Data Processing Addendum

Version 1.0 · July 15, 2026

This addendum is a review copy for customers that use Elite Email Tracker to process personal data. It becomes binding only when incorporated into an executed customer agreement identifying the legal entities, addresses, governing law, and signatures.

Scope and instructions

The customer is controller/business and Elite Email Tracker is processor/service provider for tracked-message metadata and engagement events processed to provide the service. We process only documented customer instructions, including configured tracking, analytics, permissions, retention, exports, and deletion, unless law requires otherwise.

Confidentiality and security

Authorized personnel are bound to confidentiality. Technical measures include TLS, least-privilege service accounts, hashed credentials, role-based access, audit logging, rate limiting, backups, vulnerability management, and tenant-scoped APIs. See Security.

Subprocessors and transfers

We may use listed subprocessors under written data-protection terms and remain responsible for their processing. Customers receive notice of material changes and may object on reasonable data-protection grounds. Restricted transfers use applicable safeguards, including the 2021 EU Standard Contractual Clauses where appropriate. See Subprocessors.

Rights, incidents, return and deletion

We assist with verified data-subject requests, security assessments, breach obligations, and legally required consultations, considering the nature of processing. We notify customers without undue delay after confirming a personal-data breach. At termination we return or delete customer data subject to legal retention and expiring backups.

Audit

We provide information reasonably necessary to demonstrate compliance and support proportionate audits under confidentiality, no more than annually unless an incident or regulator requires otherwise. Contact support to obtain and execute the entity-complete DPA and applicable transfer schedules.