GDPR and data processing

Roles

For the contacts you upload, you are the data controller and Nordletter is the data processor. For your own account details we are the controller.

What we do as processor

We only process your contact data on your documented instructions, to deliver, measure and support your sending.

Confidentiality

Everyone with access is bound by confidentiality and access is limited to what the work requires.

Security

Data is encrypted in transit and at rest. Access requires strong authentication. We keep automatic backups, run restore tests and monitor for abuse around the clock.

Sub-processors

We use a limited set of sub-processors for hosting, sending and support. A current list is available on request, and we tell you before adding a new one.

Data subject requests

The tools inside Nordletter let you find, export, correct and delete an individual contact. We help you answer requests you cannot answer yourself.

Breach notification

If a personal data breach occurs we notify you without undue delay with what we know and what we are doing.

Deletion

When the agreement ends we delete or return your contact data, apart from copies kept in backups for their normal retention period.

Data processing agreement

A signed data processing agreement is available on request from the privacy address in the footer.