Mail Guardian – Data Processing Agreement (DPA)

Mail Guardian — Data Processing Agreement

Revision: 12 September 2026
Contract based on the Danish Data Protection Agency's model agreement
For the purposes of Article 28(3) of Regulation 2016/679 (the GDPR)

between:

The Customer, as defined in the Mail Guardian terms of use (who is a data controller),
and
Safe Online ApS
Company registration number: 38589962
Nørrebrogade 47, 2200 København N
Denmark
(who is a data processor),
each a ‘party’; together as ‘the parties’.

HAVE AGREED on the following Contractual Clauses (the Clauses) in order to meet the requirements of the GDPR and protect the rights of the data subject.

Preamble

  1. These Contractual Clauses (the Clauses) set out the rights and obligations of the data controller and the data processor when processing personal data on behalf of the data controller.
  2. The Clauses have been designed to ensure the parties’ compliance with Article 28(3) of Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
  3. In the context of the provision of the Mail Guardian software, the data processor will process personal data on behalf of the data controller in accordance with the Clauses.
  4. The Clauses shall take priority over any similar provisions contained in other agreements between the parties.
  5. Three appendices are attached to the Clauses and form an integral part of the Clauses.
  6. Appendix A contains details about the processing of personal data, including the purpose and nature of the processing, type of personal data, categories of data subject and duration of the processing.
  7. Appendix B contains the data controller’s conditions for the data processor’s use of sub-processors and a list of sub-processors authorised by the data controller.
  8. Appendix C contains the data controller’s instructions regarding the processing of personal data, the minimum security measures to be implemented by the data processor, the retention and erasure arrangements applicable to data generated by the software, and how audits of the data processor and any sub-processors are to be performed.
  9. The Clauses along with appendices shall be retained in writing, including electronically, by both parties.
  10. The Clauses shall not exempt the data processor from obligations to which the data processor is subject pursuant to the GDPR or other legislation.

The rights and obligations of the data controller

  1. The data controller is responsible for ensuring that the processing of personal data takes place in compliance with the GDPR (see Article 24 GDPR), the applicable EU or Member State data protection provisions and the Clauses.
  2. The data controller has the right and obligation to make decisions about the purposes and means of the processing of personal data.
  3. The data controller shall be responsible, among other things, for ensuring that the processing of personal data which the data processor is instructed to perform has a legal basis.
  4. The data controller is responsible for informing its own personnel of the operation of the software in accordance with Articles 12 to 14 GDPR and any applicable national law or collective agreement governing control measures in employment relationships, before the software is deployed. Appendix C.5 sets out the information the data processor makes available to assist the data controller in doing so.

The data processor acts according to instructions

  1. The data processor shall process personal data only on documented instructions from the data controller, unless required to do so by Union or Member State law to which the processor is subject. Such instructions shall be specified in appendices A and C. Subsequent instructions can also be given by the data controller throughout the duration of the processing of personal data, but such instructions shall always be documented and kept in writing, including electronically, in connection with the Clauses.
  2. Configuration choices made by the data controller through the software’s administrative interface, where Appendix C expressly identifies them as instructions, constitute documented instructions for the purposes of sub-clause 1. The data processor records each such choice and its change history as set out in Appendix C.4 and makes that record available to the data controller.
  3. The data processor shall immediately inform the data controller if instructions given by the data controller, in the opinion of the data processor, contravene the GDPR or the applicable EU or Member State data protection provisions.

Confidentiality

  1. The data processor shall only grant access to the personal data being processed on behalf of the data controller to persons under the data processor’s authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only on a need-to-know basis. The list of persons to whom access has been granted shall be kept under periodic review. On the basis of this review, such access can be withdrawn where it is no longer necessary.
  2. The data processor shall at the request of the data controller demonstrate that the persons concerned are subject to the above-mentioned confidentiality.

Security of processing

  1. Article 32 GDPR stipulates that, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the data controller and data processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

The data controller shall evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. Depending on their relevance, the measures may include:

  1. pseudonymisation and encryption of personal data;
  2. the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  3. the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  4. a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
  1. According to Article 32 GDPR, the data processor shall also — independently of the data controller — evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. To this effect, the data controller shall provide the data processor with all information necessary to identify and evaluate such risks.
  2. Furthermore, the data processor shall assist the data controller in ensuring compliance with the data controller’s obligations pursuant to Article 32 GDPR by, inter alia, providing the data controller with information concerning the technical and organisational measures already implemented by the data processor, along with all other information necessary for the data controller to comply with its obligation under Article 32 GDPR.

If subsequently — in the assessment of the data controller — mitigation of the identified risks requires further measures to be implemented by the data processor than those already implemented, the data controller shall specify these additional measures in Appendix C.

Use of sub-processors

  1. The data processor shall meet the requirements specified in Article 28(2) and (4) GDPR in order to engage another processor (a sub-processor).
  2. The data processor shall therefore not engage another processor for the fulfilment of the Clauses without the prior general written authorisation of the data controller.
  3. The data processor has the data controller’s general authorisation for the engagement of sub-processors. The data processor shall inform the data controller in writing of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance, thereby giving the data controller the opportunity to object prior to the engagement of the sub-processor concerned. The list of sub-processors already authorised by the data controller can be found in Appendix B.
  4. Where the data processor engages a sub-processor for carrying out specific processing activities on behalf of the data controller, the same data protection obligations as set out in the Clauses shall be imposed on that sub-processor by way of a contract or other legal act under EU or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. The data processor shall be responsible for requiring that the sub-processor at least complies with the obligations to which the data processor is subject pursuant to the Clauses and the GDPR.
  5. A copy of such a sub-processor agreement and subsequent amendments shall — at the data controller’s request — be submitted to the data controller. Clauses on business-related issues that do not affect the legal data protection content of the sub-processor agreement shall not require submission.
  6. The data processor shall agree to a third-party beneficiary clause with the sub-processor whereby — in the event of bankruptcy of the data processor — the data controller shall be a third-party beneficiary to the sub-processor agreement and shall have the right to enforce it against the sub-processor, e.g. enabling the data controller to instruct the sub-processor to delete or return the personal data.
  7. If the sub-processor does not fulfil its data protection obligations, the data processor shall remain fully liable to the data controller as regards the fulfilment of the sub-processor’s obligations. This does not affect the rights of data subjects under the GDPR — in particular those foreseen in Articles 79 and 82 GDPR.

Transfer of data to third countries or international organisations

  1. Any transfer of personal data to third countries or international organisations by the data processor shall only occur on the basis of documented instructions from the data controller and shall always take place in compliance with Chapter V GDPR.
  2. In case transfers to third countries or international organisations which the data processor has not been instructed to perform by the data controller are required under EU or Member State law to which the data processor is subject, the data processor shall inform the data controller of that legal requirement prior to processing, unless that law prohibits such information on important grounds of public interest.
  3. Without documented instructions from the data controller, the data processor therefore cannot within the framework of the Clauses:
    1. transfer personal data to a data controller or a data processor in a third country or in an international organisation;
    2. transfer the processing of personal data to a sub-processor in a third country;
    3. have the personal data processed by the data processor in a third country.
  4. The Clauses shall not be confused with standard data protection clauses within the meaning of Article 46(2)(c) and (d) GDPR, and the Clauses cannot be relied upon by the parties as a transfer tool under Chapter V GDPR.

Assistance to the data controller

  1. Taking into account the nature of the processing, the data processor shall assist the data controller by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the data controller’s obligations to respond to requests for exercising the data subject’s rights laid down in Chapter III GDPR. This entails that the data processor shall, insofar as this is possible, assist the data controller’s compliance with:
    1. the right to be informed when collecting personal data from the data subject;
    2. the right to be informed when personal data have not been obtained from the data subject;
    3. the right of access by the data subject;
    4. the right to rectification;
    5. the right to erasure (‘the right to be forgotten’);
    6. the right to restriction of processing;
    7. the notification obligation regarding rectification or erasure of personal data or restriction of processing;
    8. the right to data portability;
    9. the right to object;
    10. the right not to be subject to a decision based solely on automated processing, including profiling.
  2. Where records held by the data processor have been de-identified in accordance with Appendix C.3, the data processor is no longer in a position to identify the data subject to whom such records relate. Article 11(2) GDPR applies to those records, and the data processor is not required to acquire additional information in order to identify a data subject for the purposes of sub-clause 1.
  3. In addition, the data processor shall, taking into account the nature of the processing and the information available to it, assist the data controller in ensuring compliance with:
    1. the data controller’s obligation to notify a personal data breach to the Danish Data Protection Agency without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons;
    2. the data controller’s obligation to communicate the personal data breach to the data subject without undue delay, where it is likely to result in a high risk to the rights and freedoms of natural persons;
    3. the data controller’s obligation to carry out a data protection impact assessment;
    4. the data controller’s obligation to consult the Danish Data Protection Agency prior to processing where a data protection impact assessment indicates a high risk in the absence of mitigating measures.
  4. The parties have defined in Appendix C the appropriate technical and organisational measures by which the data processor is required to assist the data controller, as well as the scope and extent of the assistance required.

Notification of personal data breach

  1. In case of any personal data breach, the data processor shall, without undue delay after having become aware of it, notify the data controller of the personal data breach.
  2. The data processor’s notification to the data controller shall, if possible, take place within 48 hours after the data processor has become aware of the personal data breach, to enable the data controller to comply with its obligation to notify the competent supervisory authority under Article 33 GDPR.
  3. In accordance with the assistance clause above, the data processor shall assist the data controller in obtaining the information which, pursuant to Article 33(3) GDPR, shall be stated in the data controller’s notification:
    1. the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
    2. the likely consequences of the personal data breach;
    3. the measures taken or proposed to be taken to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
  4. The parties have defined in Appendix C the elements to be provided by the data processor when assisting the data controller in the notification of a personal data breach.

Erasure and return of data

  1. On termination of the provision of personal data processing services, the data processor shall be under obligation to delete all personal data processed on behalf of the data controller and certify to the data controller that it has done so, unless Union or Member State law requires storage of the personal data.
  2. Deletion under sub-clause 1 shall take place within 30 days of termination and applies irrespective of any retention period specified in Appendix C.3 that has not yet expired.

Audit and inspection

  1. The data processor shall make available to the data controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 and the Clauses, and allow for and contribute to audits, including inspections, conducted by the data controller or another auditor mandated by the data controller.
  2. The data processor shall be required to provide the supervisory authorities which, pursuant to applicable legislation, have access to the data controller’s and data processor’s facilities, or representatives acting on behalf of such supervisory authorities, with access to the data processor’s physical facilities on presentation of appropriate identification.

The parties’ agreement on other terms

  1. The parties may agree other clauses concerning the provision of the personal data processing service specifying e.g. liability, as long as they do not contradict directly or indirectly the Clauses or prejudice the fundamental rights or freedoms of the data subject and the protection afforded by the GDPR.

Commencement and termination

  1. The Clauses shall become effective on the date on which the data controller accepts the Mail Guardian terms of use, and apply to all processing of personal data carried out by the data processor on the data controller’s behalf from that date. No separate signature is required for the Clauses to bind the parties.
  2. Both parties shall be entitled to require the Clauses renegotiated if changes to the law or inexpediency of the Clauses should give rise to such renegotiation.
  3. The Clauses shall apply for the duration of the provision of personal data processing services. For that duration, the Clauses cannot be terminated unless other Clauses governing the provision of personal data processing services have been agreed between the parties.
  4. If the provision of personal data processing services is terminated, and the personal data is deleted or returned to the data controller pursuant to the erasure clause, the Clauses may be terminated by written notice by either party.
  5. The data processor may issue revised versions of these Clauses and their appendices. The data processor shall notify the data controller at least 30 days before a revision takes effect where the revision changes the purposes of processing, the categories of personal data, the retention arrangements in Appendix C.3, or the security measures in Appendix C.2. The data controller may object within that period, in which case the parties shall negotiate in good faith; absent agreement, either party may terminate the affected services.

Data controller and data processor contacts / contact points

  1. The parties may contact each other using the contact points stated in the offer made by the data processor to the data controller, and at privacy@safeonline.dk.

Appendix A — Information about the processing

A.1 The purpose of the data processor’s processing of personal data on behalf of the data controller

The data processor provides the data controller with Mail Guardian, a Microsoft Outlook add-in which, at the moment a user of the data controller sends an outgoing email message:

  1. analyses the message body and, where enabled, attachments in order to detect Danish personal identification numbers (CPR-numre) and other categories of personal identifier;
  2. where such data is detected, displays a warning to the sending user before the message is sent; and
  3. records that a warning was displayed, together with the category of each detection and a masked display string, for the purpose of enabling the data controller to measure and report on the incidence of such warnings within its own compliance assurance and audit activities; and
  4. where a message was sent without having been scanned, records the reason and the number of unscanned parts, so that the data controller can establish whether and where its users were unprotected.

The record described in (c) evidences that a warning was displayed. It does not record, and the data processor does not receive, any indication of what the sending user did in response to the warning.

Where a user of the data controller submits feedback on a detection, or acknowledges a specific finding in the software’s task pane, the data processor records that act for the purpose of improving detection accuracy for the data controller.

The data processor does not use personal data processed under these Clauses to develop, train or evaluate detection models for the benefit of any other customer, or for any purpose relating to an individual user, except on the data controller’s documented instruction.

A.2 The nature of the processing

The processing is of two distinct kinds, and the distinction is material to every other part of this Appendix.

(i) Transient processing. The content of an outgoing message is transmitted to the data processor’s service, analysed in memory, and discarded when the response is returned. Message content is not written to persistent storage, and is not written to application logs. The data processor does not retain the message, its recipients, its subject line, its attachments or their filenames.

(ii) Persistent processing. Records are written which describe the outcome of that analysis: which categories were detected, a masked display string for each detection, the team, an internal identifier of the user, and the time. The construction of these records is set out in C.1.

A.3 Types of personal data

(A) Users of the software (the data controller’s personnel): an internal user identifier assigned by the data processor, the user’s team membership, and the identity data necessary to authenticate the user against the data controller’s Microsoft Entra tenant.

(B) Persons whose personal data appears in an outgoing message:

Transiently, during analysis (A.2(i)): any personal data present in the message, which may include name, contact details, Danish personal identification number (CPR), payment card and bank account details, and data falling within Article 9 GDPR such as health information — depending entirely on what the data controller’s user has written.

Persistently, in the records described in A.2(ii): a category label identifying the type of data detected, and a masked display string in which the detected identifier is replaced by typed placeholders. No unmasked identifier is written to persistent storage. No surrounding message text is retained in the warning record.

A.4 Categories of data subject

(A) Users of the software services — the data controller’s personnel.

(B) Any natural person whose personal data appears in a message sent by a user of the software. This category is not limited to the data controller’s personnel and will typically include the data controller’s own customers, clients, patients, counterparties and other third parties.

A.5 Duration of the processing

Processing may be performed when the Clauses commence and continues for as long as the data controller is a customer for the software. The retention applicable to individual records is set out in C.3.

Appendix B — Authorised sub-processors

B.1 Approved sub-processors

On commencement of the Clauses, the data controller authorises the engagement of the following sub-processors:

Sub-processor Legal entity Purpose Location of processing
Supabase Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 Hosting of the application database and serverless functions; application logging; storage of the records described in A.2(ii) European Union — Amazon Web Services region eu-north-1, Stockholm, Sweden

No provider of artificial intelligence, machine learning or text-analysis services processes message content under these Clauses. Detection is performed by the data processor’s own software executing within the environment identified above. Message content is not transmitted to any third party.

No further sub-processor is engaged. Application logging is performed within the sub-processor’s platform identified above and is not sent to any separate logging or monitoring provider.

Storage of the data controller’s personal data takes place in the region stated above. Supabase Pte. Ltd is established in Singapore, in respect of which the European Commission has not issued an adequacy decision. Where personnel of the sub-processor access the hosting environment from outside the European Economic Area for support or operational purposes, that access constitutes a transfer to a third country. Such transfers are made subject to the module two and module three standard contractual clauses incorporated in the Supabase Data Processing Addendum (Version 1, 1 August 2026), and the data processor shall provide that documentation to the data controller on request. See Appendix C.6.

The data processor shall not be entitled — without the data controller’s explicit written authorisation — to engage a sub-processor for a different processing than the one agreed, or to have another sub-processor perform the described processing.

B.2 Microsoft services

The software authenticates users against the data controller’s own Microsoft Entra tenant and operates within the data controller’s own Microsoft 365 environment. In respect of that environment, Microsoft is a processor engaged by the data controller under the data controller’s own agreement with Microsoft, and is not a sub-processor of the data processor. The data processor’s service validates identity tokens issued by Microsoft identity endpoints; no personal data of the data controller is disclosed to Microsoft by the data processor in doing so.

Appendix C — Instructions pertaining to the use of personal data

C.1 How the persistent records are constructed

The data controller instructs the data processor to construct the records described in A.2(ii) as follows. These constraints are enforced by the software and form part of the security measures relied on in C.2.

  1. Identity is derived, never accepted. The user identifier and team are resolved by the data processor’s service from the caller’s validated authentication token and the user’s own record. A client cannot assert another user’s identity or another team.
  2. No message metadata is stored. Recipients, subject line, message identifier and attachment filenames are rejected by the service’s input validation and are never written, irrespective of what a client transmits.
  3. No free-text field exists. The software provides no facility for a user to record a narrative justification, and no such field is stored.
  4. Detected identifiers are masked. Persistent records contain a category label and a masked display string only.
  5. No surrounding message text is retained in the record of a warning having been displayed.
  6. Content is excluded from logs. Application log entries record failure classes and codes only.

C.2 Security of processing

The level of security shall take into account:

  1. The data processor shall take all measures required pursuant to Article 32 GDPR.
  2. That obligation means the data processor shall perform a risk assessment and thereafter implement measures to counter the identified risk.
  3. That the software is designed to detect personal data which includes data subject to Article 9 GDPR and Danish personal identification numbers, and that it operates on communications of the data controller’s personnel — for which reason a high level of security is established, and for which reason the design constraints in C.1 restrict what may be retained at all.

The data processor applies the following measures:

  1. Encryption of personal data in transit using TLS 1.2 or above.
  2. Encryption of personal data at rest using AES-256 (or the equivalent applied by the sub-processor identified in Appendix B).
  3. Pseudonymisation as a design principle, not an exception: detected identifiers are replaced by typed placeholders before storage; feedback records are keyed by a salted hash which does not embed the detected value; user identifiers in warning records are removed entirely after the period in C.3.
  4. Row-level access control scoping every record to the team that generated it, enforced in the database rather than in application code alone.
  5. Authentication of every request that writes a record, with identity derived server-side as set out in C.1(a).
  6. Restriction of access to production data to named personnel under confidentiality obligations, on a need-to-know basis, subject to periodic review.
  7. The ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services.
  8. The ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
  9. A process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures.
  10. Logging of access to and changes in administrative configuration, including the retention settings described in C.4.

All employees of the data processor are subject to confidentiality obligations during and after their employment, and to ongoing review and training.

C.3 Storage period and erasure procedures

Records are retained as follows:

Record Stage Timing Effect
Warning displayed De-identification After the configured de-identification interval (default 90 days) The internal user identifier is permanently and irreversibly removed, and the time of the event is reduced to date precision.
Warning displayed Deletion After the configured deletion interval (default 365 days) The record is permanently deleted.
Coverage of an unscanned send De-identification 90 days The internal user identifier is permanently and irreversibly removed, and the time of the event is reduced to date precision.
Coverage of an unscanned send Deletion 365 days The record is permanently deleted.
Detection feedback Deletion 90 days The record is permanently deleted. Not configurable.
Finding acknowledgement Deletion 90 days The record is permanently deleted. Not configurable.
Diagnostic records Deletion 7 days; 30 days for sign-in failure signals The record is permanently deleted. These records carry no user identifier and no team identifier.

C.3.1 No personal data attributable to an identified or identifiable individual user of the data controller is retained by the data processor for longer than 90 days, or such shorter period as the data controller configures. This applies to every record described in this Appendix without exception. Retention beyond that period applies only to the de-identified record.

C.3.2 The differing periods are intentional. They reflect the application of the data minimisation principle to records serving different purposes, and are not an inconsistency.

C.3.3 Transient processing. Message content processed under A.2(i) is not retained at all and is therefore not subject to a retention period.

C.3.4 Execution and evidence. De-identification and deletion are effected by automated scheduled processes. The data processor retains evidence of each execution, including the time, the operation performed and the number of records affected, and shall make it available to the data controller on request and to the data controller’s auditor under the audit clause.

C.3.5 Backups. Removal from the live data store does not immediately affect encrypted backups. Backups are taken daily and the seven most recent are retained, after which the data is irretrievably deleted. During that period backups are not accessible for operational use and are restored only in a disaster recovery event. The parties acknowledge that a restore from a backup taken before de-identification would restore the user identifier, and the data processor shall re-apply C.3 to any restored data without undue delay.

C.3.6 Records predating these Clauses. Records created before these Clauses take effect in respect of the data controller remain subject to the retention period applicable when they were created and are deleted accordingly.

C.3.7 Termination. The periods in this section do not extend the data processor’s obligation under the erasure clause to delete all personal data on termination.

C.4 Retention configuration as a documented instruction

  1. The data controller may configure the de-identification and deletion intervals for warning records through the software’s administrative interface, within the ranges 30–90 and 90–365 days respectively. Those maxima are set by the data processor. Where the data controller makes no selection, the defaults in C.3 apply.
  2. A configuration change made by the data controller under sub-clause 1 constitutes a documented instruction within the meaning of the instruction clause. The data processor records the values before and after the change, the time of the change and the user of the data controller who made it, retains that record in connection with these Clauses, and makes it available to the data controller.
  3. Where the data controller reduces an interval, the reduced interval applies to all records then held. Increasing an interval does not restore records already de-identified or deleted, and does not apply to records created before the change.
  4. The data processor shall not configure or alter these intervals on the data controller’s behalf except on the data controller’s documented instruction, and any change so made is recorded under sub-clause 2 and is visible to the data controller.
  5. The data controller may record in the software the legal basis on which it relies for the retention it has configured. Where recorded, the data processor retains that statement with the configuration history.

C.5 Assistance with information to data subjects and with impact assessments

  1. The data processor makes available to the data controller a description of the processing sufficient for the data controller to prepare the information required by Articles 13 and 14 GDPR, including model text in Danish and English describing what the software records, what it does not record, and the retention applicable.
  2. The data processor makes available to the data controller a description of the processing, the categories of data, the recipients, the retention arrangements and the security measures, sufficient for the data controller to carry out a data protection impact assessment under Article 35 GDPR. The data protection impact assessment is the data controller’s to perform; the data processor’s role is to supply accurate material for it.
  3. The data processor shall inform the data controller of any change to the software which materially alters what is recorded or for how long, in advance of that change taking effect, so that the data controller may update its own information and assessments.

C.6 Instruction on the transfer of personal data to third countries

  1. The data controller instructs the data processor to engage the sub-processor identified in Appendix B.1 notwithstanding that it is established in a third country, on the basis of the standard contractual clauses referred to in that Appendix. This constitutes the data controller’s documented instruction for the purposes of the clause on transfer of data to third countries.
  2. Save as set out in sub-clause 1, where the data controller has not in these Clauses or subsequently provided documented instructions pertaining to the transfer of personal data to a third country, the data processor shall not be entitled to perform such transfer.

C.7 Procedures for the data controller’s audits and inspections

The data controller or the data controller’s representative may perform an inspection of the places where the processing of personal data is carried out by the data processor, including physical facilities as well as systems used for and related to the processing, to ascertain the data processor’s compliance with the GDPR, the applicable EU or Member State data protection provisions and these Clauses. The data controller may perform an inspection when it deems it required.

The data processor’s costs, if applicable, relating to inspections shall be covered by the data controller. The data processor shall, however, be under obligation to set aside the resources (mainly time) required for the data controller to perform the inspection.

In addition, and without an inspection being required, the data processor shall on request provide the data controller with the deletion execution evidence described in C.3.4 and the configuration history described in C.4.2.

Acceptance and record of the Clauses

  1. These Clauses form part of the Mail Guardian terms of use. The data controller accepts them by accepting those terms, and they bind the parties from that date without separate signature.
  2. The current revision of the Clauses, including all three appendices, is published by the data processor at https://helpcenter.bysafeonline.com/article/[id]-mailguardian-dpa and carries the revision date shown on the first page. The data processor maintains the superseded revisions and makes any of them available to the data controller on request.
  3. The data processor records, for each data controller, the revision of the Clauses in force and the date from which it applied. That record, together with the configuration history described in Appendix C.4.2, constitutes the parties’ record of the Clauses and of instructions given under them, retained in writing and electronically as required by the Preamble.
  4. Where the data controller requires a counterpart executed by signature, the data processor will provide the Clauses in that form on request. The text is identical; the executed counterpart records the same Clauses and does not vary them.

Still need help? Contact Us Contact Us