Legal

Data Processing Addendum

Last updated: July 27, 2026

This DPA applies where Imapost processes personal data on behalf of a customer subject to GDPR, UK GDPR, or CCPA/CPRA. It is incorporated by reference into our Terms of Service.

Roles

Customer is the Controller. Imapost is the Processor.

Security

Encryption in transit and at rest, workspace-level RLS, RBAC, least-privilege, audit logging, incident response, and quarterly access reviews.

International transfers

Where personal data is transferred outside the EEA/UK, transfers rely on the EU SCCs and, where applicable, the UK IDTA.

Sub-processors

Supabase, Vercel, Stripe, Razorpay, OpenAI, Google (Gemini), Anthropic (Claude), and the social platforms customers connect.

Contact

dpo@imapost.com