Structural commitments ensuring uncompromising compliance with global data sovereignty frameworks and regional protection regulations.
This Data Protection Agreement (DPA) forms an integral addendum to the Mailstine Terms of Use. It applies structurally to the processing of personal data on behalf of our clients (Platform Operators) utilizing Mailstine's infrastructure to distribute automated communications and manage subscriber architectures.
For the purpose of global and regional privacy frameworks (including NDPA, GDPR, and CCPA), the operational roles are strictly delineated:
You determine the purposes and structural means of processing. You control the acquisition, scope, and categorical nature of the subscriber data uploaded into our clusters.
We provide the architectural engines required to execute your distribution commands. We process subscriber arrays exclusively on your behalf and at your explicit directive.
Mailstine shall process Personal Data solely in accordance with documented instructions from the Client. The execution of a campaign distribution via our dashboard interface or API constitutes a documented instruction. We will immediately notify the Client if, in our engineering assessment, an instruction violates regional data protection laws.
To maintain high-availability infrastructure, Mailstine engages specialized third-party sub-processors (e.g., localized cloud hosting providers, transactional SMTP relays).
Mailstine commits to implementing and maintaining Technical and Organizational Measures (TOMs) to secure data arrays against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure.
Utilization of high-grade AES-256 encryption for data at rest and strict enforcement of TLS 1.2/1.3 for all structural data in transit across network boundaries.
Tenant data is logically segmented within database clusters to ensure absolute isolation between distinct organizational deployments.
In the event of a confirmed structural data breach compromising Client subscriber matrices, Mailstine will notify the Client without undue delay (and strictly within 48 hours of positive engineering verification). We will provide comprehensive technical logs detailing the nature of the breach, mitigation vectors deployed, and affected database partitions to assist the Client in meeting their regulatory reporting obligations.
Mailstine is architected to prioritize local data sovereignty. For businesses operating within the region, infrastructure routing ensures compliance with the Nigeria Data Protection Act (NDPA). Any required cross-border data transfers necessary for international email delivery are conducted under legally recognized transfer mechanisms and standard contractual clauses.
For inquiries regarding this agreement, structural security audits, or specific data processing obligations, clients may contact our dedicated Data Protection pipeline.
Direct access to our infrastructure compliance team.