Data Protection Agreement

Structural commitments ensuring uncompromising compliance with global data sovereignty frameworks and regional protection regulations.

Last Updated: June 10, 2026

01. Applicability & Scope

This Data Protection Agreement (DPA) forms an integral addendum to the Mailstine Terms of Use. It applies structurally to the processing of personal data on behalf of our clients (Platform Operators) utilizing Mailstine's infrastructure to distribute automated communications and manage subscriber architectures.

02. Structural Roles of the Parties

For the purpose of global and regional privacy frameworks (including NDPA, GDPR, and CCPA), the operational roles are strictly delineated:

The Client (Data Controller)

You determine the purposes and structural means of processing. You control the acquisition, scope, and categorical nature of the subscriber data uploaded into our clusters.

Mailstine (Data Processor)

We provide the architectural engines required to execute your distribution commands. We process subscriber arrays exclusively on your behalf and at your explicit directive.

03. Documented Processing Directives

Mailstine shall process Personal Data solely in accordance with documented instructions from the Client. The execution of a campaign distribution via our dashboard interface or API constitutes a documented instruction. We will immediately notify the Client if, in our engineering assessment, an instruction violates regional data protection laws.

04. Sub-Processor Pipelines

To maintain high-availability infrastructure, Mailstine engages specialized third-party sub-processors (e.g., localized cloud hosting providers, transactional SMTP relays).

  • Authorization: The Client grants Mailstine general authorization to utilize infrastructural sub-processors bound by equally stringent data protection obligations.
  • Notification: Mailstine will provide structural notice of any intended changes concerning the addition or replacement of core sub-processors via our technical dashboard updates.

05. Security Architecture (TOMs)

Mailstine commits to implementing and maintaining Technical and Organizational Measures (TOMs) to secure data arrays against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure.

Cryptographic Safeguards

Utilization of high-grade AES-256 encryption for data at rest and strict enforcement of TLS 1.2/1.3 for all structural data in transit across network boundaries.

Logical Isolation

Tenant data is logically segmented within database clusters to ensure absolute isolation between distinct organizational deployments.

06. Breach Notification Protocols

In the event of a confirmed structural data breach compromising Client subscriber matrices, Mailstine will notify the Client without undue delay (and strictly within 48 hours of positive engineering verification). We will provide comprehensive technical logs detailing the nature of the breach, mitigation vectors deployed, and affected database partitions to assist the Client in meeting their regulatory reporting obligations.

07. Data Localization & Sovereignty

NDPA Framework Alignment

Mailstine is architected to prioritize local data sovereignty. For businesses operating within the region, infrastructure routing ensures compliance with the Nigeria Data Protection Act (NDPA). Any required cross-border data transfers necessary for international email delivery are conducted under legally recognized transfer mechanisms and standard contractual clauses.

08. Data Protection Officer (DPO)

For inquiries regarding this agreement, structural security audits, or specific data processing obligations, clients may contact our dedicated Data Protection pipeline.

Privacy Engineering Desk

Direct access to our infrastructure compliance team.

[email protected]