Data processing agreement
How we handle your data when we have access to your systems. This agreement forms part of our terms of service.
Last updated: 27 September 2026
Scope and roles
ZeroSpams software runs on your own servers and uses your own email-sending account, so the personal data it collects stays under your control. This agreement applies only when ZeroSpams ("we", the processor) can access personal data on your systems ("you", the controller), for example while installing the software, testing it, or fixing a fault.
It is designed to meet article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the processor obligations of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). If you are established in the DIFC or ADGM, the equivalent provisions of those laws apply as well.
Details of the processing
| Subject matter | Installing, configuring, testing and fixing ZeroSpams software on your systems. |
|---|---|
| Duration | Only while we have access to your systems for that work. |
| Data subjects | Visitors who submit, or try to submit, forms on your websites; people who exchange messages with you through the mail system; your staff who use it. |
| Personal data | Whatever is stored in the installation: form contents, IP addresses and derived country, browser and device details, how visitors arrived, messages and attachments, email delivery status, and staff names and email addresses. |
| Purpose | Only to carry out the work described in your quote, or a fix you asked for. |
Our obligations
- We process personal data only on your documented instructions (these terms, your quote and your written requests), unless the law requires otherwise; in that case we'll tell you first unless the law forbids it.
- We look at personal data only as far as the work requires. Where we can, we test with made-up data.
- We don't copy personal data out of your systems, except where a fix can't be done otherwise; any copy is deleted as soon as the fix is done.
- Everyone on our team who has access is bound by confidentiality.
- We help you answer requests from data subjects and deal with security questions, as far as our work is concerned.
- We make available the information needed to show we meet this agreement.
Sub-processors
We don't use sub-processors for work on your systems. The software sends email through your own email-sending account and, if you enable it, looks up countries through your own ipinfo.io account. Those providers work for you, under your contracts with them.
Breaches
If we become aware of a personal data breach connected to our access or our work, we'll tell you without undue delay, and in any case within 48 hours, with what we know about its nature, the data and people affected, likely consequences, and what we're doing about it.
End of access
When the work is done, we tell you so that you can remove or change the access you gave us. We delete any passwords and any copies of your data that we hold.
Your obligations
You're responsible for having a lawful basis for the processing, for telling your visitors about it in your privacy notice, for collecting consent where the law requires it, and for the security of your servers and accounts.
Security measures
- Access to your systems only through the accounts you give us, over encrypted connections, and only by named members of our team.
- Passwords and access details stored in an encrypted password manager, and deleted when the work ends.
- Software installed with hashed admin passwords, sign-in throttling, automatic sign-out and partly hidden IP addresses in spam records.
- No personal data stored on our own computers beyond what a specific fix requires.