Skip to content

Data Processing Agreement

Last updated June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Controller”) and Pradsgaard Labs EMV (“day3”, “Processor”) and governs how day3 processes personal data on your behalf under the GDPR. By using day3 to send to subscribers you import, you accept this DPA.

1. Roles and scope

You are the Controller of the subscriber personal data you upload and send to. day3 is the Processor, acting only on your documented instructions — which include your configuration and use of the service. For account and billing data, Pradsgaard Labs EMV is the Controller and that processing is governed by our Privacy Policy.

2. Subject matter and duration

day3 processes personal data for as long as your account is active and for the limited period afterward described in clause 8. The subject matter is the provision of the day3 email service.

3. Nature and purpose of processing

Storing your audiences; sending the campaigns you create; recording delivery events (delivered, bounced, complained, unsubscribed); and presenting analytics back to you. day3 does not use your subscriber data for any purpose of its own.

4. Categories of data and data subjects

Data subjects: your subscribers and contacts.

Personal data: typically email address and any name or fields you choose to import, plus engagement and delivery events. You agree not to upload special categories of data unless you have a lawful basis to do so.

5. day3's obligations

  • Process personal data only on your documented instructions.
  • Ensure people authorised to process it are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (clause 6).
  • Assist you in meeting your own GDPR obligations (clause 7).

6. Security measures

day3 maintains appropriate technical and organisational measures — EU-only data residency, encryption in transit and at rest, least-privilege access, and managed backups — described on our Security page, which forms part of this DPA.

7. Sub-processing

You authorise day3 to engage the sub-processors listed on our sub-processors page. day3 imposes data-protection terms on each sub-processor no less protective than this DPA, remains liable for their performance, and will give notice of intended changes so you may object.

8. Assistance, breaches, return and deletion

  • day3 helps you respond to data-subject requests and, where relevant, with DPIAs and consultations.
  • day3 notifies you without undue delay after becoming aware of a personal data breach affecting your data.
  • On termination, day3 deletes or returns your personal data within a reasonable period, except where retention is required by law.

9. International transfers

day3 processes personal data within the EU. Where any transfer outside the EEA would occur, it is covered by an adequacy decision or Standard Contractual Clauses.

10. Audits

day3 makes available the information needed to demonstrate compliance with this DPA and will respond to reasonable audit requests, including by providing relevant third-party reports from its sub-processors.

Contact

To request a countersigned copy or raise a data-protection matter, email hello@day3.app.