Skip to content
Claim your free business email

Data Processing Addendum

Last updated

About this addendum

This Data Processing Addendum is part of the agreement between you, the customer, and the company that operates Rasket (“Rasket”, “we”, “us”) under our Terms of Service.

It applies whenever we process personal data on your behalf to provide the service, and takes effect when you accept the Terms; nothing needs to be signed. Where this addendum and the Terms disagree about personal data, this addendum wins. To keep a copy, save this page as a PDF from your browser’s print menu.

Roles

For the email you send and receive through Rasket, and the contacts, recipients and content that go with it, you are the controller — or a processor acting for your own customer — and we are your processor. You decide what is sent, to whom, and why.

For your Rasket account, billing and your use of our website, we decide how personal data is used, and the Privacy Policy covers it rather than this addendum.

Details of the processing

Details
Subject matterProviding the Rasket service under the Terms of Service.
DurationFor as long as you use the service, and then until the data is deleted as “Deletion and return” below describes.
Nature and purposeAccepting, storing, sending, receiving and reporting on email; open and click tracking when you turn it on; hosting mailboxes; storing contacts, templates, campaigns and automations; and keeping the service secure and free of abuse.
Types of personal dataEmail addresses and names; message headers, subjects, bodies and attachments; delivery events, and the time, IP address and user agent of opens and clicks when tracking is on; contacts and the properties you store about them; unsubscribe and consent records; and the mail your mailboxes hold.
Data subjectsYour recipients, contacts and correspondents, and the people on your team who use the service.
Special categoriesRasket is not designed for special categories of personal data. You decide what your messages contain.

What we commit to

  • We process personal data only on your documented instructions: the Terms, this addendum, and the way you configure and use the service through the dashboard and the API. If the law requires us to do otherwise, we tell you first unless that law forbids it.
  • Everyone we authorise to process the data is bound to keep it confidential. A small number of our operators can reach it, through an internal console that asks for a second factor at every sign-in, only to investigate an incident or an abuse report or to keep the service running, and every action there is written to the audit log.
  • We protect the data with the technical and organisational measures described on our security page and in the Privacy Policy, among them TLS in transit, encryption at rest, team isolation enforced in the database, hashed passwords and API keys, encrypted secrets, two-factor authentication and an audit log.
  • We help you answer requests from data subjects. Most can be answered yourself: delete a contact through the dashboard or the API, or export or delete a project from Settings → Data. For anything else, write to us.
  • We give you the information we have when you need it for a data protection impact assessment or a consultation with a supervisory authority.

Subprocessors

You authorise us to use the subprocessors on our subprocessors page. We bind each one to data protection obligations that protect the data at least as well as this addendum, and we remain responsible to you for what they do. Before a new subprocessor starts, we update that page and announce the change in the changelog; you may object by writing to support@rasket.com, and if we cannot resolve the objection you can stop using the service.

International transfers

Our application and database run in the United States, so personal data from other countries is transferred there; the subprocessors page says where each provider processes it. Where the law that applies to you requires a transfer mechanism, we rely on the Standard Contractual Clauses approved by the European Commission, or the equivalent mechanism that law recognises, with “Details of the processing” above as the description of the transfer.

Personal data breaches

If we become aware of a breach of security that leads to personal data we process for you being lost, altered, disclosed or accessed without authorisation, we tell your team’s admins without undue delay, with what we know about it and what we are doing, and we keep you informed as we learn more.

Deletion and return

You can download a copy of a project’s data, or delete the project, at any time from Settings → Data. While you use the service, data is deleted when its retention window ends, as the Privacy Policy’s retention table lists. When you stop using the service, deleting the project erases its data 30 days later. Deleted data can remain in database backups for up to 90 days, which are used only to recover from a disaster. We may keep data longer only where the law requires it.

Audits

We make available the information needed to show that we meet this addendum: this page, the security page, and written answers to a reasonable security questionnaire. We do not hold a third-party certification today. Any further audit is agreed with us in advance, at your cost, and must not put other customers’ data at risk.

Liability

Each party’s liability under this addendum is subject to the limitations in the Terms of Service.

Contact

Questions about this addendum or your data: info@rasket.com. For help with your account: support@rasket.com.