Data Processing Addendum
Last updated: July 24, 2026 (draft, not yet in effect)
This Data Processing Addendum (“DPA”) is incorporated into the Cocomail Terms of Serviceand is available to every customer whose processing of subscriber personal data through Cocomail requires processor terms: for example, where a subscriber list includes people whose data is protected by EU/EEA or UK data protection law. Where it applies, the customer (“you”) is the controller and Cocomail (cocomail.cc), operated by Panara Studio LLC (8 The Green, STE B, Dover, DE 19901), is the processor. This DPA itself requires no signature (it is incorporated through the Terms), and a countersigned copy is available on request via [email protected]. The Standard Contractual Clauses described in Section 6 are different: where they apply, they must be separately executed (see Section 6).
As controller, you are responsible for your lawful basis, the jurisdictions of your recipients, your collection notices, your direct-marketing compliance, and your tracking instructions (including the audience declaration and per-newsletter tracking confirmation the product records). You must not use Cocomail to process special categories of personal data (see Annex I) without our prior written agreement. Cocomail does not determine subscriber geography and processes subscriber data only as described here.
1. Subject matter and duration
Processing of your subscriber data to provide the Cocomail newsletter service, for as long as you hold an account, until deletion or return under Section 8.
2. Processing on documented instructions
We process subscriber data only on your documented instructions (your use of the product (imports, sends, tracking settings, exports, deletions) constitutes those instructions) and never for our own purposes, except where applicable law to which Cocomail is subject requires otherwise. In that case we inform you of the legal requirement before processing, unless the law prohibits us from doing so. We will tell you if we believe an instruction violates data protection law.
3. Confidentiality and security
Persons authorized to process subscriber data are bound by confidentiality. We implement the technical and organisational measures in Annex II and assist you, taking into account the nature of processing, with your own security, breach-notification and impact-assessment obligations (Art. 32–36 GDPR). We notify you without undue delay after becoming aware of a personal data breach affecting your subscriber data.
4. Data subject rights
Taking into account the nature of the processing, we assist you with appropriate technical measures to fulfil data-subject requests: self-serve export, contact deletion, and unsubscribe links that are honored immediately. Requests we receive directly from your subscribers are ordinarily forwarded to you as the responsible controller, unless applicable law requires us to handle them ourselves.
5. Subprocessors
You authorize the subprocessors listed in Annex III: the vendors engaged in processing subscriber data on our behalf. (Vendors that process only our own website or customer data, such as our consent-gated website analytics, appear in the Privacy Policy but are not subprocessors of subscriber data.) We will give at least 30 days' notice (by email or in-app notice) before adding or replacing a subprocessor; if you reasonably object on data-protection grounds and we cannot offer an alternative, you may terminate the affected service and receive a pro-rata refund of prepaid fees. We remain fully liable for our subprocessors and impose data-protection obligations equivalent to this DPA on each of them.
6. Processing locations and international transfers
Cocomail processes subscriber data in the United States: the application backend and database run on Convex (AWS us-east-1, N. Virginia), email delivery runs on AWS SES/SNS (us-east-1), and the application is hosted on a Hostinger VPS in Boston, Massachusetts. In addition, Panara Studio LLC is administered from India, and authorized personnel may access customer and subscriber data from India for support, security and operations. The service is not EU-hosted, and this DPA does not present any hosting location as a transfer safeguard in itself.
Where and only where the GDPR or UK GDPR legally applies to a transfer of personal data to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), Module 2 (controller → processor) and, where you act as processor for your own clients, Module 3 (processor → processor), are available for execution with us on request via [email protected], together with the UK Information Commissioner's Addendum to the EU SCCs (version B1.0) for transfers of UK personal data. This page is not itself an executed set of Standard Contractual Clauses: the clauses take effect between the parties only once entered into with the applicable modules and options selected, the annexes completed (the Annexes below supply the starting information), and any required signatures in place. Even then, executing the clauses does not by itself complete every transfer requirement: assessments and supplementary measures may also be needed for a given transfer. This DPA does not claim that any particular transfer safeguard applies to every customer or every data flow; customers whose processing requires SCCs or the UK Addendum should request execution via [email protected].
7. Audits
We make available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR and allow audits, normally satisfied by our documentation and vendor attestations; on-site audits require 30 days' notice, at most once per year, at your cost, without access to other customers' data.
8. Deletion and return
You can export subscriber data at any time. On account deletion, we delete subscriber data from active systems as described in the Privacy Policy (access disabled immediately, deletion begins immediately), unless applicable law to which Cocomail is subject requires continued storage, in which case we retain only what and for as long as that law requires, and tell you where legally permitted. Import/export files are additionally deleted 30 days after each job completes.
Annex I: Description of processing
- Parties: data exporter, the customer identified by their Cocomail account; data importer, Panara Studio LLC, 8 The Green, STE B, Dover, DE 19901, [email protected].
- Data subjects:the customer's newsletter subscribers and contacts.
- Categories of data: email address, first name, last name, tags/segments, subscription status and source, engagement events (opens, clicked URLs, user agent), bounce and complaint records.
- Special categories (Art. 9 GDPR): none are intended, and you must not process special-category data through Cocomail without our prior written agreement. Note that a tag, segment or list can itself reveal a special category (for example, a list defined by health condition, religious affiliation, political opinion or sexual orientation), and this prohibition covers such indirect processing too.
- Frequency: continuous, for the duration of the account.
- Retention: per Section 8 and the Privacy Policy.
- Processing locations: United States (Convex on AWS us-east-1, N. Virginia; AWS SES/SNS us-east-1; Hostinger VPS, Boston, Massachusetts), with authorized operational access from India (Section 6).
- Competent supervisory authority:determined by the exporter's establishment. This page does not designate a fixed default authority.
Annex II: Technical and organisational measures
- Encryption in transit (TLS) for all traffic.
- Passwords stored only as salted hashes; card data handled entirely by Stripe.
- Tenant isolation: every query is scoped to the owning account; per-tenant sending reputation isolation.
- Access control: production access limited to operating personnel; secrets kept in deployment configuration, not code.
- Administrative-access audit: any operator access to a customer account through the support tooling is logged (operator, account, start/end timestamps: no account content) for support, security, accountability and investigation of unauthorized access; records are retained 12 months, then deleted automatically.
- Automatic deletion: 30-day retention on import/export files; complete tenant purge on account deletion with an orphaned-file sweep: access disabled immediately, purge starts immediately and continues without intentional delay until tenant-scoped rows are gone. Excepted from the purge: the minimal administrative-access audit records above (retained for their fixed 12-month security period, then deleted) and any records applicable law requires us to keep (Section 8).
- Abuse controls: suppression lists, bounce/complaint monitoring with automatic pause, rate limiting.
- Backups: customer data resides in Convex (not on the Hostinger VPS application host). Convex platform backups follow Convex's published schedule: daily backups retained up to 7 days, weekly up to 14 days. The Hostinger VPS runs the Next.js application and does not store the customer database or subscriber lists, so it does not retain customer-data backups.
Annex III: Authorized subprocessors
The vendors that actually process subscriber data on our behalf:
- Convex: application backend and database (stores subscriber records, engagement events). United States (AWS us-east-1, N. Virginia).
- Amazon Web Services (SES/SNS): email delivery to subscribers; bounce and complaint events. United States (us-east-1).
- Hostinger: application hosting and request handling (subscriber opens, clicks, unsubscribe and subscribe requests transit it). United States (Boston, Massachusetts).
The following vendors serve Cocomail but are not subprocessors of subscriber data, because their data flows do not include it: Stripe (customer billing data), Google (customer sign-in data), Resend (Cocomail's own account and operational email to customers: password resets, alerts; subscriber-facing email such as opt-in confirmations is sent via AWS SES, not Resend), and DataFast (website analytics for site-visitor data, loaded only with cookie consent, for which we act as controller). This classification reflects our current product data flows; if a flow changes so that a vendor begins processing subscriber personal data on our behalf, we will update this Annex and give the notice required by Section 5.
Contact
Privacy and DPA questions: [email protected].