Data Processing Agreement
Last updated: August 2026
This DPA covers personal data you put into LexLab services — recipient lists, mailbox contents, data on your VPS, domain registrant details. You are the controller. We are the processor. It forms part of the Terms of Service and applies automatically when you use a service that processes personal data on your behalf.
If your organisation needs this executed as a signed document, email support@lexlabtools.com with DPA in the subject line.
1. Parties and Roles
For personal data you submit or generate through the services, you are the controller — you decide whose data it is, why you hold it, and what happens to it. LexLab is the processor, acting on your instructions.
For a small set of data we decide about ourselves — your account details, our billing records, our security and abuse logs — we are the controller. That is covered by the Privacy Policy, not by this DPA.
Where you resell LexLab services, you are the controller toward your own customers, and you are responsible for having a lawful basis and equivalent terms in place with them.
2. Your Instructions
We process personal data only to deliver the services you bought, and only as instructed by you through the dashboard, the API, the SMTP interface, or a written request. Your use of the services is the instruction.
We will also process data where law requires it. If we are compelled to do something outside your instructions, we will tell you before doing so unless the law forbids that notification.
If an instruction from you appears to break data protection law, we will say so and may decline it.
3. What We Process
| Service | Categories of personal data | Data subjects |
|---|---|---|
| SMTP relay (LexLabMTA, Relay SMTP) | Recipient email addresses, sender identity, subject lines, message bodies and attachments, delivery and bounce metadata, IP addresses | Your recipients, your staff |
| Mailbox / email hosting | Mailbox contents, contacts, headers, authentication logs, access IPs | Your staff, anyone who mails them |
| VPS / RDP hosting | Whatever you choose to store or run on the server — we do not define or inspect it in normal operation | Determined entirely by you |
| Domain registration | Registrant, admin, and technical contact details as required by ICANN | You, or the registrant you name |
Processing lasts for as long as you hold the service, plus the retention windows in Section 8.
4. Special Category Data
The services are not designed for special category data under GDPR Article 9 — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation — nor for criminal offence data, payment card numbers, or government identifiers. Do not send it through LexLab without agreeing additional terms with us in writing first.
5. Confidentiality
Access to your data is limited to personnel who need it to run or support the service. They are bound by confidentiality obligations that survive the end of their engagement. We do not sell your data, and we do not use it to train models or build profiles.
6. Security Measures
We maintain technical and organisational measures appropriate to the risk, including:
- TLS in transit for web, API, and SMTP connections, with opportunistic TLS on outbound relay
- Encryption at rest on hosted storage where the underlying provider supports it
- Role-based access control, with administrative access restricted to named personnel
- Credential and API key isolation per client account
- Request-level filtering against injection and cross-site scripting at the application edge
- Logging of administrative access and abuse-relevant events
- Separation of client environments on hosted services
These measures change as threats change. We may replace a measure with an equivalent or stronger one without notice, and will not reduce the overall level of security during your term.
7. Subprocessors
You give general authorisation for us to engage the subprocessors below. Each is bound by data protection terms no less protective than this DPA.
| Subprocessor | Purpose | Processing location |
|---|---|---|
| Contabo GmbH | VPS and RDP infrastructure, server hosting | Germany / EU [PLACEHOLDER — confirm if any client servers sit in non-EU Contabo regions] |
| Namecheap, Inc. | Domain registration and registrar services | United States |
| Cloudflare, Inc. | DNS management for client domains | Global edge network |
| NOWPayments | Cryptocurrency payment processing | [PLACEHOLDER — confirm NOWPayments processing jurisdiction] |
| Telegram FZ-LLC | Order notifications and support messaging, where you choose to use it | United Arab Emirates / global |
| [PLACEHOLDER — add any other third party that touches client data: SMS gateway, monitoring, backup provider, SMM upstream, analytics] | ||
We will give you [PLACEHOLDER — notice period for new subprocessors, e.g. 30 days] notice before adding or replacing a subprocessor. If you have a reasonable data protection objection, tell us within that window and we will work to resolve it; if we cannot, you may terminate the affected service without penalty and receive a refund of the unused prepaid period.
8. Retention and Deletion
- While the service is live — data is retained for as long as you keep it there. You control deletion through the dashboard, the API, or by deleting it on your own server.
- On cancellation or termination — data is retained for [PLACEHOLDER — post-termination retention, e.g. 30 days] so you can export it, then deleted.
- Delivery logs and metadata — retained for [PLACEHOLDER — log retention, e.g. 90 days] for abuse investigation and deliverability troubleshooting.
- Backups — deleted data persists in backup media until the backup rotates out, up to [PLACEHOLDER — backup rotation period, e.g. 35 days].
- Legal holds — billing records and anything under a legal or law enforcement obligation are retained for the period the law requires, regardless of the above.
Ask for written confirmation of deletion and we will provide it.
9. Assisting You
We will help you meet your own obligations, taking into account what we can actually see:
- Data subject requests. If a recipient or end user contacts us directly, we forward the request to you and do not respond substantively ourselves. Where the data sits in a system only we can reach, we will help you locate, export, correct, or delete it.
- Impact assessments and prior consultation. We will provide the information we hold that you reasonably need.
- Audits. We will answer reasonable written questions about our processing and supply available documentation. On-site audits are by prior arrangement, no more than [PLACEHOLDER — audit frequency, e.g. once per year], at your cost, unless a regulator requires otherwise.
10. Personal Data Breach
If we become aware of a breach affecting your personal data, we notify you without undue delay and in any case within [PLACEHOLDER — breach notification window, e.g. 48 / 72 hours] of confirming it. Notification goes to your account email address — keep it current.
We will tell you what we know: what happened, which data and roughly how many records are involved, what we have done, and what we recommend you do. Early notification may be incomplete; we update as the investigation progresses. Reporting to your supervisory authority and to affected individuals is your responsibility as controller.
11. International Transfers
Some subprocessors are outside the EEA and the UK. Where personal data moves to a country without an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses, with the UK Addendum where UK data is involved. Those clauses are incorporated into this DPA by reference and apply automatically.
You can keep hosted workloads in the EU by choosing an EU region when you provision. Email delivery cannot be geographically constrained — messages go wherever the recipient's mail server is.
12. Liability and Term
This DPA runs for as long as we process personal data on your behalf. Liability under it is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms of Service on the handling of personal data, this DPA wins.
13. Contact
Data protection questions, DPA signature requests, subprocessor objections, and breach correspondence: support@lexlabtools.com.
[PLACEHOLDER — if LexLab has no EU/UK establishment and offers services to EU/UK data subjects, an Article 27 representative may be legally required. Confirm whether one is appointed and name them here.]