Nexpand Mail — Data Processing Agreement
Last updated: 18 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Zsigmond Gergely, egyéni vállalkozó (sole proprietor, Hungary), registered seat: 1026 Budapest, Guyon köz 5., Hungary, sole-proprietor registration number: 59673189, VAT number: 90477241-2-41 ("Processor") and the customer ("Controller") and is concluded pursuant to Article 28 GDPR. It applies to all personal data the Controller brings into or generates through the Nexpand Mail service ("Customer Data"). It is accepted electronically together with the Terms; no signature is required.
1. Subject matter, duration, nature and purpose
The Processor processes Customer Data on the Controller's behalf for the sole purpose of providing the Nexpand Mail service described in the Terms: hosting and organising the Controller's contact and campaign data, composing and dispatching emails from the Controller's own mailboxes at the Controller's instruction, detecting replies and bounces, maintaining suppression lists, operating the warm-up module, and synchronising data to systems the Controller connects. Processing lasts for the duration of the service agreement plus the deletion period in Section 8.
2. Categories of data subjects and data
- Data subjects: the Controller's outreach recipients, prospects and business contacts; participants of warm-up pools configured by the Controller; the Controller's own staff whose mailboxes are connected.
- Categories of personal data: name; email address; company and job attributes; personalisation fields the Controller supplies; the content of emails sent through the Service and of replies received; engagement and delivery events (sent, bounced, replied, opted out); suppression entries; mailbox identifiers and encrypted OAuth tokens of connected mailboxes.
- No special categories of data (Art. 9 GDPR) are intended to be processed; the Controller must not import them.
3. Controller's responsibilities
The Controller warrants that it has a valid legal basis for its outreach and for the processing of Customer Data, that its emails comply with applicable marketing and anti-spam law (see the Acceptable Use & Anti-Spam Policy), that it provides data subjects with the information required by Arts. 13–14 GDPR where applicable, and that its instructions comply with applicable law. The Controller's instructions are given through the features of the service.
4. Processor's obligations
The Processor shall:
- process Customer Data only on the Controller's documented instructions (the Terms, this DPA and the Controller's use of the service features), unless required by EU or Member State law — in which case the Processor informs the Controller unless prohibited;
- ensure persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Annex 2 (Art. 32 GDPR);
- assist the Controller, insofar as reasonably possible, in fulfilling data-subject requests (Arts. 12–23) — the service's export, correction, deletion and suppression features are the primary means of such assistance — and in the Controller's obligations under Arts. 32–36;
- notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, providing the information reasonably available;
- make available the information necessary to demonstrate compliance with Art. 28 and allow audits as set out in Section 7;
- not sell Customer Data or use it for its own purposes.
5. Subprocessors
The Controller grants general authorisation to engage the subprocessors listed in Annex 1. The Processor will notify customers (email or in-app) at least 14 days before adding or replacing a subprocessor; the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Controller may terminate the affected service. The Processor imposes data-protection obligations on subprocessors equivalent to this DPA and remains liable for their performance.
Microsoft and Google are not subprocessors of the Processor: they are the Controller's own service providers, engaged under the Controller's own agreements; the Service merely accesses them with the authorisation the Controller grants.
6. International transfers
Customer Data is hosted in the EU. Where a subprocessor processes personal data outside the EEA, the transfer is covered by an adequacy decision (including the EU–US Data Privacy Framework) or the EU Standard Contractual Clauses (2021/914), as noted in Annex 1.
7. Audit
Upon written request, at most once per year (or after a personal data breach), the Processor will provide documentation of its compliance with this DPA. If this is insufficient, the Controller may conduct or mandate an audit during business hours, with 30 days' notice, without access to other customers' data, at the Controller's cost.
8. Deletion and return
The Controller can export Customer Data and delete records at any time through the service. Upon termination of the agreement, the Processor deletes all Customer Data within 30 days of the account's deletion, except where EU or Member State law requires longer storage. Data disappears from rolling backups within a further 30 days as backups rotate. Emails already delivered to recipients and copies residing in the Controller's own mailboxes (Sent folders) are outside the Processor's control.
9. Liability and precedence
Liability under this DPA is subject to the limitations of the Terms, except where the GDPR mandates otherwise (Art. 82). In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.
Annex 1 — Approved subprocessors
| Subprocessor | Processing | Location / transfer mechanism |
|---|---|---|
| Rackhost Zrt., 6722 Szeged, Tisza Lajos krt. 41., Hungary | Infrastructure hosting (application server, database, backups) | EU (Hungary) |
| Resend (Plus Five Five, Inc.), USA | Transactional email delivery for the service itself (account verification, password reset) | USA — Standard Contractual Clauses |
| HubSpot, Inc., USA | Only where the Controller connects its own HubSpot portal: contact and email data the Controller selects for sync (transfer at the Controller's direction to the Controller's own HubSpot account) | EU/USA — EU–US Data Privacy Framework |
Stripe processes only the Controller's own billing data (as independent controller) and never Customer Data; it is therefore listed in the Privacy Policy, not here.
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
- Encryption in transit: all web and API traffic over TLS (HTTPS).
- Encryption at rest: mailbox OAuth tokens encrypted with AES-256-GCM; mailbox passwords are never received or stored.
- Access control: password authentication (scrypt hashes), email verification, HttpOnly session cookies, rate-limited login; company-based role model (advisor / manager / client) enforced on every read and write.
- Infrastructure: EU-located virtual private server, firewalled, key-based SSH access only.
- Backups & recoverability: automated, layered backups (hourly on-server, off-site copy on separate EU infrastructure, and an offline copy), rotated on a rolling schedule.
- Sending safety: per-mailbox daily caps and send windows; automatic suppression of bounced, replied and opted-out addresses; crash-safe send claiming so no message is dispatched twice.
- Logging: security-relevant events and sending activity recorded in a per-account audit log.
- Organisational: confidentiality obligations for personnel; least-privilege administration; security patches applied promptly.
Log in · Create account · Part of the nexpand suite · nexpand.hu