Data Processing Addendum
Last updated: 10 August 2026
This Addendum forms part of the Penomaly Terms of Service between you ("the Customer") and Penomaly. It applies whenever Penomaly processes personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland on the Customer's behalf.
Where this Addendum and the Terms of Service conflict on data protection, this Addendum wins.
1. Roles
The Customer is the controller. Penomaly is the processor.
The Customer decides why and how their subscribers' personal data is processed. Penomaly processes it only on the Customer's documented instructions.
Separately, Penomaly is a controller of the Customer's own account data, which is covered by the Privacy Policy rather than this Addendum.
The Customer confirms it has a lawful basis for the data it puts into Penomaly, and that its own privacy notice tells subscribers their data is processed by a service provider.
2. What is processed
Subject matter: provision of the Penomaly email marketing platform.
Duration: for as long as the Customer's account is open, plus the retention periods in section 8.
Nature and purpose: storing subscriber records, sending email on the Customer's instruction, recording delivery, opens, clicks, bounces, complaints and unsubscribes, maintaining suppression and consent records, and providing reporting.
Categories of data subject: the Customer's newsletter subscribers, ARC readers, and newsletter swap partners.
Categories of personal data:
- Email address
- Name, where the Customer collects it
- Tags and custom fields the Customer chooses to store
- Signup source, date, and IP address where captured, as consent evidence
- Engagement data: opens, clicks, bounces, complaints, unsubscribes
- Suppression status and its reason
Special category data: Penomaly is not designed for special category data as Article 9 defines it, and the Customer should not upload it. If the Customer does, they remain responsible for the additional lawful basis it requires.
3. Penomaly's obligations
Penomaly will:
- Process personal data only on the Customer's documented instructions, including for international transfers, unless required otherwise by law, in which case Penomaly will inform the Customer first unless that law forbids it
- Ensure that everyone authorised to process the data is bound by an appropriate duty of confidentiality
- Implement the technical and organisational measures in Annex A
- Respect the conditions in section 5 for engaging a sub-processor
- Assist the Customer, so far as is reasonably possible, in responding to requests from data subjects exercising their rights
- Assist the Customer with data protection impact assessments and with prior consultation of a supervisory authority, taking into account the nature of processing and the information available to Penomaly
- Delete or return personal data at the end of the service, per section 8
- Make available the information reasonably needed to demonstrate compliance with Article 28, and allow for audits per section 9
4. Security
Penomaly maintains the measures set out in Annex A and will not materially reduce them during the term.
Personal data breach. Penomaly will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer's data, and will provide the information the Customer needs to meet its own notification obligations, including the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken.
5. Sub-processors
The Customer gives general authorisation for Penomaly to engage sub-processors, subject to the conditions below.
Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway Corp. | Application hosting and database | United States |
| Clerk Inc. | Authentication and user management | United States |
| Amazon Web Services, Inc. | Email delivery, object storage | United States |
| Stripe, Inc. | Payment processing | United States |
| Cloudflare, Inc. | CDN, DNS and denial of service protection | Global |
| Anthropic PBC | Optional AI features the Customer chooses to use | United States |
Penomaly will:
- Impose data protection obligations on each sub-processor no less protective than those in this Addendum
- Remain fully liable to the Customer for a sub-processor's performance
- Give the Customer at least 30 days notice before adding or replacing a sub-processor, by email to the account's registered address
If the Customer reasonably objects on data protection grounds within that period, the parties will discuss it in good faith. If it cannot be resolved, the Customer may terminate the affected part of the service without penalty and receive a pro rata refund of prepaid fees.
6. International transfers
Penomaly's infrastructure is in the United States. Personal data will be transferred there.
For transfers from the EEA, Penomaly relies on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, controller to processor, which are incorporated into this Addendum by reference. For the purposes of Annex I and II of those Clauses, the details in sections 2 and 5 and Annex A apply. The governing law is Ireland and the competent supervisory authority is the Irish Data Protection Commission unless the Customer's own lead authority applies.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with the UK Information Commissioner as the competent authority.
For transfers from Switzerland, references to the GDPR are read as references to the Swiss FADP and the competent authority is the Swiss FDPIC.
7. Data subject requests
If Penomaly receives a request directly from one of the Customer's subscribers, Penomaly will not respond to it substantively. It will forward the request to the Customer without undue delay and let the individual know it has done so.
Penomaly provides tools within the product for the Customer to access, export, correct and delete subscriber records without needing to contact us.
8. Deletion and return
On termination, the Customer may export their data at any point during the 90 day period that follows. After that, Penomaly deletes personal data from production systems within 30 days, and from backups within a further 90 days as backups rotate.
One deliberate exception: suppression records survive deletion. These record only that a given email address unsubscribed, complained, or hard bounced, and the reason. Retaining them is necessary so that a later import cannot re-subscribe someone who asked not to be contacted. Penomaly relies on legitimate interests and on the Customer's own compliance obligations for this retention. No content, tags or engagement history is retained with them.
9. Audits
Penomaly will make available the information reasonably necessary to demonstrate compliance with Article 28.
Where the Customer reasonably requires more, an audit may be carried out once in any 12 month period, on at least 30 days written notice, during business hours, without unreasonable disruption, and subject to confidentiality. The Customer bears its own costs. Penomaly may satisfy an audit request by providing a recent third party report where one is available.
10. Liability
Liability under this Addendum is subject to the limitations in the Terms of Service, except where that is not permitted by applicable data protection law.
Annex A: Technical and organisational measures
Encryption. TLS 1.2 or higher for all data in transit. Data at rest is encrypted by the underlying infrastructure providers.
Network isolation. The production database is reachable only over a private network and is not exposed to the public internet.
Access control. Access to production systems is restricted to personnel who need it, protected by multi-factor authentication, and reviewed periodically.
Payment data. Full card numbers are never transmitted to or stored on Penomaly systems. Payment credentials are handled by a PCI DSS compliant processor. Penomaly stores only a token and a one-way hash used for abuse prevention.
Separation. Every query against customer-owned data is scoped by account identifier, so one customer's records cannot be returned to another.
Logging. Access and security events are logged and retained for 12 months.
Backups. Databases are backed up automatically, encrypted, and rotated.
Resilience. Infrastructure providers maintain redundancy and disaster recovery appropriate to the service.
Personnel. All personnel with access are bound by confidentiality obligations that survive the end of their engagement.
Contact
Data protection enquiries: privacy@penomaly.com
Penomaly P.O. Box 94 Poteet, TX 78065 United States