Data Processing Addendum

Effective September 24, 2026

Your contacts’ personal data is yours, not ours. This addendum sets out the terms on which we process it for you — what we may do with it, who else touches it, how it is protected, and what happens when you ask for it back.

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of the Terms of Use between Vadelis Labs Inc., a Florida corporation (“Vadelis Labs”, “Processor”), which operates MessageFuel, and the customer (“you”, “Controller”). MessageFuel is a product of Vadelis Labs Inc., and the Processor under this DPA is the company. It governs our processing of personal data contained in Customer Data — your contacts’ information — and applies wherever data protection law imposes processor obligations on us, including the EU and UK GDPR, the CCPA as amended by the CPRA, the Florida Digital Bill of Rights and equivalent US state laws.

You are the controller (or, where you act for your own client, the processor and we are your sub-processor). You determine whose data enters the platform, why, and what is sent to them. We process it only to provide the Service. Nothing in this DPA makes us a controller of Customer Data.

This DPA is accepted with the Terms of Use

No signature is required — accepting the Terms of Use accepts this DPA. If your procurement process needs a countersigned copy, or your own DPA template, write to Info@messagefuel.com and we will arrange it.

2. Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Personal information”, “business”, “service provider”, “sell” and “share” have the meanings given in the CCPA. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914. “Sub-processor” means a processor we engage to process Customer Data.

3. Our processing instructions

We process Customer Data only on your documented instructions, which consist of this DPA, the Terms of Use, and the actions you take in the Service — importing contacts, building an audience, sending a campaign, connecting an integration, exporting or deleting data. We will not process it for any other purpose.

  • We do not sell or share personal information, as those terms are defined by US state privacy law, and we certify that we understand and will comply with that restriction as a service provider.
  • We do not retain, use or disclose personal information outside the direct business relationship with you, or combine it with personal information received from another source, except as permitted by law.
  • We do not use Customer Data to train models, to build a product, or for our own marketing.
  • We will tell you if, in our opinion, an instruction infringes data protection law — though we do not police the lawfulness of your messaging, which is your obligation under the Acceptable Use Policy.
  • We may process Customer Data where required by law, and will inform you first unless the law forbids it.

Your obligations

You warrant that you have a lawful basis for the processing you instruct, that you have given your contacts the privacy notice their jurisdiction requires, that you hold the consent required to message them, and that your instructions comply with applicable law. You must not upload special category data, health data subject to HIPAA, cardholder data, government identifiers or biometric data — the platform is not built for them and we do not contract for them.

4. Confidentiality of personnel

We limit access to Customer Data to personnel and contractors who need it to provide or support the Service. Everyone with access is bound by a written obligation of confidentiality that survives the end of their engagement, and access to production data is granted on a least-privilege basis. Administrative access to a customer account by our staff is logged.

5. Security measures

We implement appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Those measures currently include:

  • Tenant isolation enforced in the database. Every customer-scoped table is protected by row-level security tied to organisation membership, so isolation does not depend on the application layer being correct.
  • Encryption. TLS for data in transit; encryption at rest by our database, storage and hosting providers.
  • Credential protection. Provider API keys and OAuth tokens are server-side only and are never exposed to a browser. Advertising authorisation tokens sit in a table with no user-level read access at all, and the only representation that can reach a browser has the token removed.
  • Authentication and access control. Passwords are stored as salted hashes by our authentication provider; role-based permissions limit what each member of your organisation can reach.
  • Input validation at every external boundary. Public endpoints validate, rate limit and reject abusive traffic before it reaches storage.
  • Auditability. Consent events are append-only and cannot be rewritten after the fact; sends carry a per-batch audit trail.
  • Resilience. Managed, backed-up infrastructure with point-in-time recovery provided by our database host.

Security measures evolve. We may change them provided the level of protection is not materially reduced.

6. Sub-processors

You give general authorisation for us to engage sub-processors. Each is engaged under a written contract imposing data protection obligations no less protective than those in this DPA, and we remain liable to you for their performance.

Our current sub-processors are:

  • Supabase. Database, authentication and file storage (United States).
  • Vercel. Application hosting, serverless compute and logging (United States).
  • Twilio. SMS and MMS delivery, carrier registration and delivery receipts.
  • SendGrid (Twilio). Email delivery, engagement events and sender authentication.
  • Google (Google Ads). Customer Match audiences — only when a customer connects an ad account, and only as irreversibly hashed identifiers.
  • Meta (Facebook, Instagram). Custom Audiences — only when a customer connects an ad account, and only as irreversibly hashed identifiers.
  • PostHog. Server-side product analytics — which features an account uses. Keyed to an account user id, never to a contact, and only where configured.
  • Litmus or Email on Acid. Optional cross-client inbox previews. Receives the rendered email only, never a contact list.

The last three are engaged only for customers who switch the relevant feature on. We will give you at least 30 days’ notice before adding or replacing a sub-processor that processes Customer Data. If you reasonably object on data protection grounds within that period, tell us and we will work with you to find an alternative; if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for it.

7. Data subject requests

The Service gives you the tools to answer most requests yourself: contacts can be searched, exported, corrected and deleted, opt-outs are recorded and enforced, and the preference centre lets a recipient update their own details and consent.

If a data subject contacts us directly about data we hold for you, we will not respond substantively — we will tell them to contact you, and pass the request on where we can identify you. Taking into account the nature of the processing, we will provide reasonable assistance with your obligations under GDPR Articles 12–23 and the equivalent US state provisions, and with data protection impact assessments and prior consultations under Articles 35 and 36, at your cost where the assistance is substantial.

8. Personal data breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — to the extent that information is available, supplemented as we learn more. We will not delay notice in order to complete an investigation first. Notice of a breach is not an admission of fault. Reporting to a supervisory authority or to affected individuals is your decision as controller, and we will give you what you need to make it.

9. Return and deletion

You may export Customer Data at any time while your account is active. On termination, and on request within 30 days afterwards, we will return or delete Customer Data at your choice; after that window we delete or de-identify it in the ordinary course. Deletion propagates out of backups over the normal backup cycle rather than instantly.

Suppression records are deliberately retained

Opt-out and consent records are kept after the related contact is deleted. An opt-out record is the only thing that prevents someone being messaged again once their contact row is gone, and a consent record is the evidence that a message was permitted when it was sent. Retaining them is a legal obligation for both of us, and they are retained in a minimised form.

10. Audits and information

On reasonable written request, and no more than once in any twelve-month period unless a regulator or a breach requires otherwise, we will make available the information necessary to demonstrate compliance with this DPA, and will respond to a reasonable security questionnaire. Where an on-site audit is required by law, it will be conducted on at least 30 days’ notice, during business hours, subject to confidentiality, without access to other customers’ data or to our production systems, and at your expense.

11. International transfers

Customer Data is stored in the United States. Where we process personal data subject to the EU or UK GDPR, the transfer is made under the Standard Contractual Clauses, which are incorporated into this DPA by reference and take effect on acceptance of the Terms of Use:

  • Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are yourself a processor for your client.
  • The optional docking clause applies. In Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in section 6 above. In Clause 11, the optional independent dispute resolution body does not apply. In Clause 17, the governing law is the law of Ireland; in Clause 18, the forum is the courts of Ireland.
  • Annex I is completed by section 12 of this DPA, Annex II by section 5, and Annex III by section 6.
  • For UK transfers, the Information Commissioner’s International Data Transfer Addendum applies to the SCCs, with the tables completed by the corresponding sections of this DPA and neither party able to end it under Section 19 other than as permitted.

12. Details of processing

  • Subject matter. Provision of the MessageFuel SMS and email marketing platform.
  • Duration. For the term of the Terms of Use, plus the deletion window in section 8.
  • Nature and purpose. Storing and organising contact lists; capturing submissions from signup forms; composing, rendering and transmitting SMS and email messages; recording delivery and engagement outcomes; recording consent and opt-outs; and, on instruction, transmitting hashed identifiers to advertising platforms.
  • Categories of data subjects. The controller’s contacts, subscribers, customers and prospects; and the controller’s own personnel who use the Service.
  • Categories of personal data. Name; mobile telephone number; email address; any custom fields the controller defines; group and label membership; inferred time zone; consent status and consent history including the wording shown, timestamp, IP address and user agent; message content addressed to the data subject; and delivery and engagement records including delivery status, error codes, bounces, opens, clicks and unsubscribes.
  • Special category data. None. The Service is not to be used for special category or sensitive data, and controllers are contractually prohibited from submitting it.
  • Frequency. Continuous, for the duration of the agreement.

13. General

In the event of a conflict, this DPA prevails over the Terms of Use with respect to the processing of personal data, and the SCCs prevail over this DPA with respect to transfers they govern. Our liability under this DPA is subject to the limitations in the Terms of Use, except where those limitations are not permitted by applicable data protection law.

If this DPA is amended, we will give account holders notice in the same way as for the Terms of Use.

Contact

Data protection enquiries, DPA countersignature requests and security questionnaires: Info@messagefuel.com.

Vadelis Labs Inc.Attn: MessageFuel1784 NW Madrid WayBoca Raton, FL 33432United StatesInfo@messagefuel.com