Data processing agreement (template)
Status: draft, for Marlin's legal review. Every fact below is taken from
the service as built (apps/service) and its plan
(docs/plans/2026-09-18-mail-service.md, "Legal shape"); the wording has not
been reviewed by a lawyer. The privacy notice for recipients and operators is
at mail.lumitra.co/privacy.
Between the organisation operating a workspace in Lumitra Mail (the Controller) and Lumitra Mail, run by Marlin Jai Pohl, Grumbkowstr. 6, 13156 Berlin, Germany (the Processor), under Article 28 of the General Data Protection Regulation (GDPR).
1. Subject and duration
The Processor runs Lumitra Mail, a service that stores the Controller's contacts, builds and sends the Controller's email through the mail provider the Controller connects, keeps the sent mail, and hosts the pages recipients use to manage their subscriptions. The agreement lasts as long as the Controller has a workspace in the service, and its obligations on deletion outlast it (section 9).
2. Nature and purpose of the processing
Storing contact records and topic subscriptions; rendering and sending email; recording delivery outcomes, blocks (unsubscribes, bounces, complaints) and, when the Controller turns it on for the workspace, opens and clicks; keeping an archive of what was sent; serving unsubscribe, preference and sign-up pages; running the automations the Controller defines.
3. Categories of data and of data subjects
Recipients of the Controller's email: email address, name, the properties the Controller records (for example a language or a customer number), topic subscriptions, blocks and their reason, the sent messages as sent and the provider's message id, and, when tracking is on, open and click events.
The Controller's staff: the account used to sign in (email address, name, company), roles, invitations, API keys, and an audit log of changes.
4. Instructions
The Processor processes personal data only on the Controller's documented instructions, which are: the Controller's use of the dashboard, the API and the SDK, this agreement, and the service's documented behaviour. The Processor informs the Controller when it believes an instruction infringes data protection law.
5. Confidentiality
Persons the Processor authorises to process the data are bound to confidentiality. Access to production is limited to the operator of the service and is recorded.
6. Security (Art. 32)
- Data at rest in a PostgreSQL database and an object store on servers in Germany (section 7); provider credentials and API keys sealed with a key the service holds, never stored in plain text; transport encrypted (TLS) for the dashboard, the API, the hosted pages and mail submission.
- Every workspace's data is separated by workspace id in every query; API keys are scoped (full, send, read) and hashed; members carry roles.
- An audit log of changes per workspace; signed webhooks; unsubscribe links signed per recipient.
- Backups of the database as part of the hosting platform; the Processor restores from them in a loss event.
- The service's own conformance, integration and end-to-end test suites run before every deployment.
7. Sub-processors
The Controller authorises these sub-processors; the Processor informs the Controller of a change with reasonable notice, and the Controller may object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Servers for the service, its database and the sent archive | Germany |
| Cloudflare, Inc. (R2, through the Processor's Storage Brain service) | Storage of images the Controller uploads for its emails | EU jurisdiction with the provider's transfer terms |
| The mail provider the Controller connects (its own SMTP server, or Resend, Inc.) | Delivery of the email | As chosen by the Controller |
| Lumitra's authentication service (auth.lumitra.co) | Sign-in of the Controller's staff | Germany |
8. Assistance
The Processor assists the Controller with data subject requests through the
service's own means: a contact's record, its messages and its blocks can be
read through the API and the dashboard; a contact can be erased
(contacts.erase), which removes the contact, its recipient records and the
archived emails for that person and keeps the block on the address so the
person is not mailed again; the whole workspace can be exported through the
API. The Processor informs the Controller without undue delay of a personal
data breach affecting the Controller's data.
9. Deletion and return
On termination the Controller may export its data through the API. When the Controller's company is deleted at Lumitra, every workspace of that company is erased, uploaded images first, in one transaction; otherwise the Controller deletes its workspace or asks the Processor to. Blocks (suppressions) are kept until the Controller deletes them, because they exist to honour a recipient's wish.
10. Audits
The Processor makes available the information necessary to demonstrate compliance and allows for and contributes to audits by the Controller or an auditor it mandates, on reasonable notice and at the Controller's cost.
11. Transfers
Personal data is processed in Germany. A transfer to a third country happens only where a sub-processor in section 7 entails one, under that sub-processor's transfer terms (standard contractual clauses).
12. Term of the sub-processor list and changes
This agreement is provided with the service and changes when the service does; the Processor keeps the current version at the address of this page and tells operators about a change of sub-processor before it takes effect.