Relaytera
ProductsEmail hostingcPanel hostingDevelopersPricing
Log inGet started
Menu
ProductsEmail hostingcPanel hostingDevelopersPricing
Log inGet started
Trust & legalPolicy centre
All policies
DPA · 2026-08-06

Data Processing Addendum

This DPA supplements the Terms when Relay processes personal data for a customer as processor or service provider.

Operator
Relaytera
Effective
6 August 2026
Version
2026-08-06
Operator details, recorded legal approval, and the published subprocessor register are present.
On this page
  1. Instructions and compliance
  2. Confidentiality and security
  3. Subprocessors and transfers
  4. Requests, assessments, and incidents
  5. Return, deletion, and audit
  6. Processing details
  7. Contact and precedence

1. Instructions and compliance

Relay will process customer personal data only to provide and secure the service, follow the agreement and documented customer configuration, or comply with law. Relay will notify the customer if an instruction appears unlawful unless prohibited from doing so.

The customer is responsible for lawful instructions, notices, permissions, and a valid basis for the data submitted to Relay.

2. Confidentiality and security

Personnel authorised to process customer data are bound by confidentiality. Relaytera's technical and organisational measures are described in the Security Overview and include applicable identity/access controls, tenant scoping, encryption in transit, protected secrets, audit records, backup/recovery controls, and release gates. A description of a control is not a guarantee that every staged feature is enabled for every service or account.

3. Subprocessors and transfers

The customer gives general authorisation for subprocessors actually needed to deliver the service, subject to equivalent data-protection obligations. Before production customer processing begins, Relaytera must publish an accurate Subprocessor Register and a practical change-notice mechanism for material changes.

For a restricted international transfer that Relaytera initiates, Relaytera must use an applicable transfer mechanism and make the relevant safeguard information available on reasonable request, subject to confidentiality and security limits.

4. Requests, assessments, and incidents

Taking account of the nature of processing, Relay will reasonably assist customers with data-subject requests, risk assessments, regulator consultations, and evidence of compliance. The customer remains responsible for responding as controller.

Relay will notify the designated customer contact without undue delay after confirming a personal-data breach affecting customer data and will provide available information needed for the customer’s duties. Notification is not an admission of fault.

5. Return, deletion, and audit

During the service, available export and deletion controls may be used. Relay control-plane export does not include cPanel website/database content or Relay Mail mailbox contents; customers must use the relevant hosting, IMAP, or JMAP export path. At termination, Relaytera will handle data according to the agreement, product-specific retention/deletion process, protected backup rotation, and legal obligations.

Relay will make relevant security and compliance information available and support a reasonable audit process. Audits must protect other customers, security, and confidentiality, avoid unnecessary disruption, and use existing independent reports first when available.

6. Processing details

  • Subject matter: Relay outbound email delivery; Relay Hosting (cPanel) hosting and mail where selected; Relay Mail mailbox hosting where separately released; related customer administration, security, support, and service operations.
  • Duration: the agreement plus configured retention, including the published retained-service and backup windows — up to 30 days by default for a cancelled Relay Hosting service and up to 30 days by default for a Relay Mail mailbox after a confirmed deletion request.
  • Data subjects: customer users, recipients, senders, contacts, and people represented in customer content or support records.
  • Data types: contact and account details, message content and metadata, delivery events, hosting and mailbox data where selected, identifiers, diagnostics, and customer-supplied attributes.
  • Sensitive data: not intentionally required; customers must not submit it unless expressly agreed with appropriate safeguards.

7. Contact and precedence

Privacy and DPA enquiries may be sent to support@relaytera.com. If this DPA conflicts with the Terms on processor obligations, this DPA controls for that conflict. Customer-specific transfer modules or commercial terms require a signed order.

PreviousAcceptable useNextSecurity
Relaytera

Mailbox hosting, cPanel websites, and the outbound Relay API stay on separate products.

Built for clear operational boundaries
Products
Email hostingcPanel hostingTransactional email APIPricing
Developers
Quick startAPI referenceWebhooksVersion policy
Company
support@relaytera.comSupport formTrust centreTermsPrivacyLog in
© RelayteraCustomer-owned domains · documented product boundaries