Data Processing Agreement
Last updated: 26 July 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms & Conditionsor other services agreement between you (the “Customer”) and Postelist (“Postelist”, “we”, “us”) (together, the “Agreement”). Postelist provides done-for-you private email infrastructure and deliverability services for established senders (the “Service”). This DPA applies whenever we process personal data on your behalf to deliver the Service. Postelist is established in Hong Kong and operates globally. Where processing falls within Article 28 of the EU or UK GDPR, this DPA is the written contract required by that Article.
The core commitment
For the sending, domain, and contact data you provide or authorize us to process in running your infrastructure (“Customer Data”), you are the controller and Postelist is your processor. We process Customer Data only on your documented instructions and only to deliver the Service — never for our own purposes, and never to build a profile of, or market to, your contacts.
1. Definitions & roles
“Data Protection Laws” means all laws that apply to the processing under this DPA, including the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”), the EU General Data Protection Regulation and the UK GDPR, the California Consumer Privacy Act, and the Australian Privacy Act. “Controller”, “processor”, “data subject”, “personal data”, and “processing” have the meanings given in those laws.
Customer Data (we are your processor). When we operate your email infrastructure, you are the controller of the personal data you route through or entrust to the Service, and Postelist acts as your processor on your instructions, as set out in this DPA.
Our own account & enquiry data (we are a controller). The information you give us when you apply, book a call, communicate with us, or set up billing is processed by Postelist as an independent controller and is governed by our Privacy Policy, not this DPA.
2. Details of the processing
- Subject matter. Postelist’s processing of Customer Data to provide the Service.
- Duration. The term of the Agreement, plus the limited period needed to return or delete Customer Data on termination.
- Nature & purpose. Hosting, configuring, sending, routing, authenticating, warming, and monitoring email on your behalf, and the related storage and deliverability telemetry required to operate your infrastructure.
- Categories of data subjects. Your recipients, contacts, and personnel whose personal data you choose to route through or provide to the Service.
- Categories of personal data. Business and personal contact details you provide or authorize — such as names, email addresses, sending domains, and engagement or deliverability signals. You control what is included and are responsible for not sending special-category data through the Service.
3. Our obligations as processor
Postelist will:
- process Customer Data only on your documented instructions, including the Agreement and this DPA, unless required to do otherwise by law — in which case we will tell you first, where legally permitted;
- promptly inform you if, in our opinion, an instruction infringes Data Protection Laws;
- ensure that personnel authorized to process Customer Data are bound by confidentiality;
- implement and maintain the security measures described in Section 5; and
- assist you, taking into account the nature of the processing, with your obligations to respond to data subjects, secure the data, notify breaches, and carry out data protection impact assessments and prior consultations.
4. Confidentiality
We treat Customer Data as confidential. We limit access to those personnel and sub-processors who need it to deliver the Service, and we bind them to confidentiality obligations at least as protective as those in the Agreement.
5. Security measures
Taking into account the state of the art and the nature of the data, Postelist maintains appropriate technical and organizational measures to protect Customer Data, including:
- encryption of data in transit, and encryption at rest where appropriate;
- access controls, least-privilege permissions, and authentication for systems that process Customer Data;
- network and infrastructure hardening, monitoring, and separation between clients;
- regular review of our own and our sub-processors’ safeguards; and
- procedures to detect, respond to, and recover from security incidents.
No system is perfectly secure, but we work to protect Customer Data and to respond quickly to incidents. Report any security concern to security@postelist.com.
6. Sub-processors
You give Postelist general authorization to engage sub-processors to help deliver the Service. We impose data-protection terms on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. The sub-processors that may process Customer Data, depending on your Service configuration, include our:
- Hosting & cloud infrastructure providers — running the servers and systems that operate your email infrastructure.
- DNS, network, and delivery providers — routing, authenticating, and delivering email and managing sending reputation.
- Stripe — payment processing for your billing details.
A fuller list of the providers Postelist works with, including those that support our own communications and operations, is in our Privacy Policy. We will give you a reasonable way to learn of intended changes to the sub-processors handling Customer Data and, where Data Protection Laws require, an opportunity to object. If you reasonably object on data-protection grounds, we will work with you in good faith to address the concern; if we cannot, you may terminate the affected Service.
7. International transfers
Postelist is based in Hong Kong and works with sub-processors that operate in multiple jurisdictions, so Customer Data may be processed outside the country where you or your data subjects are located. Where Customer Data is transferred across borders, we rely on appropriate safeguards — such as the recipient’s adequacy status or contractual protections including the applicable standard contractual clauses — which you authorize us to enter into on your behalf where reasonably required.
8. Data subject requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. If we receive such a request directly regarding Customer Data, we will not respond to it ourselves (except to confirm it should be directed to you) and will forward it to you without undue delay.
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably available to help you meet your own notification obligations. We will take reasonable steps to contain and remediate the breach.
10. Return & deletion
On termination or expiry of the Agreement, and at your choice, Postelist will return or delete Customer Data and delete existing copies within a reasonable period, unless retention is required by law. Backups are deleted on their ordinary rotation cycle.
11. Audits & information
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once a year (or as required following a breach or by a regulator), allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate — subject to reasonable confidentiality and security conditions and without disrupting our other clients.
12. Your obligations as controller
You are responsible for establishing a lawful basis for the personal data you route through the Service, for obtaining any required consents, for honouring opt-outs and unsubscribe requests, and for ensuring your instructions to us comply with Data Protection Laws. You will not send special-category data or data relating to children through the Service.
13. Liability, order of precedence & governing law
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA governs the processing of Customer Data; for that processing it prevails over any conflicting term in the Agreement, and the Agreement otherwise continues in full force. This DPA is governed by the laws of the Hong Kong Special Administrative Region, except where Data Protection Laws require otherwise for a specific transfer or obligation.
14. Changes & contact
We may update this DPA from time to time to reflect changes in the Service or the law; we’ll revise the date above and, for material changes, take reasonable steps to let you know. Questions about this DPA or requests relating to Customer Data go to privacy@postelist.com. This DPA sits alongside our Terms and Privacy Policy.