breach of applicable law.

5. Sub-processors

You give us general authorisation to use sub-processors. The current list — who they are, what they do, and where they are — is published at /legal/sub-processors and is incorporated into this DPA by reference.

We will give you [SUB-PROCESSOR NOTICE PERIOD — suggest 30] days' notice before adding or replacing one, by email to your account address and by updating that page. If you reasonably object on data protection grounds within that window, tell us; we will try to find a workaround, and if we cannot, you may terminate the affected part of the service without penalty for the unused remainder of your term.

Every sub-processor is bound by data protection obligations no less protective than these, and we remain fully liable to you for what they do.

6. Data subject requests

If one of your subscribers contacts us directly, we will not answer for you. We will tell them to contact you and, where we can identify the account, tell you.

The app gives you the tools to answer most requests yourself: contact search and export (access and portability), editing (rectification), suppression (objection), and erasure (Article 17). Where you need more, we will help you within a reasonable time and at no charge for a reasonable volume of requests.

Erasure, specifically. Our erasure destroys everything that identifies the person and leaves behind a one-way hash on the never-send list, and nothing else. That retention is deliberate and relies on Article 17(3) and Recital 26: it identifies nobody, it cannot be reversed, and without it a later import would email somebody who asked to be forgotten. This is described plainly in the Privacy Policy.

7. Personal data breach

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware.

The notice will describe, as far as we know it at the time: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, the measures we have taken, and a contact point. We will keep you updated as we learn more, and we will help you meet your own notification duties under Articles 33 and 34.

Notice goes to the email address on your account. Keep it current. [CONFIRM whether a dedicated security contact field should be added to the account.]

8. Audit

On reasonable written request, and no more than once in any 12 months unless a regulator requires more or a breach has occurred, we will:

  • give you the information you reasonably need to show that we are meeting this DPA, including any third-party audit reports or certifications we hold; and
  • if that is genuinely not enough, allow an audit by you or an independent auditor you appoint who is not a competitor of ours, at your cost, on at least 30 days' notice, during business hours, without unreasonable disruption, and subject to confidentiality.

[NOTE FOR COUNSEL: we hold no SOC 2 or ISO 27001 report today. Decide whether to commit to obtaining one, and by when.]

9. International transfers

Your data is processed in the United States (hosting and database) and Canada (mail servers).

Where you transfer personal data from the EEA, the UK or Switzerland to us, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and take effect on that transfer. Where you are yourself a processor, Module Three applies instead.

For the purposes of those Clauses:

  • Data exporter is you; data importer is Amino Engine.
  • Clause 7 (docking) applies.
  • Clause 9 — option 2, general written authorisation, with the notice period in section 5.
  • Clause 11 — the optional independent dispute resolution body is not used.
  • Clause 17 — governing law is the law of [EU MEMBER STATE — commonly Ireland].
  • Clause 18(b) — forum is the courts of that same member state.
  • Annex I is populated by section 2 of this DPA and the account details; Annex II by Annex A below; Annex III by the sub-processors page.

For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated, with the Clauses above as the approved transfer mechanism, Tables 1–3 populated as set out here and Table 4: neither party may end the Addendum. [CONFIRM Table 4 election with counsel.]

For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the supervisory authority is the Swiss FDPIC.

Canada currently benefits from an EU adequacy decision for commercial organisations.

10. Government access requests

If a public authority asks us for your data, we will tell you unless we are legally forbidden to. We will challenge requests we believe are unlawful or overbroad, and we will disclose only the minimum the law requires.

11. Deletion on termination

When your account ends, you choose within [RETURN WINDOW — suggest 30] days whether you want your data returned. The app exports contacts, message history and analytics as CSV at any time, and that export is the return mechanism.

After that window we delete or irreversibly anonymise your personal data on our production systems, and instruct our sub-processors to do the same, within [DELETION WINDOW — suggest 90] days. Backups age out on their own rotation and are not restored to serve a live account.

Two things are excepted: records we must keep by law (billing and tax), and suppression hashes, which identify nobody and are retained so that a never-send decision cannot be lost. Both remain subject to the confidentiality and security terms of this DPA.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where the law does not allow that.


Annex A — Technical and organisational measures (Article 32)

Separation between customers. Every customer's data is isolated at the database level by row-level security, and the application connects with an account that cannot switch that protection off. A query run in one account's context cannot return another account's rows.

Encryption. All traffic is encrypted in transit with TLS. Passwords are stored only as hashes. DKIM signing keys are encrypted at rest.

Access control. Access to production data is limited to staff who need it, authenticated individually. Application sessions are short-lived, signed and httpOnly.

Consent and suppression integrity. The consent ledger is append-only and protected at the database level from update and deletion. Suppression entries survive erasure by design.

Sending safeguards. The platform monitors complaint and bounce rates continuously and will automatically slow or stop marketing sends before an account can damage its own or others' deliverability.

Logging. Administrative actions and data exports are recorded in an audit log.

Data minimisation. We derive a device word from the User-Agent and discard the raw string. We do not collect special category data.

Resilience. Hosting and database are managed services with automated backups maintained by our hosting sub-processor.

Incident response. Suspected incidents are triaged immediately; customer notification follows section 7.

[COUNSEL: confirm whether to add penetration testing cadence, formal vendor review policy, and staff security training commitments before signing anything.]


Questions about this DPA, or to request a signed copy: support@aminoengine.com

Questions: support@aminoengine.com