When you use MailBlue’s services, you process Personal Data relating to you and your contacts. Personal Data means data providing information about a natural person by which you can directly or indirectly establish that person’s identity. This means that the information is either directly about someone or can be traced back to that person. Examples of Personal Data include names, email addresses, telephone numbers and address details.
If you engage another organisation to process Personal Data on your behalf, the General Data Protection Regulation (GDPR) requires you to conclude a Data Processing Agreement with that organisation. Because you use MailBlue’s services, MailBlue is the Processor and you are designated as the Controller. In this Data Processing Agreement, we set out our arrangements concerning the processing of the Personal Data.
To make this Data Processing Agreement easier to read, we would first like to properly explain the most important terms to you:
Processor:
The person or organisation that processes Personal Data on behalf of the Controller, for example via a web application. In this Data Processing Agreement, MailBlue B.V., with its registered office at Akkerstraat 227, 4811 JL Breda, the Netherlands, and registered in the Commercial Register of the Dutch Chamber of Commerce under number 68740077, is the Processor.
Controller:
The (legal) person or organisation that determines whether Personal Data may be processed and, if so, which Personal Data, for what purpose that Personal Data may be processed, what that processing entails precisely, and which means may be used in doing so. In this Data Processing Agreement, you are the Controller.
Data Subject:
The person to whom the Personal Data relates. For example, your customer or supplier.
Processing of Personal Data:
Anything that can be done with Personal Data, such as:
Data Breach:
A security incident in which Personal Data is accidentally or unlawfully destroyed, lost, altered, disclosed without authorisation or accessed without authorisation, and where it can reasonably be assumed that this leads to a risk to the rights and freedoms of the persons concerned.
The subject matter of the processing:
The provision of services by MailBlue.
Duration of the processing:
The processing shall commence on the commencement date of the Agreement and shall end upon the expiry or termination of the Agreement.
Nature and purpose of the processing:
MailBlue offers software and services in the field of email marketing, marketing automation, CRM and (digital) communication channels, and supports the Client in deploying them. When you use our services, Personal Data of your customers or contacts is processed by us for marketing purposes or management purposes related to the customer relationship. MailBlue stores and processes part of the Personal Data on its own systems. The Personal Data processed in the context of the email marketing account is stored and processed via ActiveCampaign. In both cases, the processing shall take place exclusively in accordance with your instructions and not for our own purposes.
Categories of Personal Data processed:
Given the nature of MailBlue’s services, the categories of Personal Data processed may differ per Controller. Each Controller has the ability to choose which Personal Data the Processor will process. In any event, the following data is processed on behalf of each Controller:
Categories of data subjects:
Customers, prospective customers, business contacts and other contact persons of the Controller.
The Controller warrants that the processing of the Data Subjects’ Personal Data is not unlawful and that this processing does not infringe the rights of others. The Controller indemnifies MailBlue against all claims relating thereto.
In the event that MailBlue discovers a Data Breach, reasonably suspects one, or receives notice from a third party that a breach has occurred which, in its judgement, poses a real risk to the rights and freedoms of data subjects, MailBlue shall notify the Controller thereof without undue delay, so that the Controller can assess in good time whether notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is necessary. MailBlue aims in any event to inform the Controller within 72 hours of discovery, so that the Controller can comply with its own notification deadline.
The notification shall include, to the extent known at that time, at least: a description of the nature of the breach, the categories and (estimated) numbers of data subjects and personal data records concerned, the name and contact details of the contact person at MailBlue, the likely consequences of the breach, and the measures MailBlue has taken or proposes to take. If not all information is immediately available, the notification may be provided in phases.
MailBlue shall keep the Controller informed of new developments concerning the Data Breach and shall submit to the Controller the measures taken to limit and end the Data Breach and to prevent a similar incident in the future.
Notification of the Data Breach to the Dutch Data Protection Authority is the responsibility of the Controller.
This Data Processing Agreement enters into force at the moment the Controller accepts MailBlue’s General Terms and Conditions, in accordance with Article 1 of those General Terms and Conditions. Separate signature of this Data Processing Agreement is not required.
This Data Processing Agreement is entered into for the duration of the Agreement between the Parties and, where signed, in any event for the duration of the working relationship.
After termination of this Data Processing Agreement, the obligations relating to confidentiality, liability and indemnification shall continue to apply.
MailBlue offers the Controller the opportunity to export the Personal Data processed in the context of the services at any time during the contract period. Exports are possible until the expiry date of the subscription. The Controller is itself responsible for exporting the required Personal Data in good time before the end of the contract period.
After termination of the services, MailBlue shall enable the Controller to export Personal Data for a period of 6 months after the expiry date of the subscription, by means of reactivating the subscription for a minimum period of 1 month. After this period, MailBlue shall archive the account and all Personal Data and existing copies shall be permanently deleted no later than 12 months after the expiry date, unless storage of that Personal Data is required pursuant to a statutory retention obligation. In that case, MailBlue shall retain the relevant Personal Data solely for the duration of that statutory obligation, after which it shall still be deleted.
At the Controller’s request, MailBlue shall provide written confirmation of the deletion of the Personal Data.
MailBlue shall treat as confidential all Personal Data and other data it receives from the Controller. MailBlue shall restrict access to this data to only those staff who need access for the proper performance of MailBlue’s services.
MailBlue shall keep the Personal Data provided confidential and shall also impose a duty of confidentiality on its staff.
MailBlue shall provide its cooperation so that the Controller can respond to requests from data subjects under the GDPR (including requests for access, rectification, erasure, restriction of processing and data portability). MailBlue shall provide the Controller with the information required for this purpose within 5 business days of receipt of the request.
If MailBlue receives requests from third parties or government authorities to provide access to the Personal Data pursuant to a statutory obligation, MailBlue shall inform the Controller thereof without delay and in writing, unless a statutory prohibition prevents this. The Controller shall then assess whether the request is well-founded.
MailBlue acts as a partner of ActiveCampaign and works with ActiveCampaign in providing its services. ActiveCampaign is established in the United States. Depending on the data centre location, Personal Data is stored in the United States or within the European Union. For accounts where data is stored in European data centres, information about the location of the storage of Personal Data is available in the MailBlue Hub. For the purposes of ongoing platform support, authorised ActiveCampaign staff may access your email marketing account and the servers on which it is hosted from various countries. To the extent that such access takes place from countries outside the EEA that do not benefit from an adequacy decision of the European Commission, appropriate safeguards have been put in place in the form of Standard Contractual Clauses (SCCs) as adopted by the European Commission and, to the extent the receiving party is qualified for it, the EU-US Data Privacy Framework (DPF). A current list of the Sub-processors engaged by MailBlue, including the location of data storage and the transfer mechanisms used, can be consulted at mailblue.io/legal/subprocessors/.
In all transfers, MailBlue shall comply with the rules of the GDPR (Chapter V) and the arrangements in this Data Processing Agreement.
MailBlue shall ensure that the Personal Data is adequately secured. To prevent loss and unlawful processing, MailBlue shall take appropriate technical and organisational security measures. The measures taken include, among others:
MailBlue acts in accordance with the framework of the ISO 27001 standard. The current certificate is, where applicable, available at mailblue.io/legal/.
In the event that any provision of this Data Processing Agreement is null and void or voidable, this shall not affect the validity of the remainder of this Data Processing Agreement. In that case, the void provision shall be replaced by a provision that reflects the content of the void provision as closely as possible.
Deviations from and additions to this Data Processing Agreement shall apply only if agreed by both parties in writing.
This Data Processing Agreement and its performance are governed by Dutch law. Any disputes arising between the parties shall be submitted to the District Court of Zeeland-West-Brabant.
DISCLAIMER
MailBlue makes no undertaking or warranty whatsoever that this Data Processing Agreement provides a legally sufficient basis for compliance with the Controller’s obligations under the applicable legislation. MailBlue expressly disclaims all representations or warranties that the Data Processing Agreement will satisfy the Controller’s obligations, whether express, implied, statutory, arising under a trade treaty or otherwise. The Controller acknowledges that compliance with the GDPR is a shared responsibility and that MailBlue is responsible solely for the obligations it bears as Processor under the GDPR.