Saltar al contenido

MailerLite Classic cerró registros y cuentas gratuitas. TinyCourier toma el relevo. Ver la guía de migración

Legal

Data Processing Agreement

This Data Processing Agreement (“DPA”) governs how TinyCourier processes personal data on your behalf when you use the service. It forms part of, and is incorporated into, our Terms of Service. It applies where you (the “Customer”) are a controller and we are your processor — principally for the subscriber lists and campaign content you upload. By using the service you agree to this DPA on behalf of the controller you represent; no signature is required, but a counter-signed copy is available on request.

Effective:
27 June 2026
Last updated:
27 June 2026

1. Parties and roles

This DPA is between Regula Rothen, trading as TinyCourier (“TinyCourier”, “we”, “processor”), a sole proprietor based in Bern, Switzerland, and you, the Customer (the “controller”). For personal data contained in your subscriber lists and campaigns, you determine the purposes and means of processing and are the controller; we process that data only on your behalf as your processor.

2. Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). “Customer Personal Data” means personal data we process on your behalf under this DPA, as described in Annex 1. “Sub-processor” means a third party engaged by us to process Customer Personal Data.

3. Scope of processing

We process Customer Personal Data only to provide and support the service, and only on your documented instructions, which include this DPA, the Terms of Service, and your use of the product's features. We will inform you if, in our opinion, an instruction infringes the GDPR, the FADP, or other applicable data protection law. The subject matter, duration, nature, purpose, types of data, and categories of data subjects are set out in Annex 1.

We will not sell Customer Personal Data, use it for our own purposes, or disclose it to third parties except as permitted by this DPA or required by law. We do not use Customer Personal Data to train artificial-intelligence models.

4. Our obligations as processor

  • Confidentiality: we ensure that people authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality.
  • Security: we implement appropriate technical and organizational measures as described in Annex 2, taking into account the state of the art and the risks of the processing.
  • Assistance: taking into account the nature of the processing, we assist you by appropriate measures in fulfilling your obligations to respond to data subject requests (Section 7), and in ensuring security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36 GDPR).
  • Records: we maintain records of the processing we carry out on your behalf.

5. Sub-processors

You give us general authorization to engage sub-processors. Our current sub-processors are listed in Annex 3 and at tinycourier.com/subprocessors. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.

We will give you reasonable notice (at least 30 days where practicable) before adding or replacing a sub-processor that processes Customer Personal Data. If you object on reasonable data-protection grounds, we will work with you in good faith to find a solution; if none is found, you may terminate the affected part of the service.

6. International transfers

We host Customer Personal Data in Switzerland and the EU. Where a sub-processor processes Customer Personal Data in a country that Switzerland or the EU has not recognized as adequate, we ensure an appropriate transfer mechanism is in place — principally the European Commission's Standard Contractual Clauses together with the Swiss FDPIC addendum, and, where applicable, certification under the EU–US and Swiss–US Data Privacy Framework. The Standard Contractual Clauses are incorporated into this DPA by reference and prevail in the event of a conflict regarding restricted transfers.

7. Data subject requests

If we receive a request from a data subject relating to Customer Personal Data, we will not respond directly (except to confirm the request relates to you) and will, without undue delay, forward it to you. Taking into account the nature of the processing, we will provide reasonable assistance, including through features of the product, to help you respond to such requests.

8. Personal data breaches

We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, its likely consequences, and the measures taken or proposed. We will cooperate with you and take reasonable steps to mitigate the breach.

9. Audits

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 GDPR. To keep disruption proportionate for a small provider, audits are normally satisfied by our responses to a reasonable written security questionnaire no more than once per year. An on-site audit may be conducted where required by a supervisory authority or by applicable law, on reasonable prior notice, during business hours, and subject to confidentiality.

10. Return and deletion

On termination of the service, or at your request, we will delete Customer Personal Data from our active systems within 30 days, and from routine backups as those backups expire, unless applicable law requires us to retain it. On request before deletion, we will help you export your data in a commonly used format.

11. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. In the event of a conflict, this DPA prevails over the Terms of Service with respect to the processing of Customer Personal Data, and the Standard Contractual Clauses prevail over this DPA with respect to restricted transfers.

12. Governing law

This DPA is governed by the laws of Switzerland, and the courts of Bern, Switzerland have exclusive jurisdiction, without prejudice to any mandatory jurisdiction or transfer-mechanism rules that apply under the GDPR or the Standard Contractual Clauses.

Annex 1 — Details of processing

  • Subject matter: provision of the TinyCourier email newsletter service.
  • Duration: for as long as the Customer uses the service, plus the retention periods in Section 10.
  • Nature and purpose: storing and managing subscriber lists; sending campaigns and transactional email; tracking deliveries, opens, and clicks; providing related features and support.
  • Types of personal data: subscriber email addresses, names, and any custom fields the Customer chooses to store; sign-up source and date; engagement data (opens, clicks, bounces, unsubscribes); campaign content.
  • Categories of data subjects: the Customer's subscribers and contacts.

Annex 2 — Security measures

We maintain technical and organizational measures appropriate to the risk, including:

  • Encryption in transit: data is encrypted in transit using current TLS.
  • Encryption at rest: data is encrypted at rest where supported by our infrastructure providers.
  • Authentication: user passwords are stored only as salted one-way hashes.
  • Access control: access to production systems and Customer Personal Data is restricted to authorized personnel on a need-to-know basis and protected by strong authentication.
  • Backups: regular backups are maintained and protected.
  • Resilience and monitoring: systems are monitored for errors and security events, and we take measures to restore availability after an incident.
  • Sub-processor diligence: sub-processors are bound by contractual data protection obligations no less protective than this DPA.

We may update these measures over time provided the level of protection is not materially reduced.

Annex 3 — Sub-processors

The following sub-processors are authorized as of 27 June 2026:

Provider Purpose Location
Hetzner Online GmbH Application hosting, databases, backups Finland
Oracle Corporation Campaigns and double opt-in email delivery Zurich, Switzerland
Stripe, Inc. / Stripe Payments Europe Subscription billing and payment processing Ireland & United States
Functional Software, Inc. Application error and crash monitoring European Union
Hiver, Inc. Customer support tooling United States
Google LLC Sign-in with Google (OAuth) authentication United States
Plus Five Five, Inc. Transactional email for TinyCourier system notifications Ireland

The current list is always available at tinycourier.com/subprocessors.