EEmail Editor

Data processing agreement (template)

Status: draft, for Marlin's legal review. Every fact below is taken from the service as built (apps/service) and its plan (docs/plans/2026-09-18-mail-service.md, "Legal shape"); the wording has not been reviewed by a lawyer. The privacy notice for recipients and operators is at mail.lumitra.co/privacy.

Between the organisation operating a workspace in Lumitra Mail (the Controller) and Lumitra Mail, run by Marlin Jai Pohl, Grumbkowstr. 6, 13156 Berlin, Germany (the Processor), under Article 28 of the General Data Protection Regulation (GDPR).

1. Subject and duration

The Processor runs Lumitra Mail, a service that stores the Controller's contacts, builds and sends the Controller's email through the mail provider the Controller connects, keeps the sent mail, and hosts the pages recipients use to manage their subscriptions. The agreement lasts as long as the Controller has a workspace in the service, and its obligations on deletion outlast it (section 9).

2. Nature and purpose of the processing

Storing contact records and topic subscriptions; rendering and sending email; recording delivery outcomes, blocks (unsubscribes, bounces, complaints) and, when the Controller turns it on for the workspace, opens and clicks; keeping an archive of what was sent; serving unsubscribe, preference and sign-up pages; running the automations the Controller defines.

3. Categories of data and of data subjects

Recipients of the Controller's email: email address, name, the properties the Controller records (for example a language or a customer number), topic subscriptions, blocks and their reason, the sent messages as sent and the provider's message id, and, when tracking is on, open and click events.

The Controller's staff: the account used to sign in (email address, name, company), roles, invitations, API keys, and an audit log of changes.

4. Instructions

The Processor processes personal data only on the Controller's documented instructions, which are: the Controller's use of the dashboard, the API and the SDK, this agreement, and the service's documented behaviour. The Processor informs the Controller when it believes an instruction infringes data protection law.

5. Confidentiality

Persons the Processor authorises to process the data are bound to confidentiality. Access to production is limited to the operator of the service and is recorded.

6. Security (Art. 32)

  • Data at rest in a PostgreSQL database and an object store on servers in Germany (section 7); provider credentials and API keys sealed with a key the service holds, never stored in plain text; transport encrypted (TLS) for the dashboard, the API, the hosted pages and mail submission.
  • Every workspace's data is separated by workspace id in every query; API keys are scoped (full, send, read) and hashed; members carry roles.
  • An audit log of changes per workspace; signed webhooks; unsubscribe links signed per recipient.
  • Backups of the database as part of the hosting platform; the Processor restores from them in a loss event.
  • The service's own conformance, integration and end-to-end test suites run before every deployment.

7. Sub-processors

The Controller authorises these sub-processors; the Processor informs the Controller of a change with reasonable notice, and the Controller may object.

Sub-processorPurposeLocation
Hetzner Online GmbHServers for the service, its database and the sent archiveGermany
Cloudflare, Inc. (R2, through the Processor's Storage Brain service)Storage of images the Controller uploads for its emailsEU jurisdiction with the provider's transfer terms
The mail provider the Controller connects (its own SMTP server, or Resend, Inc.)Delivery of the emailAs chosen by the Controller
Lumitra's authentication service (auth.lumitra.co)Sign-in of the Controller's staffGermany

8. Assistance

The Processor assists the Controller with data subject requests through the service's own means: a contact's record, its messages and its blocks can be read through the API and the dashboard; a contact can be erased (contacts.erase), which removes the contact, its recipient records and the archived emails for that person and keeps the block on the address so the person is not mailed again; the whole workspace can be exported through the API. The Processor informs the Controller without undue delay of a personal data breach affecting the Controller's data.

9. Deletion and return

On termination the Controller may export its data through the API. When the Controller's company is deleted at Lumitra, every workspace of that company is erased, uploaded images first, in one transaction; otherwise the Controller deletes its workspace or asks the Processor to. Blocks (suppressions) are kept until the Controller deletes them, because they exist to honour a recipient's wish.

10. Audits

The Processor makes available the information necessary to demonstrate compliance and allows for and contributes to audits by the Controller or an auditor it mandates, on reasonable notice and at the Controller's cost.

11. Transfers

Personal data is processed in Germany. A transfer to a third country happens only where a sub-processor in section 7 entails one, under that sub-processor's transfer terms (standard contractual clauses).

12. Term of the sub-processor list and changes

This agreement is provided with the service and changes when the service does; the Processor keeps the current version at the address of this page and tells operators about a change of sub-processor before it takes effect.