DATA PROCESSING AGREEMENT
made on 2024-08-01
Customer (“You”) hereinafter referred to as “Controller”, and
EnovaPoint, UAB, a private company with limited liability, incorporated under the laws of Lithuania, having its statutory seat in Vilnius and its principal place of business at P.Vileisio str. 19a-43, Vilnius 10300, Lithuania, registered with the State Enterprise Centre of Registers under juridical person register code 300691229; hereinafter referred to as “Processor”,
referred to collectively as “Parties”.
This Data Processing Agreement is incorporated in the Terms of Service Agreement hereinafter the “Principal Agreement” regarding the JungleMail for Office 365 (Newsletter Platform) hereinafter the “Service”
1. Introduction
This Data Processing Agreement (“DPA”) is made as of and for the duration of the Principal Agreement by and between the Parties. This DPA is applicable in relation to the Principal Agreement.
Save as provided in the Principal Agreement, the Controller and the Processor have concluded this DPA for the Processing of Personal Data.
A description of the Service is included in Schedule 1.
Organizational and technical measures taken by the Processor are described in Schedule 2.
An overview of the type of Personal Data, categories of data subjects, the purpose of Processing is included in Schedule 3.
This DPA forms an integral part of the Principal Agreement. This DPA is effective upon and subject to the conclusion of the Principal Agreement by both Parties.
The duration, term and termination of this DPA follow the term of the Principal Agreement. Terms not defined herein shall have the meaning as set forth in the Principal Agreement or within the relevant Data Protection Laws.
The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the General Data Protection Regulation (GDPR), as well as the Swiss and UK Data Protection laws.
Within the scope of the Agreement and in its use of the Services, Customer as a Data Controller will be responsible for complying with all requirements that apply to it under applicable Data Protection Laws, including but not limited to the General Data Protection Regulation (GDPR), as well as the Swiss and UK Data Protection laws, with respect to its Processing of Personal Data and the Instructions it issues to EnovaPoint.
The Controller represents and warrants that it has obtained all necessary rights and consents under applicable law to disclose to Processor — or allow Processor to collect, use, retain and process — any Personal Data that it provides to Processor or authorizes Processor to collect, including information that the Processor may collect directly from the Controller’s end users via usage of the Service or other mean.
In consideration of the Principal Agreement, the Parties hereto agree as follows.
2. Definitions and Interpretation
Unless otherwise defined herein, capitalized terms and expressions used in this DPA shall have the following meaning:
- “Customer” means the company or organization who has accepted the Principal Agreement. Customer has access to User Management at all times and can assign Service Licenses to any Service Users;
- “Customer’s Data” means any digital data, files and information, which is subjected to the Services or otherwise inserted to the Service by Customer (including the specific users, recipients, activities, templates, images, email content, and other data associated with the Customer);
- “Controller” shall mean the company or organization that determines the purposes and means of the Processing of Personal Data; in accordance with the EU Data Protection Laws and/or Swiss Data Protection Laws;
- “Processor” shall mean the company that processes Personal Data on behalf of the Controller;
- “Personal Data” means any information relating to an identified or identifiable individual where such information is contained within Customer’s Data and is protected similarly as personal data, personal information or personally identifiable information under applicable Data Protection Laws.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by Processor and/or its Sub-Processors in connection with the provision of the Services. “Personal Data Breach” will not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems;
- “Data Protection Laws” means the GDPR, EU, Swiss, UK Data Protection Laws and, to the extent applicable, the data protection or privacy laws of any other country;
- “GDPR” means EU General Data Protection Regulation 2016/679;
- “Sub-processor” means any person appointed by or on behalf of the Processor to process Personal Data on behalf of the Controller in connection with the Principal Agreement.
- “Controller Instructions” means the directives given by the Controller to the Processor regarding the processing of Personal Data, encompassed within the Principal Agreement (including this DPA), and the use of the Service, constitute the Customer’s complete and final Instructions to EnovaPoint in relation to the Processing of Personal Data, and any additional Instructions outside the scope of the Instructions shall require prior written agreement between the parties.
Lower case terms used but not defined in this DPA, such as “processing”, “profiling”, “sensitive personal data”, and “data subject” will have the same meaning as set forth in Article 4 of the GDPR, irrespective of whether GDPR applies, and their cognate terms shall be construed accordingly.
3. Processing of Personal Data
Processor acknowledges that for the purposes of Data Protection Laws, the Controller is the Controller of Personal Data, and the Processor is the Processor of such data. In situations where the Controller acts as a Processor of Personal Data, the Processor acknowledges its role as a Sub-processor, unless stated otherwise in the Principal Agreement or this DPA.
The Processor shall:
- comply with all applicable Data Protection Laws in the Processing of Personal Data; and
- process Personal Data strictly in accordance with the Controller’s instructions, unless required by law to act without such instructions.
The Controller instructs the Processor to process Personal Data in relation to and for the execution of the Principal Agreement. The Processor agrees to process Personal Data exclusively for the purposes outlined in this DPA and the Principal Agreement. The Processor guarantees that it will not use the Personal Data that it processes in the context of this DPA for its own or third-party purposes without the Controller’s express written consent, unless a mandatory legal provision requires the Processor to do so. In such case, the Processor shall immediately inform the Controller of that legal requirement before processing such information, unless the law explicitly prohibits such disclosure.
The Parties agree that the Service is not intended for the Processing of Sensitive Personal Data, and, as such, the parties do not anticipate the transfer of Sensitive Personal Data.
4. Disclosure of Personal Data
The Processor will not disclose Personal Data except:
- as the Controller directs;
- as described in this DPA; or
- as imposed by mandatory legal provisions.
The Processor will not disclose Personal Data to law enforcement bodies unless required by law. If law enforcement contacts Processor with a demand for Personal Data, Processor will attempt to redirect the law enforcement agency to request that data directly from The Controller. If compelled to disclose Personal Data to law enforcement, the Processor will promptly notify the Controller and provide a copy of the demand unless legally expressly prohibited from doing so.
Upon receipt of any other third-party request for Personal Data, the Processor will promptly notify the Controller unless prohibited by law. The Processor will reject the request unless required by law to comply. If the request is valid, the Processor will attempt to redirect the third party to request the data directly from the Controller.
The Processor will not provide any third party:
- direct, indirect, blanket, or unfettered access to Personal Data;
- encryption keys used to secure Personal Data or the ability to break such encryption; or
- access to Personal Data if the Processor is aware that such data is to be used for purposes other than those stated in the third party’s request.
In support of the above, the Processor may provide the Controller’s basic contact information to the third party.
5. Processor Personnel
The Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Sub-processor who may have access to Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with applicable laws in the context of that individual’s duties to the Processor. The Processor will further ensure that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality
6. Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall in relation to the Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR, irrespective of whether GDPR applies.
In assessing the appropriate level of security, the Processor shall take into account in particular of the risks that are presented by the processing, in particular from a Personal Data Breach.
Organizational and technical measures taken by the Processor are described in Schedule 2.
7. Data Transfer
The Processor partners with Microsoft Azure to provide cloud hosting services and will store Customer’s Data at rest in one of available Microsoft Azure datacenters (e.g. Netherlands (EU), UK, US, CA, AU) selected by the Controller.
For the Service, the Processor will process Customer’s Data in Controller selected location and other countries used by sub-processors (who are GDPR-compliant), depending on the Controller’s settings.
Where Customer is based in the Switzerland or European Economic Area (EEA), it is recommended to select a hosting location within the EEA (for example, EU, UK) for their data processing and storage. Processor may not transfer or authorize the transfer of Data to countries outside the selected region without the prior written consent of the Controller.
If Personal Data processed under this DPA is transferred from Switzerland or a country within the EEA to a country outside the EEA, the Parties shall ensure that the personal data are adequately protected. To achieve this, the Parties shall, unless agreed otherwise, rely on EU approved Standard Contractual Clauses (SCC) for the transfer of Personal Data. If for any reason Processor cannot comply with its obligations under the SCC or is in breach of any warranties under the SCC, and Controller intends to suspend the transfer of European Client Data to Processor or terminate the SCC, Controller agrees to provide Processor with reasonable notice to enable Processor to cure such non-compliance and reasonably cooperate with Processor to identify what additional safeguards, if any, may be implemented to remedy such noncompliance. If Processor has not or cannot cure the non-compliance, Controller may suspend or terminate the affected part of the Service in accordance with the Terms of Service.
8. Subprocessors
Controller grants Processor a general authorization, in accordance with Article 28 (2) of Regulation (EU) 2016/679, to engage Sub-Processors for the purposes of providing the Services.
The Sub-Processors listed in https://www.enovapoint.com/legal/sub-processors at the time of the conclusion of this Addendum shall be deemed authorized by Controller.
The Processor shall provide the Controller with prior notification of the intention to appoint any new Sub-Processor, regardless of whether such new Sub-Processor is appointed for an existing or a new processing function. Upon receiving notice of the Processor’s intention to engage a new Sub-Processor, the Controller may object to such engagement by promptly notifying the Processor in writing via email at support@enovapoint.com within ten (10) business days after receipt of the Processor’s notice.
In the event that Controller objects to the use of any Sub-Processor, Processor will recommend to Controller commercially reasonable changes in the configuration or use of the Services to avoid processing of Personal Data by the proposed Sub-Processor. If Processor is unable to assist Controller with its objection regarding engagement of a Sub-Processor within a reasonable period of time which shall not exceed thirty (30) days, Controller may, upon written notice to Processor, terminate the Services in accordance with the Terms of Service.
Processor may only engage third-party Sub-Processors in connection with the provision of Services, if Processor:
- Has entered into a written agreement with the Sub-Processor containing data protection obligations no less protective than those in this DPA with respect to Personal Data.
- Ensures that an adequate level of data protection for Sub-Processors that are located outside of the EU/EEA exists or is created (e.g., by concluding Processor-to-Processor EU Standard Contractual Clauses).
- Sub-Processor’s access is restricted to only what is necessary to maintain the Services or to provide the Services to customers.
The Processor, when engaging and substituting Sub-Processors, shall: (a) remain responsible to the Controller for the provision of the Services and (b) be liable for the actions and omissions of its Sub-Processors undertaken in connection with Processor ’s performance of this DPA to the same extent Processor would be liable if performing the Services directly.
9. Data Subject Rights
Taking into account the nature of the processing, the Processor shall assist the Controller by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller obligations, as reasonably understood by the Controller, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
The Processor shall:
- promptly notify the Controller if it receives a request from a Data Subject under any Data Protection Law in respect of Personal Data; and
- ensure that it does not respond to that request except on the documented instructions of the Controller or as required by Applicable Laws to which the Processor is subject, in which case the Processor shall to the extent permitted by Applicable Laws inform the Controller of that legal requirement before the Processor responds to the request.
10. Personal Data Breach
If the Processor becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Controller Data or Personal Data while processed by the Processor (each a “Security Incident”), the Processor without undue delay, and in any event within 48 hours, will notify the Controller of the Security Incident, investigate the Security Incident and provide the Controller with detailed information about the Security Incident and take reasonable steps to mitigate the effects and to minimize any damage resulting from the Security Incident. Such notice may be provided by posting a notification in the Service app; by sending an email to the Contact Person provided in the Service; and/or additionally, to the email addresses of Service licensed Users. The Controller shall ensure that its contact information is current and accurate at all times during the terms of this DPA.
The Processor shall make reasonable efforts to assist the Controller in fulfilling its obligation under applicable laws to notify the relevant authorities and data subjects about such Security Incident.
The Processor’s notification of or response to a Security Incident under this section is not an acknowledgement by the Processor of any fault or liability with respect to the Security Incident.
The Controller is obligated to promptly notify the Processor about any possible misuse of its accounts, authentication credentials, or any security incident related to the Service.
11. Data Protection Impact Assessment and Prior Consultation
The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which the Controller reasonably considers to be required by the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to the processing of Personal Data by, and taking into account the nature of the processing and information available to, the Processor.
12. Deletion or return of Personal Data
Upon termination of the Principal agreement and/or DPA, Processor will initiate a process that deletes the personal data in accordance with our standard backup and retention policy or in accordance with Controller’s written request. This requirement shall not apply to the extent Processor is required by the applicable law to retain some or all of the Personal Data, or to Personal Data it has archived on back-up systems, which Personal Data Processor shall securely isolate and protect from any further processing, except to the extent required by applicable law. If the Controller terminates the Services but does not give any Instructions, then normal data retention period applies.
13. Audit rights
The Processor shall allow for and not interfere with audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, to verify compliance with the terms of this DPA and the applicable data protection laws. Such audits may be conducted no more than once in any 12-month period, except where required due to a Customer Data Breach or by a competent Supervisory Authority, at the Controller’s expense, and upon at least 30 days prior notice.
The Processor shall provide reasonable assistance and access to all information, systems, and facilities as may be reasonably necessary for the purpose of such audits.
The controller shall protect the confidentiality of all information obtained through such audits, and provide any written audit report to the Processor or notify the Processor of any non-compliance discovered during the audit.
14. General Terms
Each of the Controller, Processor and/or Sub-processor must keep any information it receives confidential according to the relevant confidentiality provisions set forth in the Principal Agreement.
Notwithstanding the foregoing, in addition to the applicable provisions set forth in the Principal Agreement, all notices and communications given under this DPA must be in writing and will be sent by email. The Controller shall be notified by email sent to the Account Owner’s email address provided in the Service. The Processor shall be notified by email sent to the address: support@enovapoint.com.
Regarding the termination of this DPA the specific provisions of the Principal Agreement apply.
15. Governing Law and Jurisdiction
The choice of law and competent court comply with the applicable provisions of the Principal Agreement.
If you would like to sign the document, please send an email to support@enovapoint.com
Schedule 1: Service Description
JungleMail for Office 365 (JungleMail 365) is an email service app for the Microsoft 365 platform, hosted in Microsoft Azure and distributed through the Microsoft 365 app store (AppSource) or provided directly by EnovaPoint together with its related services.
JungleMail 365 is designed to enhance internal communications by quickly creating personalized, engaging email newsletters and reviewing analytics. Additional features include:
- Direct sending to Azure AD groups and Distribution Lists.
- Easy-to-use Drag & Drop builder with pre-made, customizable templates.
- Integration with SharePoint to populate newsletters with content.
- Targeted newsletters based on recipients’ subscription preferences and employee data.
- Personalized emails with dynamic content.
- Comprehensive newsletter analytics to track and enhance engagement.
- Click Map feature to optimize newsletter structure by tracking interaction.
- Archiving newsletters directly in SharePoint.
- Real-time collaboration with co-authoring and live chat.
- Branded colors and fonts to strengthen visual identity.
- Scheduled email campaigns to optimize time management.
- Tailored content targeting specific employee groups to increase relevance.
- Privacy enhancement by replacing email addresses with pseudonyms using Analytics Pseudonymization.
Schedule 2: Technical and Organizational Measures
Security
- Dedicated Security Team
- Physical Security at HQ
- Protection of equipment
- Data encryption at rest and in transit
- Penetration testing conducted by the third party
- Certifications & attestations
- Security program is covered by the ISO 27001 and SOC 2
- Periodic mandatory education and awareness for all personnel and hired staff
Privacy
- Assigned Data Protection Officer
- Established Privacy Policy
- Vendor Due Diligence
- Periodic data privacy awareness and mandatory education for all employees and hired personnel
Compliance
- Vendor Due Diligence
- Pre-employment screening on personnel and similar requested from our sub-contractors
Service Infrastructure
- The Processor servers are hosted in England in UK South Microsoft Azure Datacenter.
- Security through strict IP whitelisting and logical controls for data segregation
- Tested and implemented Business Continuity and Disaster Recovery plan based on Business Impact Analysis
Backups
- Backup and Retention Policy
- Point in Time restore backups will be kept for 35 days.
- Differential backups occur every 12 hours.
- Storage replication type: Geo-redundant storage.
- Backup restoration testing is performed at least annually to help ensure the recoverability of application data
Personnel
- Numerous polices including Code of Conduct and Information Security Policy including:
- Non-Disclosure Agreements (including third parties)
- Clear procedures on reporting incidents to security & privacy team
- Clean Desk policy
Schedule 3: Overview of Personal Data
The subject matter of the Processing of the Personal Data is set out in the Principal Agreement and this DPA.
The duration of the Processing shall be in accordance with the Principal Agreement, the Controller’s instructions and the terms of this DPA.
Nature of the processing: Customer Data will be processed in accordance with the Principal Agreement, and this DPA, and may be subject to the following processing activities:
- Storage and other Processing necessary to deliver, maintain and improve the Services provided to the Controller; and/or
- Disclosure in accordance with the Principal Agreement (including this DPA) and/or as compelled by applicable laws.
Purpose of the transfer and further processing: Processor will Process Customer Data as necessary to provide the Services pursuant to the Principal Agreement, and as further instructed by Controller in its use of the Services.
The categories of Data Subjects are:
- “Users” – any individual accessing and/or using the Services through the Customer’s account.
- “Recipients” – usually Customer’s employees, or partners, in some cases external recipients, to whom Users send emails or otherwise engage via the Service.
Types of Customer Data which may include personal data:
Controller may upload, submit, or otherwise provide certain personal data to the Service. The extent of this data is typically determined and controlled solely by the Controller and may include the following types of personal data:
- Account Owner Information (Contact Person): First and Last name, Email address.
- Billing information: Billing address, billing email address, payment information.
- Service Users: Microsoft 365 (Entra ID) profile data, which may include first and last name, email address, login name, Entra ID’s user Id, SharePoint user id.
- Sending accounts: configured by Users sending email addresses for email delivery.
- Internal Recipients: Controller’s employees’ contact data, such as first and last names, email addresses, job titles, departments, countries, and other Microsoft 365 user profile data used in the newsletter, subscription preferences, and any other additional information that the Controller provides to the Service. This data can be used for mail merge, newsletter analytics, and for targeted content delivery.
- External Recipients: Controller’s external recipients’ (if any) contact data as email addresses and other personal data used in the newsletter. This data can be used for mail merge, newsletter analytics, and for content delivery
The Customer acknowledges that in connection with the performance of the Services, Processor employs the use of unique identifiers, web beacons and similar tracking technologies. For internal recipients the Controller issues the email addresses to employees with the expectation they will receive company email, so no explicit consent is required as it is a legitimate interest of the business. However, if Customer will use the Service to send emails to external recipients, the Customer as Data Controller shall maintain appropriate notice, consent, and other mechanisms as are required by Data Protection Laws to enable Processor to deploy previously mentioned tracking technologies lawfully on and collect data from the devices of such recipients.
Revision history
The prior Data Processing Agreement valid until 1 August 2024 is available here.
The prior Data Processing Agreement valid until 20 January 2023 is available here.