Legal
Data Processing Addendum
This Data Processing Addendum forms part of the agreement when ShipMsg processes personal data for a customer.
Effective September 3, 2026
Scope and instructions
The customer is controller and ShipMsg is processor for customer data submitted to ShipMsg. We process that data only on documented instructions in the agreement, product configuration, and authorized support requests, unless law requires otherwise. Processing covers hosting, authentication, routing, delivery reconciliation, support, security, billing, export, retention, and deletion for the contract term.
This DPA is incorporated into the customer agreement and applies when customer data is subject to data-protection law. “Controller,” “processor,” “personal data,” “processing,” “data subject” and “personal-data breach” have the meanings given by applicable law. The customer's configuration and authorized use of ShipMsg are documented instructions. We will notify the customer if an instruction appears unlawful unless prohibited by law.
People and data
Data subjects can include customer users, contacts, message recipients, and support participants. Data can include identifiers, contact details, consent evidence, message and media content, template and Flow responses, device and network data, delivery events, audit records, and billing metadata. Customers must not submit prohibited data and must configure additional safeguards for sensitive use cases.
Security and assistance
We maintain controls for access, tenant isolation, encryption, secrets, audit evidence, vulnerability handling, resilience, backup, restoration, and deletion. Personnel and contractors with access are bound by confidentiality. We assist customers with verified data-subject requests, security obligations, assessments, and regulator inquiries in a manner proportionate to the service and information available to us.
Controls include least-privilege access, tenant and environment isolation, encryption in transit and of protected data at rest, per-account key boundaries, credential sealing, signed webhooks, malware scanning, immutable audit evidence, monitored controllers, vulnerability management, backups and tested restoration. We regularly evaluate these measures and may replace a control with one providing materially equivalent or stronger protection.
Incidents
We will notify affected customers without undue delay after confirming a personal-data breach and provide available information needed for the customer's legal obligations. Notification does not constitute an admission of fault or liability.
Notice will include, as available, the nature of the breach, affected categories, likely consequences, measures taken or proposed, and a contact for follow-up. The customer is responsible for notices to its data subjects and regulators unless law places that duty directly on ShipMsg. We preserve an incident timeline and relevant evidence subject to security and legal restrictions.
Subprocessors and transfers
The customer authorizes the subprocessors listed on our Subprocessors page. We remain responsible for their processing to the extent required by applicable law and impose data-protection obligations appropriate to their role. We will provide notice of material additions and a reasonable opportunity to object on legitimate data-protection grounds. International transfers use a legally recognized transfer mechanism when required.
The published list is the customer's general written authorization. Customers may subscribe to notices and object to a new subprocessor before it begins materially different processing. The objection must identify reasonable data-protection grounds. We will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate only the affected service without penalty for its unused prepaid period.
Where European restricted transfers require them, the applicable controller-to-processor or processor-to-processor modules of the European Commission Standard Contractual Clauses are incorporated by reference and prevail over conflicting agreement language. The UK Addendum applies to restricted UK transfers. The customer may request the completed transfer annex and relevant transfer-impact information.
Return, deletion, and audit
At the end of service, we return or delete customer data according to the agreement, configured retention, and applicable law. We provide compliance information and permit a reasonable audit where required, subject to confidentiality, security, and cost controls.
We first satisfy audits through current independent reports, policies, summaries and written responses. If those are insufficient for a legal requirement, the customer may conduct one reasonable audit annually, and after a confirmed breach, with advance notice, qualified independent personnel, no access to other customers' data, and reimbursement of reasonable costs unless material noncompliance is found. Government supervisory authority rights are not limited.
Controller obligations
The customer will provide lawful instructions, notices and legal bases; obtain required consent; respond to recipient rights; minimize submitted data; configure retention and access; and ensure its use of ShipMsg complies with law and provider policy. The customer will not instruct us to process data that the agreement does not support or unlawfully combine data across independent businesses.
Processing details
- Subject matter: operation and support of the ShipMsg business messaging service.
- Duration: the service term plus configured retention and required deletion periods.
- Purpose: authentication, hosting, messaging, routing, reconciliation, security, support, billing, analytics, export and deletion.
- Data subjects: customer users, contacts, message recipients, representatives and support participants.
- Data: identifiers, contact details, consent, content, media, templates, Flow responses, delivery events, usage, device, network, audit and billing metadata.
- Frequency: continuous or as initiated and configured by the customer.
Priority and survival
This DPA controls over conflicting agreement terms for its subject. The remainder of the customer agreement, including liability allocation, continues to apply. Processing, confidentiality, security, return, deletion and audit obligations survive for as long as protected customer personal data remains in our possession.
Contact
ShipMsg legal questions: legal@shipmsg.com. Privacy questions and rights requests: privacy@shipmsg.com. ShipMsg support questions: support@shipmsg.com. Do not email passwords, payment-card data, message content, or identity documents; ShipMsg will provide a secure verification channel when needed.