1. Parties and incorporation
This Data Processing Addendum ("DPA") forms part of the agreement between Paravane Labs, Inc. ("Paravane") and the customer that has accepted the Paravane Terms of Service, signed an Order, or otherwise entered into an agreement for the Services ("Customer").
This DPA applies only to the extent Paravane processes Customer Personal Data on behalf of Customer as a processor, service provider, contractor, or equivalent role under applicable Data Protection Laws. This DPA does not apply to personal information Paravane processes as an independent controller/business for its own purposes, which is addressed in the Privacy Policy.
2. Definitions
| Term | Meaning |
|---|---|
| Affiliate | An entity that controls, is controlled by, or is under common control with a party. |
| Customer Personal Data | Personal Data contained in Customer Data that Paravane processes on behalf of Customer in connection with the Services. |
| Data Protection Laws | All data protection, privacy, data security, breach notification, and similar laws applicable to the processing of Customer Personal Data under the Agreement, including GDPR, UK GDPR, Swiss data protection law, and applicable U.S. state privacy laws where relevant. |
| GDPR | Regulation (EU) 2016/679, the General Data Protection Regulation. |
| Security Incident | A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Paravane. |
| Services | The Paravane services purchased or used by Customer, including the smtpRS API, dashboard, documentation, and support. |
| Subprocessor | A third party engaged by Paravane to process Customer Personal Data on behalf of Customer in connection with the Services. |
Terms such as "controller," "processor," "personal data," "processing," "data subject," "business," "service provider," "contractor," "consumer," "sale," and "share" have the meanings given in applicable Data Protection Laws.
3. Roles of the parties
Customer is the controller/business or processor/service provider, as applicable, for Customer Personal Data. Paravane is a processor/service provider or subprocessor/contractor, as applicable, when processing Customer Personal Data on behalf of Customer.
Customer determines the purposes and means of processing Customer Personal Data, including what data to submit, which endpoints to call, how to configure the Services, how to interpret outputs, and what actions to take based on outputs. Paravane processes Customer Personal Data only as described in this DPA and the Agreement or as otherwise instructed by Customer in writing.
4. Customer instructions
Customer instructs Paravane to process Customer Personal Data to provide, secure, support, maintain, troubleshoot, and improve the Services; process API requests; generate outputs; authenticate users; manage accounts, sessions, email verification, password reset, API keys, subscriptions, billing status, and usage reporting; prevent abuse; enforce Usage Limits; comply with law; and perform the Agreement. Customer may provide additional documented instructions, provided they are consistent with the Agreement and lawful.
Paravane will promptly notify Customer if Paravane believes an instruction violates Data Protection Laws, unless prohibited by law. Paravane is not responsible for determining whether Customer's instructions comply with laws applicable to Customer, Customer's industry, Customer's end users, or Customer's downstream uses.
5. Customer obligations
Customer is responsible for:
- Providing all notices, obtaining all consents, establishing all lawful bases, and honoring all opt-outs required for Customer Personal Data.
- Ensuring Customer Personal Data is accurate, lawful, relevant, and limited to what is necessary for Customer's permitted use.
- Ensuring Customer has the right to submit Customer Personal Data to Paravane and instruct Paravane to process it.
- Complying with Data Protection Laws, the Terms of Service, the AUP, and Documentation.
- Not submitting prohibited sensitive, regulated, or special-category data unless expressly authorized in a separate written agreement.
- Responding to data subject/consumer requests where Customer is the controller/business and instructing Paravane where assistance is needed.
- Securing Customer systems, credentials, API keys, sessions, integrations, exports, logs, payment-provider accounts, and downstream uses of outputs.
6. Paravane processing obligations
Paravane will:
- Process Customer Personal Data only on documented instructions from Customer, including this DPA, the Agreement, Orders, Documentation, API calls, dashboard settings, and written instructions accepted by Paravane.
- Ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations.
- Implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as described in Annex B.
- Assist Customer with data subject/consumer requests, security obligations, data protection impact assessments, and regulatory consultations to the extent required by Data Protection Laws and taking into account the nature of processing and information available to Paravane.
- Notify Customer of Security Incidents as described in this DPA.
- Use Subprocessors only as described in this DPA.
- Delete or return Customer Personal Data as described in this DPA and the Agreement.
- Make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and operational restrictions.
7. Confidentiality and personnel access
Paravane will limit access to Customer Personal Data to personnel, contractors, and Subprocessors who need access to provide, secure, support, maintain, or improve the Services, or to comply with law. Paravane will take reasonable steps to ensure that such personnel are subject to confidentiality obligations and receive security guidance appropriate to their roles.
8. Security measures
Paravane will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. The measures are described in Annex B and may be updated over time, provided that updates do not materially reduce the overall security of the Services during an active subscription.
Customer acknowledges that security measures must account for the nature of the Services, the data submitted by Customer, Customer's configurations, Customer's integrations, and evolving threats. Customer is responsible for implementing appropriate security measures in Customer's own environment.
9. Subprocessors
Customer authorizes Paravane to engage Subprocessors to process Customer Personal Data in connection with the Services, including infrastructure, security, payment processing, email delivery, and other service providers listed in Paravane's Subprocessor List.
Paravane will impose written data protection obligations on Subprocessors that are no less protective, in substance, than the obligations in this DPA to the extent applicable to the Subprocessor's processing. Paravane remains responsible for Subprocessors' performance of their data protection obligations under this DPA.
Paravane will provide notice of material new Subprocessors by updating the Subprocessor List or providing another notice mechanism. Customer may object to a new Subprocessor on reasonable data protection grounds within 30 days of notice. If the parties cannot resolve the objection, Customer may terminate the affected Services as its sole remedy, unless the parties agree otherwise.
10. Data subject and consumer requests
If Paravane receives a request directly from an individual relating to Customer Personal Data, Paravane will, where reasonably identifiable as Customer Personal Data and legally permitted, either direct the individual to Customer or notify Customer. Paravane will not respond to the substance of the request except on Customer's documented instructions or as required by law.
Taking into account the nature of processing, Paravane will provide reasonable assistance to Customer to fulfill Customer's obligations to respond to requests for access, deletion, correction, portability, restriction, objection, opt-out, appeal, or similar rights under Data Protection Laws.
11. Security Incident notification
Paravane will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notice will include information reasonably available to Paravane, which may include the nature of the incident, categories of affected data, approximate number of affected records if known, likely consequences if known, mitigation measures, and a contact point for follow-up.
Paravane's notification of, or response to, a Security Incident is not an admission of fault or liability. Customer is responsible for determining whether notification to individuals, regulators, customers, or others is required, unless applicable law requires Paravane to notify directly.
12. Assistance with DPIAs and consultations
Taking into account the nature of processing and information available to Paravane, Paravane will provide reasonable assistance to Customer with data protection impact assessments, transfer impact assessments, and prior consultations with regulators where required by Data Protection Laws and related to Paravane's processing of Customer Personal Data.
13. Deletion and return
Upon termination or expiration of the Services, Paravane will delete or return Customer Personal Data in accordance with the Agreement, Documentation, retention schedules, and Customer's documented instructions, unless retention is required by law or permitted for security, fraud prevention, dispute resolution, backup, or compliance purposes.
Customer acknowledges that Customer Personal Data may remain in encrypted backups and logs until overwritten or deleted in the ordinary course of business, subject to access restrictions and retention controls. Paravane will not restore backup data except for disaster recovery, security, legal, or operational purposes.
14. Audits and information rights
Upon reasonable written request and subject to confidentiality, security, and availability restrictions, Paravane will make available information reasonably necessary to demonstrate compliance with this DPA. This may include security documentation, summaries, questionnaires, third-party certifications, audit reports if available, or written responses.
On-site audits are permitted only where required by Data Protection Laws and only after the parties agree on scope, timing, confidentiality, security controls, auditor qualifications, and cost allocation. Audits must not unreasonably interfere with Paravane operations, compromise security, expose other customers' information, or require disclosure of trade secrets or highly sensitive information.
15. International transfers
Customer authorizes Paravane and its Subprocessors to process Customer Personal Data in the United States, the European Economic Area, and other countries where Paravane or its Subprocessors operate, subject to applicable transfer safeguards.
Where Customer Personal Data protected by GDPR, UK GDPR, Swiss data protection law, or similar laws is transferred to a country without an applicable adequacy decision, the parties will use an appropriate transfer mechanism, such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss addendum terms, a lawful data privacy framework if Paravane later becomes certified under that framework, or another lawful mechanism.
16. Government and legal requests
If Paravane receives a government, law-enforcement, national-security, court, or regulatory request for Customer Personal Data, Paravane will review the request and, where legally permitted and commercially reasonable, notify Customer before disclosure so Customer may seek protective relief. Paravane may disclose Customer Personal Data where Paravane reasonably believes disclosure is required by law.
17. U.S. state privacy law service-provider terms
To the extent Customer Personal Data is subject to U.S. state privacy laws that require service-provider, processor, contractor, or similar contract terms, Paravane will:
- Process Customer Personal Data only for the business purposes described in the Agreement, this DPA, Documentation, and Customer instructions.
- Not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising as those terms are defined by applicable law.
- Not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law.
- Not combine Customer Personal Data with personal information received from other sources except as permitted by applicable law, such as for security, fraud prevention, debugging, analytics, service improvement, or other permitted business purposes.
- Provide the same level of privacy protection required by applicable law for the processing activities covered by this DPA.
- Notify Customer if Paravane determines it can no longer meet its obligations under applicable law.
- Allow Customer to take reasonable and appropriate steps to help ensure Paravane uses Customer Personal Data consistently with Customer's obligations, through the audit and information mechanisms in this DPA.
18. De-identified and aggregated data
Paravane may process data derived from Customer Personal Data in de-identified, anonymized, or aggregated form for security, analytics, service improvement, benchmarking, research, and business purposes, provided that Paravane maintains and uses such data in de-identified or aggregated form and does not attempt to re-identify individuals except to test or validate de-identification or as permitted by law.
19. Order of precedence
If there is a conflict between this DPA and the Terms of Service, this DPA controls for the processing of Customer Personal Data. If there is a conflict between this DPA and Standard Contractual Clauses or another mandatory transfer mechanism, the transfer mechanism controls to the extent of the conflict. A signed enterprise agreement may modify this DPA only if it expressly states that it does so.
20. Limitation of liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by applicable law or expressly modified in a signed written agreement.
21. Contact
Legal and DPA questions may be sent to legal@paravane.io. Privacy questions and rights requests may be sent to privacy@paravane.io. Security questions and reports may be sent to security@paravane.io. General information requests may be sent to contact@paravane.io. Legal notices may also be mailed to: 11166 Fairfax Blvd Suite 500 #1378, Fairfax, VA 22030, United States; Phone: (703) 972-1286.
Annex A - Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of Paravane Services, including the smtpRS API, dashboard, scoring outputs, support, security, billing-adjacent account administration, and related operations. |
| Duration | For the term of the Agreement plus retention periods described in the Agreement, Privacy Policy, Documentation, or Customer instructions. |
| Nature and purpose | Receiving API requests, processing customer-submitted identifiers, generating risk scores and outputs, authenticating requests, logging usage, preventing abuse, debugging, providing support, maintaining security, and complying with law. |
| Categories of data subjects | Customer personnel and users; individuals associated with submitted email addresses, IP addresses, domains, or identifiers; customer end users or prospects where Customer submits their identifiers; support contacts. |
| Categories of personal data | Business contact information, account identifiers, email addresses, domain names, IP addresses, online identifiers, API request metadata, user-agent strings, timestamps, status codes, risk signals, scores, labels, reason codes, support communications, and other fields Customer submits. |
| Sensitive data | Not intended. Customer must not submit sensitive, regulated, or special-category data unless expressly authorized by separate written agreement. |
| Processing operations | Collection, receipt, transmission, hosting, storage, retrieval, consultation, analysis, transformation, scoring, logging, disclosure to Subprocessors, deletion, and related processing necessary to provide the Services. |
| Customer instructions | The Agreement, this DPA, Orders, API calls, dashboard settings, Documentation, support requests, and other written instructions accepted by Paravane. |
Annex B - Technical and organizational measures
| Measure | Description |
|---|---|
| Encryption in transit | Use HTTPS/TLS for transmission of Customer Personal Data over public networks, with current protocol and certificate management appropriate for public web and API endpoints. |
| Encryption at rest | Use infrastructure-supported encryption or equivalent protections for production storage, managed databases, object storage, backups, or disks that hold Customer Personal Data. |
| Access controls | Use role-based or least-privilege access controls for production systems, with access limited to authorized personnel with a business need. |
| Authentication | Use password hashing and secure authentication for user accounts. Administrative access should use strong authentication and MFA where available; customer-facing MFA and SSO/SAML are not available unless separately offered or agreed. |
| API credential security | Issue unique API keys/tokens, allow rotation/revocation, and monitor for suspicious usage. Customers remain responsible for keeping credentials secret. |
| Logging and monitoring | Maintain logs for security, reliability, performance, abuse detection, and troubleshooting, subject to retention limits and access controls. |
| Network and infrastructure security | Use reputable hosting and security providers, firewall/WAF controls where applicable, network segmentation where appropriate, and secure configuration management. |
| Vulnerability management | Apply security patches, dependency updates, and vulnerability remediation based on severity, exposure, and operational risk. |
| Secure development | Use code review, environment separation, secrets management, dependency review, and deployment controls appropriate to the size and maturity of the company. |
| Backups and resilience | Maintain backups and recovery procedures appropriate to the Services, with backup retention generally targeted at approximately 30 to 90 days unless otherwise required. |
| Personnel security | Restrict production access to authorized personnel; use confidentiality obligations; provide security awareness appropriate to role. |
| Vendor management | Review subprocessors for security and privacy fit and require written data protection commitments. |
| Incident response | Maintain an incident response process for identifying, investigating, mitigating, and notifying customers of Security Incidents. |
| Data minimization | Limit stored data and logs to what is reasonably necessary for service operation, security, billing, support, improvement, and compliance. |
| Deletion and disposal | Delete or overwrite Customer Personal Data according to retention schedules, customer instructions, and legal requirements. |
Annex C - Subprocessors
The Subprocessor List published by Paravane is incorporated into this DPA and identifies third parties Paravane uses to process Customer Personal Data in connection with the Services.
Annex D - Transfer mechanisms
Where required for restricted transfers, the parties will use the EU Standard Contractual Clauses, the UK International Data Transfer Addendum for UK transfers, Swiss addendum language for Swiss transfers, or another lawful transfer mechanism applicable to the transfer. Paravane does not rely on EU-U.S. Data Privacy Framework certification unless it has completed and maintains that certification.
Annex E - Customer configuration and instructions
| Area | Instruction/setting |
|---|---|
| Data submitted | Customer controls which identifiers and fields are submitted to the Services. |
| Retention configuration | Default position: ordinary API request metadata is retained for approximately 90 days unless a different period is required for security, abuse prevention, debugging, legal claims, compliance, or a customer agreement. Full API payloads should not be stored by default where feasible. Customer-configurable log retention, deletion, or masking settings should be described when implemented. |
| Access controls | Customer controls its users, roles, API keys, and integrations through available dashboard and API controls. |
| Output use | Customer controls thresholds, workflows, review processes, notices, appeals, and downstream actions taken based on outputs. |
| Deletion requests | Customer may request deletion/export through privacy@paravane.io or the dashboard/support process when available. |