This DPA applies where Imapost processes personal data on behalf of a customer subject to GDPR, UK GDPR, or CCPA/CPRA. It is incorporated by reference into our Terms of Service.
Roles
Customer is the Controller. Imapost is the Processor.
Security
Encryption in transit and at rest, workspace-level RLS, RBAC, least-privilege, audit logging, incident response, and quarterly access reviews.
International transfers
Where personal data is transferred outside the EEA/UK, transfers rely on the EU SCCs and, where applicable, the UK IDTA.
Sub-processors
Supabase, Vercel, Stripe, Razorpay, OpenAI, Google (Gemini), Anthropic (Claude), and the social platforms customers connect.