Data Processing Agreement
The terms under which we process personal data on your behalf when you send email through Waymail, written out in full.
Last updated 15 September 2026
In one paragraph. This agreement is section 12 of the Terms of Service, set out in full as Article 28 of the GDPR requires. It applies to every workspace automatically and needs no signature. You are the controller of the personal data you put into Waymail — recipients, contacts, messages, delivery history; Gundhus AS is your processor; Amazon Web Services, in Frankfurt, is the only subprocessor that handles that data.
1. Scope and parties
1.1 This agreement is between Gundhus AS, Hellvikskogsvei 93, 1459 Nesodden, Norway, organisation number 922 852 014 (“Gundhus AS”, “we”, “us”), and the organisation that uses Waymail (“you”). It is part of the Terms of Service and applies from the moment you accept them. Where the Terms and this agreement differ on the processing of personal data, this agreement prevails.
1.2 “Customer Data” has the meaning in section 5 of the Terms. “Personal data”, “processing”, “controller”, “processor”, “data subject”, “supervisory authority” and “personal data breach” have the meanings in Article 4 of the GDPR, Regulation (EU) 2016/679, as it applies in the EEA, including Norway.
1.3 If you use Waymail to send email for your own clients — as a platform does — you are a processor for them and we are your subprocessor. You confirm that your clients have authorised this, and that your instructions to us reflect theirs.
2. Details of the processing
| Subject matter | Providing the Waymail service to your workspace. |
|---|---|
| Duration | For as long as the Terms apply, and until Customer Data has been deleted under section 9. |
| Nature and purpose | Storing, sending and tracking email; recording what happens to each message; managing contacts, topics and suppressions; and delivering webhooks — all as you direct through the API, the console and your settings. |
| Data subjects | Your recipients and contacts; anyone named in the messages you send; and, if you are a platform, your clients' recipients and contacts. |
| Personal data | Email addresses and names; message subjects, bodies, attachments, headers and tags, which may contain any personal data you choose to include; contact properties and topic subscriptions; delivery, open and click events, including user-agent strings; and suppression entries with their reasons. |
| Special categories | Not intended. Do not send special categories of personal data (Article 9) through Waymail unless you have a lawful basis, and appropriate safeguards, for sending them by email. We apply no measures specific to them. |
3. Roles and instructions
3.1 You are the controller of the personal data in Customer Data, and we are your processor.
3.2 Your documented instructions are: this agreement and the Terms; what you do through the API and the console; and your workspace's settings — its region, its retention period, and whether open and click tracking are on. An instruction outside these needs our written agreement.
3.3 We will tell you if we believe an instruction infringes the GDPR or other data protection law. We are not obliged to check your instructions systematically.
4. Our obligations as processor
We will:
- process the personal data only on your documented instructions, unless EU or EEA law requires otherwise — in which case we tell you before processing, unless that law forbids it;
- ensure that everyone we authorise to process it is bound by a duty of confidentiality, by contract or by law;
- protect it with the technical and organisational measures Article 32 requires, including those described on the Security page and under Security in the Privacy Policy. We may change those measures, but not reduce the overall level of protection;
- engage subprocessors only as section 5 allows;
- help you respond to data subjects' requests to exercise their rights, taking into account the nature of the processing — mostly through the API and the console, which let you find, export, correct and delete contacts, messages and suppression entries. If a data subject writes to us instead, we pass the request to you promptly and help you answer it;
- help you meet your obligations under Articles 32 to 36 — security, breach notification, data protection impact assessments and prior consultation — taking into account the nature of the processing and the information available to us;
- notify you of personal data breaches as section 7 describes;
- delete or return Customer Data at the end of the service as section 9 describes; and
- make available the information needed to show that we meet Article 28, and allow for and contribute to audits as section 10 describes.
5. Subprocessors
5.1 You give us general authorisation to engage the subprocessors below. Only Amazon Web Services processes Customer Data. The others handle the console's sign-in, our own domain and our mailbox — data we control, as the Privacy Policy describes — and none of them receives the messages you send or the addresses you send them to.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, databases, queues and email delivery (Amazon SES) for Customer Data | Frankfurt, Germany (eu-central-1) for EU workspaces; website and console files worldwide through CloudFront, which hold no Customer Data |
| Clerk, Inc. | Console accounts and sign-in | United States |
| Cloudflare, Inc. | DNS for waymail.app; forwarding email sent to waymail.app addresses; Turnstile bot protection at sign-in | Global network |
| Zoho Corporation B.V. | Our own mailbox, for email sent to hello@waymail.app | EU |
5.2 Before anyone is charged for a paid plan, we will add a payment provider to this list. It will handle billing details, not Customer Data.
5.3 We will tell your workspace's owners by email, and update this page, at least 30 days before we add or replace a subprocessor. You may object within those 30 days on reasonable data protection grounds. If we cannot resolve the objection, you may end the Terms without penalty before the change takes effect, with the export period section 9 of the Terms provides.
5.4 Each subprocessor is bound by a written contract with data protection obligations equivalent to those in this agreement. We remain fully responsible to you for its performance.
6. International transfers
6.1 Customer Data of a workspace in the EU region is stored and processed in the EU, in Frankfurt, and its email is sent through Amazon SES in the same region. We operate Waymail from Norway, in the EEA. Only the EU region is open today; a workspace's region is chosen when it is created and cannot change.
6.2 Where personal data is transferred outside the EEA — by us, or by a subprocessor — the transfer is covered by an adequacy decision of the European Commission, such as the EU–US Data Privacy Framework, or by the Standard Contractual Clauses the Commission has adopted, with any supplementary measures needed.
7. Personal data breaches
7.1 If we become aware of a personal data breach affecting Customer Data, we notify your workspace's owners by email without undue delay, and in any case within 48 hours.
7.2 The notice describes the nature of the breach; the categories and approximate number of data subjects and records concerned, where known; the likely consequences; the measures we have taken or propose to take; and who to contact. Where we do not yet know everything, we send what we know and follow up as we learn more.
7.3 Notifying a supervisory authority or data subjects is your decision as controller; we give you what you need to make it. An attempt that fails — a blocked request, a rejected sign-in — is not a breach.
8. Your obligations
You are responsible for having a lawful basis, and any consent the law requires, for the personal data you send through Waymail and for open and click tracking if you switch them on; for the lawfulness of your instructions; for answering data subjects and supervisory authorities; for choosing your workspace's region and retention period; and for keeping your credentials secure, as section 2 of the Terms says.
9. Deletion and return
9.1 While your workspace is active, you can retrieve Customer Data through the API at any time. Message bodies are kept only for the retention period your workspace chooses — 7 to 90 days, or not at all — and delivery history for your plan's period, as the Privacy Policy lists.
9.2 When the Terms end, you have 30 days to export Customer Data through the API, unless they ended because of your breach. After your workspace is closed, we delete Customer Data within 30 days, except where the law requires us to keep it. Backup copies age out within a further 35 days. We confirm the deletion in writing if you ask.
10. Information and audits
10.1 We answer reasonable written questions about how we process Customer Data and provide the documentation that shows it.
10.2 Where that is not enough, or a supervisory authority requires it, you or an independent auditor you appoint may audit our processing on 30 days' written notice, at your cost, no more than once a year unless a supervisory authority requires more. An audit takes place during business hours, does not disrupt the service or expose other customers' data, and its findings are confidential. For the infrastructure Amazon Web Services runs, we rely on Amazon's own audit reports.
11. Liability, law and changes
11.1 The limits of liability in section 14 of the Terms apply to this agreement. It is governed by the laws of Norway, with Oslo tingrett as the court of first instance, as section 17 of the Terms provides.
11.2 This agreement survives the end of the Terms for as long as we hold any Customer Data.
11.3 We may update this agreement as section 16 of the Terms allows: with at least 30 days' notice to workspace owners before a change that materially affects your rights. The version in force is the one at waymail.app/legal/dpa.
12. Contact
Questions about this agreement, a data subject's request, or a subprocessor change: hello@waymail.app. Our legal identity is on the Company Details page.