1. Parties and scope
This Data Processing Agreement (“DPA”) is between Sendix (“Sendix”, processor), and the customer that accepted the Terms of Service (“Customer”, controller). It forms part of the Terms of Service and applies whenever Sendix processes personal data on the Customer’s behalf (“Customer Personal Data”). It is accepted together with the Terms and requires no separate signature.
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in KVKK and, where it applies, the GDPR. If the Customer is itself a processor for another controller, Sendix is its sub-processor and the Customer is responsible for passing on the relevant commitments.
2. Processing on instructions
Sendix processes Customer Personal Data only to provide the Service in accordance with the Terms, the Customer’s configuration of the Service, and other documented instructions the Customer gives. The Terms, this DPA and the Customer’s use of the dashboard, API and SMTP are the Customer’s complete instructions.
Sendix will tell the Customer if it believes an instruction infringes applicable data protection law, and may suspend the affected processing until the instruction is confirmed or changed. Sendix may process Customer Personal Data where required by law, and will inform the Customer beforehand unless the law prohibits it.
The Customer is responsible for the lawfulness of the processing, for having a legal basis for each Recipient, for informing data subjects, and for not submitting special categories of personal data unless that is necessary and lawful.
3. Confidentiality
Sendix ensures that everyone authorised to process Customer Personal Data is bound by confidentiality obligations and accesses it only as necessary to operate, support or secure the Service.
4. Security
Sendix implements and maintains the technical and organisational measures in Annex 2, taking into account the state of the art, costs, and the nature, scope and purposes of the processing, as required by Article 12 KVKK and Article 32 GDPR. Sendix may update these measures provided the overall level of protection is not reduced.
5. Sub-processors
The Customer gives general authorisation for Sendix to use the sub-processors in Annex 3. Sendix imposes data protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.
Sendix will notify the Customer by email and on the sub-processor page at least 30 days before authorising a new sub-processor to process Customer Personal Data. The Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected Service and receive a refund of prepaid fees for the unused period.
6. Assistance
Taking into account the nature of the processing, Sendix assists the Customer through the Service’s features (such as search, export, suppression and deletion) and, where necessary, on request, in responding to data subject requests, carrying out data protection impact assessments and consulting supervisory authorities. If Sendix receives a request directly from a data subject about Customer Personal Data, it refers the data subject to the Customer and does not respond on the merits unless instructed.
7. Personal data breaches
Sendix notifies the Customer without undue delay, and in any event within 72 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records, likely consequences and the measures taken or proposed. Sendix takes reasonable steps to contain the breach and supports the Customer in meeting its own notification obligations, including to the KVKK Board within 72 hours.
8. Deletion and return
During the term, Customer Personal Data is deleted automatically at the end of the retention period of the Customer’s plan, and the Customer can delete data at any time through the Service. When the Customer deletes its account, Sendix deletes Customer Personal Data immediately from its live systems; copies in encrypted backups are overwritten within 14 days. Before deletion the Customer can export its data where its plan includes export. Sendix may keep data where the law requires it, protected and only for that purpose.
9. Information and audits
Sendix makes available the information necessary to demonstrate compliance with this DPA, including answers to reasonable security questionnaires. Where that is not sufficient or a supervisory authority requires it, the Customer may carry out an audit, at most once a year, with at least 30 days’ notice, during business hours, at its own cost, subject to confidentiality and without access to other customers’ data. Audits are carried out remotely unless an on-site audit is necessary.
10. International transfers
Sendix processes Customer Personal Data primarily in Türkiye. Transfers to sub-processors outside Türkiye are carried out in accordance with Article 9 KVKK. Where the law requires the standard contract published by the KVKK Board for a transfer between the Customer and Sendix, the parties will execute it on request.
To the extent the Customer transfers personal data subject to the GDPR to Sendix in Türkiye, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“SCCs”) are incorporated by reference: Module Two (controller to processor) or Module Three (processor to processor), as applicable. For the SCCs: Clause 7 does not apply; under Clause 9(a) Option 2 applies with the notice period in section 5 of this DPA; the optional wording in Clause 11 does not apply; under Clause 13 the competent supervisory authority is the one determined by the Customer’s establishment or representative; under Clauses 17 and 18 the law and courts of Ireland apply. Annexes I and II of the SCCs are completed by Annexes 1 and 2 of this DPA. For transfers subject to UK law, the UK International Data Transfer Addendum applies, and for Switzerland the SCCs apply with the necessary adaptations for the Swiss Federal Act on Data Protection. The SCCs prevail if they conflict with this DPA.
11. Liability, term and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms, except where the law does not allow them. This DPA applies for as long as Sendix processes Customer Personal Data. If this DPA conflicts with the Terms, this DPA prevails in relation to personal data. This DPA is governed by the law that governs the Terms, except for the SCCs.
Annex 1 – Details of processing
| Item | Description |
|---|---|
| Subject matter and nature | Sending, receiving, storing and analysing email and related data on behalf of the Customer: hosting, transmission, queuing, DKIM signing, bounce and complaint processing, suppression, templates, audiences, webhooks, logging. |
| Purpose | Providing the Service to the Customer under the Terms. |
| Duration | The term of the Terms plus the deletion periods in section 8. |
| Data subjects | Recipients and senders of Customer email; the Customer’s end users, customers and contacts; Customer staff whose data appears in Customer Data. |
| Categories of data | Email addresses, names and other contact data; message content, subject lines and attachments; contact list properties and segments; delivery, bounce and complaint events; if tracking is enabled, open and click time, IP address and user agent; any other personal data the Customer includes in messages. |
| Special categories | None intended. The Customer must not submit special category data unless necessary and lawful, and is responsible for additional safeguards. |
| Frequency | Continuous, for as long as the Customer uses the Service. |
| Retention | According to the Customer’s plan: Free 7 days, Pro 90 days, Enterprise as agreed (up to 730 days); delivery analytics up to 25 months; suppression entries until removed. |
Annex 2 – Technical and organisational measures
- Encryption in transit: HTTPS/TLS for the website, dashboard and API; STARTTLS for SMTP submission; outbound delivery upgrades to TLS whenever the receiving server supports it; MTA-STS enforced for Sendix’s own domains.
- Encryption at rest for secrets: DKIM private keys, provider credentials and other decryptable secrets are protected with authenticated AES-256-GCM envelope encryption. Backups are encrypted before they leave the server.
- Credentials: passwords are hashed with bcrypt; API keys, SMTP credentials and SCIM tokens are shown once and stored only as hashes; webhook payloads are signed with per-endpoint HMAC secrets.
- Access control: optional TOTP two-factor authentication, with a fresh code required for sensitive operations such as billing and account deletion when enabled; role-based workspace permissions; admin functions restricted to operators and recorded in the audit log.
- Infrastructure: databases, queues and analytics stores listen only on local interfaces; host firewall with a minimal set of open ports; brute-force protection; each service runs as its own unprivileged system user; sending nodes hold no database or signing secrets.
- Logging and monitoring: audit logs of authentication and sensitive actions (kept 365 days); continuous health probes and a public status page; metrics and alerting for the delivery pipeline.
- Resilience: regular encrypted backups with a rolling 14-day window, stored on the primary server and copied to a second server in Türkiye; documented restore procedure.
- Data minimisation and deletion: plan-based retention enforced by scheduled jobs; account deletion erases data and stored files immediately; delivery analytics limited to 25 months.
- Personnel and process: access to production limited to the operator; confidentiality obligations; dependency vulnerability scanning; secret rotation after security events; responsible disclosure channel at [email protected].
Annex 3 – Sub-processors
| Provider | Purpose | Data | Location |
|---|---|---|---|
| ODEAWEB Bilişim Teknolojileri San. ve Tic. Ltd. Şti. (Bilhost) | Hosting of the primary servers (application, databases, queues, file storage), a sending node and encrypted backups | All account and customer data | Türkiye |
| Alastyr Telekomünikasyon A.Ş. | Hosting of a sending and inbound mail node | Messages in transit, delivery metadata | Türkiye |
| Cloudflare, Inc. | DNS, content delivery, TLS termination, DDoS and bot protection (including Turnstile) for the website, dashboard and API | IP address, request metadata, data in HTTPS requests passing through the network | United States (global network) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Card payments, if you choose Stripe at checkout | Name, email, payment details, amount | Ireland / United States |
| PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş. | Card payments, if you choose PayTR at checkout | Name, email, phone, payment details, amount | Türkiye |
| iyzico Ödeme Hizmetleri A.Ş. | Card payments, if you choose iyzico at checkout | Name, email, phone, payment details, amount | Türkiye |
| Ödesin (odesin.com) | Card payments, if you choose Ödesin at checkout | Name, email, phone, payment details, amount | See the provider’s privacy notice |
| Dodo Payments | Card payments and card-backed trials, if you choose Dodo Payments at checkout | Name, email, payment details, amount | Outside Türkiye |
| OxaPay | Crypto payments, if you choose OxaPay at checkout | Email, order reference, amount, wallet transaction data | Outside Türkiye |
| NOWPayments | Crypto payments, if you choose NOWPayments at checkout | Email, order reference, amount, wallet transaction data | Outside Türkiye |
| Google LLC | Sign in with Google, if you choose it | Name, email, Google account identifier | United States |
| GitHub, Inc. | Sign in with GitHub, if you choose it | Name, email, GitHub account identifier | United States |
| Knoku (knoku.com) | Documentation assistant on docs.sendix.dev, loaded only when you open it | Questions you type into the assistant, IP address, browser data | See the provider’s privacy notice |
The current list is maintained at sendix.dev/legal/subprocessors.
Questions about this document: [email protected]

