Legal
Data Processing Agreement
The short version
When you send mail through Announcer you hand us personal data about your recipients. For that data you decide what happens and we only carry it out. This page is the agreement that says so, in the terms Article 28 of the GDPR requires. It is already in force for every account — you do not have to ask us for a copy or sign anything to get one.
This box is a summary and is not the agreement. The sections below are.
1. What this is, and when it applies
This Data Processing Agreement ("DPA") forms part of the Terms of Use between you ("you", "the Customer") and Trohld AS, registered at Ladebekken 38, 7041 Trondheim, Norway ("Misralo", "we", "us"). It applies automatically from the moment you create an account, for as long as that account exists, and it governs our processing of personal data on your behalf under Regulation (EU) 2016/679 ("GDPR") and the equivalent UK regime.
Where this DPA and the Terms of Use disagree about personal data, this DPA wins. Where this DPA and our Privacy Policy disagree, this DPA wins for data you send us about other people; the Privacy Policy governs data about you.
With one exception: nothing in this DPA varies the limitations and exclusions of liability in the Terms of Use, which apply to claims under this agreement exactly as they apply to any other.
If your organisation needs a countersigned copy on paper, write to privacy@misralo.com and we will sign one. It will say what this page says.
2. Who is who
There are two different sets of personal data here and they have different owners, which is the distinction the rest of this document rests on.
- Data about your recipients — the addresses you send to, and what happened to that mail. You are the controller. We are your processor, and we act only on your instructions. This DPA covers it.
- Data about you — your account, your login, your domains, your billing relationship with us. We are the controller for that, and our Privacy Policy covers it. This DPA does not.
You are responsible for having a lawful basis to email the people you email, and for the content of what you send. We do not check either, and nothing in this agreement moves that responsibility onto us.
3. What we process, and why
| Subject matter | Providing the Announcer transactional email service: accepting messages you submit, signing them, delivering them, and reporting what happened. |
|---|---|
| Duration | For as long as your account is open, subject to the deletion schedule in section 11. |
| Nature and purpose | Transmission of email on your instruction, and the recording of delivery outcomes so that you can see them and so that we can protect the sending reputation the service depends on. |
| Categories of data subject | The people you send mail to — typically your own users, customers or subscribers. |
| Types of personal data | Recipient email addresses; the sender address you choose; subject lines; message and delivery metadata (identifiers, timestamps, delivery status, error text returned by the receiving server); bounce and complaint reports; and the addresses on your suppression list. |
| Not processed | Message bodies are not stored. The content you submit is assembled, signed and handed to the outbound mail server; no database record retains it. It follows that we cannot produce, search, export or restore the content of a message, for you or for anyone else. Subject lines are the exception and are stored deliberately. |
| Special categories | The service is not designed for special-category data under Article 9, and we ask you not to put it in a subject line. What you place in a message body we do not see or keep. |
4. Your instructions
We process recipient personal data only on your documented instructions. Your instructions are: this DPA, the Terms of Use, and the API calls and dashboard actions you make. We do not use the data for anything of our own — we do not mine it, build profiles from it, train anything on it, sell it, or market to your recipients.
If we are ever required by EU or member-state law to process it otherwise, we will tell you before doing so unless that law forbids the warning. If we think one of your instructions breaches data protection law, we will tell you and may pause that processing rather than carry it out.
5. Confidentiality
Everyone we authorise to access this data is bound to keep it confidential, by contract or by professional obligation, and that duty outlives their engagement with us. Access is limited to the people who need it to run and support the service.
6. Security
We take the measures required by Article 32. Concretely, and as of the date above:
- All traffic is served over TLS. The API and the dashboard are reachable no other way.
- Message bodies are never written to storage, which is the strongest control available: what is not kept cannot leak.
- Passwords are stored as Argon2id hashes; session tokens and API keys only as SHA-256 hashes, so a copy of our database does not yield a working credential.
- Each customer's DKIM private keys stay on our server, are never returned by any endpoint, and are deleted with the domain or the account.
- Backups are encrypted before they leave the host.
- Authentication, signup and account endpoints are rate-limited against guessing.
- Tenant isolation is enforced in the application on every request; a key or session reaches its own account's data and nothing else.
Security is not a fixed list. We may change these measures, but not in a way that materially weakens the protection described here.
7. Sub-processors
You give us general authorisation to engage the sub-processors below. Each is bound by data protection terms no weaker than these, and we remain fully liable to you for what they do.
| Who | What for | Where |
|---|---|---|
| Akamai (Linode) | The server the service runs on, and encrypted off-host backups. | Stockholm, Sweden |
| Cloudflare | Authoritative DNS for our own domains, and forwarding of mail sent to our published addresses. | Global |
That is the whole list, and it is short on purpose. Google, GitHub and Stripe/Link appear in our Privacy Policy but not here. Google and GitHub are involved only if you choose to sign in with them; Link is involved only if you buy a paid plan, and as the seller of record it acts on its own account rather than on our instructions. All three touch your own account data — where we are the controller, or they are — and never your recipients' data, which is the only thing this agreement covers.
If we intend to add or replace a sub-processor we will say so at this page and by email to account holders at least 30 days beforehand. If you object on reasonable data protection grounds within those 30 days, tell us and we will work to offer you an alternative; if we cannot, you may close your account before the change takes effect and we will refund any prepaid, unused fees.
8. Where the data goes
The service runs on a single host in Sweden, inside the EEA, and that is where account data, domains and message records are stored.
Email is a global system, and this is the one transfer you should understand clearly: a message you send leaves for the recipient's own mail provider, wherever that provider is. If you address a message to someone whose mail is hosted outside the EEA, the message goes outside the EEA. That destination is determined by the address you choose, not by us, and it is an inherent and necessary part of the instruction you give us — Article 49(1)(b) and (c) rather than a transfer mechanism we could substitute. No such transfer is a decision we make on your behalf.
Where a sub-processor in section 7 may access data from outside the EEA in the course of operating or supporting its infrastructure, that access is covered by the European Commission's Standard Contractual Clauses in that sub-processor's own data protection terms.
9. Helping you answer your users
Most requests you receive you can answer yourself, immediately, without involving us:
message records are searchable by recipient in the dashboard and through
GET /v1/messages, and your suppression list is readable and
editable the same way. That is deliberate — a right you have to email a vendor about is
a right that takes days instead of seconds.
For anything that needs us, we will assist you with appropriate technical and organisational measures, so far as is possible, in meeting your obligations under Articles 12 to 22, 32 and 35 to 36. If a data subject contacts us directly about data you control, we will not answer for you — we will tell them to contact you, and tell you it happened.
10. If something goes wrong
If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay — meaning as soon as we have confirmed there is a breach, not once we have finished understanding it, and in time to be useful to you against your own deadline under Article 33(1). The notice will describe what we know: the nature of the breach, the categories and rough number of records involved, the likely consequences, what we have done and what we propose to do. If we do not yet know everything, we will send what we have rather than wait, and follow up.
Notifying your supervisory authority and, where required, your users, is your call to make as controller. We will give you what you need to make it.
11. Deletion and return
Message records and their delivery events are deleted automatically once they fall outside the history window on your plan — 14 days on the free plan. This is enforced by a job on our servers, not by request.
You can close your account yourself from the dashboard at any time. Doing so deletes the account and everything attached to it: your domains and their signing keys, your API keys and webhooks, every message record and its delivery history, and your suppression list. It happens immediately, with no grace period in which we could undo it.
Two honest exceptions. Encrypted backups roll off on their own short schedule, so deleted data survives in them until those expire. Operational and mail server logs age out on a rolling window measured in weeks. Neither is used for anything but running and restoring the service.
Before closing your account you can export what you need through the API. After it is closed there is nothing left for us to return.
12. Showing our work
We will make available to you the information needed to demonstrate compliance with Article 28, which for a service this size means answering your questions properly and in writing. Ask at privacy@misralo.com.
You may audit that compliance, or appoint an independent auditor to do so, on 30 days' written notice, no more than once in any 12 months, during business hours, and without unreasonable disruption to the service — except where a supervisory authority requires otherwise or a breach has occurred, in which case those limits do not apply. Audits are at your cost. We will not treat a reasonable request as an inconvenience.
13. Changes to this agreement
We may update this DPA to reflect changes in the service or in the law. For any change that materially affects your rights or our obligations we will give account holders at least 30 days' notice by email before it takes effect. The date at the top of this page always reflects the current version.
14. Contact
privacy@misralo.com reaches a person, for anything in this agreement — a countersigned copy, a sub-processor objection, an audit request, or a question you would rather ask before signing up.