Data Processing Addendum

Last updated September 2026. TransactionX.

Draft — have a lawyer review before launch. If you have customers in the EU or UK, this needs proper review including transfer mechanisms.

Roles

You are the controller of the data described below. TransactionX is the processor and acts only on your documented instructions, which for this service means: providing the monitoring you subscribed to.

Subject matter and duration

Processing continues for the term of your subscription plus the retention periods in the Privacy Policy.

Nature of the data

Email authentication metadata for domains you control: DNS record contents, sending IP addresses, message volumes and authentication outcomes. Account contact details for the people you authorize.

The service does not process message content, recipient addresses or any special category data, and is not technically capable of doing so.

Sub-processors

StripePayment processing
PostmarkTransactional email delivery
Hosting providerInfrastructure

We will give thirty days' notice by email before adding a sub-processor, and you may terminate if you object.

Security measures

Breach notification

We will notify you without undue delay and within seventy-two hours of becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more.

Deletion and return

On termination you may export your data for thirty days. After that we delete it on the schedule in the Privacy Policy, or sooner on request.

Audit

We will respond to reasonable written questions about our processing once per year.

Contact

christopher@transactionx.com