Data processing terms
Last updated: 25 September 2026
These are the processor terms that apply when we process personal data on a customer's behalf. They are part of each product's Terms of Service and are copied here word for word, for customers who ask for a data processing agreement. They are not a separate agreement: the Terms of Service linked below are the binding text.
VibeKit
From VibeKit Terms of Service, Section 11. "Section" references in this part refer to the VibeKit Terms of Service. The sub-processors are listed on the sub-processors page.
This Section applies where we process personal data on your behalf as your processor (or "service provider") — mainly End-User Data. We will:
- process that personal data only to provide the Service and on your documented instructions, which consist of these Terms and your Customer Configuration, unless the law requires otherwise;
- not sell or share it, and not use it for any purpose other than providing, securing, and supporting the Service;
- ensure that people authorised to process it are bound by confidentiality;
- implement the security measures described in our Privacy Policy;
- use the sub-processors listed in our Privacy Policy, remain responsible for them, and update that list before adding a new sub-processor, so that you can object by closing your account;
- taking into account the nature of the processing, provide reasonable assistance with data-subject requests, security, and data-protection impact assessments;
- notify you without undue delay after becoming aware of a personal-data breach affecting that data;
- on your request, and on termination, delete that data within a reasonable period, except where retention is required by law; and
- make available information reasonably necessary to demonstrate compliance with this Section.
Where personal data is transferred out of the UK or EEA, the European Commission's Standard Contractual Clauses (and the UK Addendum) are incorporated by reference to the extent required. You authorise the sub-processors listed in the Privacy Policy.
ReMail
From ReMail Terms of Service, Section 11.3. "Section" references in this part refer to the ReMail Terms of Service. The sub-processors are listed on the sub-processors page.
11.3 Data processing terms. Where we process personal data on your behalf as your processor (or "service provider"), we will: process it only to provide the Service and on your documented instructions (these Terms and your Customer Configuration), unless the law requires otherwise; not sell or share it or use it for any other purpose; ensure people authorised to process it are bound by confidentiality; implement the security measures described in our Privacy Policy; use the sub-processors listed in our Privacy Policy, remain responsible for them, and update that list before adding a new one so that you can object by closing your account; provide reasonable assistance with Recipients' requests, security, and impact assessments; notify you without undue delay after becoming aware of a personal-data breach affecting that data; delete it on request or on termination within a reasonable period, except where retention is required by law; and make available information reasonably necessary to demonstrate compliance with this Section. Where personal data is transferred out of the UK or EEA, the European Commission's Standard Contractual Clauses (and the UK Addendum) are incorporated by reference to the extent required. Resend is engaged by you, under your own Resend account, and is not our sub-processor.