# Data Processing Agreement

_Last updated: 6 October 2026_

**In short:** If you use Print and Mail Company for a business or organisation, you decide which letters are sent to whom, and we print and post them on your behalf. This agreement sets out the rules for that processing under Article 28 GDPR. It applies automatically, and we can provide a signed copy on request.

- We process recipient data and letter content only on your instructions, to print and send your letters.
- Letter files are deleted automatically 30 days after the letter is posted.
- Our sub-processors are listed in Annex 2. We give you 30 days' notice before we add or replace one.
- We notify you of personal data breaches without undue delay, and at the latest within 48 hours.

## 1. Parties and conclusion

1.1 This Data Processing Agreement ("DPA") is concluded between the business customer using Print and Mail Company ("Customer", "you"), as controller, and LeFaLux vGmbH, 40 rue du Travail, L-2625 Beggen, Luxembourg, RCS Luxembourg B298899 ("we", "us"), as processor.

1.2 This DPA applies automatically whenever you use our service for your trade, business, craft or profession, or on behalf of a company, association, public body or other organisation, and we process personal data on your behalf in doing so. It forms part of our [Terms of Service](/legal/terms) ("Terms"), and you accept it together with them. No separate signature is required; the DPA is concluded in electronic form (Art. 28(9) GDPR).

1.3 If you would like a copy signed by us, write to support@printandmailcompany.com. The signed copy has the same content as this DPA.

1.4 If you process the personal data as a processor on behalf of another controller, we act as your sub-processor. In that case you confirm that your controller has authorised your instructions and our engagement, and you remain our only point of contact.

1.5 This DPA does not apply to private customers who use our service for purely personal or household purposes. Our [Privacy Policy](/legal/privacy) explains how we handle data in that case.

1.6 If this DPA conflicts with the Terms, this DPA prevails on matters of data protection. If Standard Contractual Clauses apply between the parties, they prevail over this DPA.

## 2. Definitions

2.1 Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in the GDPR (Regulation (EU) 2016/679).

2.2 In this DPA:

- **"Customer Personal Data"** means the personal data we process on your behalf when providing the Service, as described in section 4;
- **"Service"** means the printing and mailing service offered at printandmailcompany.com, including the website, customer account, REST API and MCP server;
- **"Sub-processor"** means another processor that we engage to process Customer Personal Data;
- **"Data Protection Law"** means the GDPR and the data protection laws of the EU and Luxembourg that apply to the processing.

## 3. Subject matter, duration, nature and purpose

3.1 **Subject matter.** Printing the letters you provide, putting them into envelopes printed with the recipient's address, franking them and handing them to POST Luxembourg for delivery, together with the related storage, status information and support.

3.2 **Nature of the processing.** Receiving and storing files and data via the website, API or MCP server; automated technical checks (page size, margins, page count, colour); rendering letters composed with our compose tool and generating print files; printing, folding and enveloping; handing letters to the postal operator; providing status and tracking information; support; and deletion.

3.3 **Purpose.** Providing the Service to you in accordance with the Terms and your instructions.

3.4 **Duration.** For as long as you use the Service, and afterwards until Customer Personal Data has been deleted as described in section 13.

## 4. Personal data and data subjects

4.1 **Types of personal data:**

- names, company names and postal addresses of recipients;
- return addresses, if you provide your own;
- any personal data contained in letters. You decide what this is and we don't review it. It may include contact details, customer or contract numbers, dates, financial information and other information about recipients or third parties;
- letter details: reference, options, status, dates, and the tracking number and delivery status of registered letters.

4.2 **Special categories.** Letters may contain special categories of personal data (Art. 9 GDPR), such as health data, or personal data relating to criminal convictions and offences (Art. 10 GDPR), if you include them. You must assess whether it is lawful and appropriate to send such data using the Service, taking into account the measures in Annex 1, and carry out a data protection impact assessment where required. We apply the measures in Annex 1 to all letters in the same way, without knowing their content.

4.3 **Categories of data subjects:**

- letter recipients;
- people named or referred to in letters;
- your employees and representatives, such as signatories or contact persons named in letters or return addresses;
- any other people whose data you include in letters.

## 5. Your responsibilities

5.1 As controller, you are responsible for the lawfulness of the processing, in particular for having a legal basis for each letter, for informing data subjects (Arts. 13 and 14 GDPR) and for the accuracy of addresses and content.

5.2 You give only lawful instructions and send through the Service only the personal data needed for your purpose.

5.3 You are responsible for instructions given through your account, including by users you allow to use it and by AI assistants and API keys you authorise.

5.4 You inform us without undue delay if you find errors or irregularities in the processing.

## 6. Instructions

6.1 We process Customer Personal Data only on your documented instructions, including with regard to transfers to third countries, unless EU or Member State law requires us to do otherwise. In that case we inform you of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.

6.2 Your instructions consist of:

- the Terms and this DPA;
- your use of the Service's functions, such as uploading documents, entering recipient data, choosing options and sending or cancelling letters;
- requests made through the API or MCP server with your credentials, including by AI assistants you have authorised; and
- other written instructions, including by email, within the scope of the Service. If an instruction goes beyond the normal scope of the Service, we may charge for it after telling you the cost.

6.3 If we believe that an instruction infringes Data Protection Law, we inform you immediately. We may suspend that instruction until you confirm or change it.

6.4 **Processing for our own purposes.** We process the following data as an independent controller, not under this DPA, as described in our [Privacy Policy](/legal/privacy):

- your account, payment and billing data, including the data of the users of your account;
- invoices and accounting records, which include the letter reference and postage zone but not the recipient's name or address;
- data we need to comply with legal obligations, for example to respond to lawful requests from authorities;
- data we need to handle reports of illegal content and to enforce our [Acceptable Use Policy](/legal/acceptable-use), including evidence relating to a reported letter; and
- data we need to establish, exercise or defend legal claims.

## 7. Confidentiality

7.1 We ensure that everyone authorised to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and that this obligation continues after their work for us ends.

7.2 Access to Customer Personal Data is limited to people who need it for their tasks. Production staff handle printed letters physically but do not read their content beyond what printing, quality control and enveloping technically require.

7.3 We don't use Customer Personal Data for our own purposes, except as described in section 6.4. In particular, we don't use it for profiling or advertising, we don't sell it and we don't use it to train AI models.

## 8. Security

8.1 We implement the technical and organisational measures described in Annex 1 to ensure a level of security appropriate to the risk (Art. 32 GDPR).

8.2 The measures are subject to technical progress. We may adapt them as long as the overall level of protection is not reduced, and we update Annex 1 accordingly.

## 9. Sub-processors

9.1 You give us general written authorisation to engage Sub-processors. The Sub-processors listed in Annex 2 are approved when this DPA is concluded.

9.2 We inform you at least 30 days in advance of any intended addition or replacement of a Sub-processor, by email to your account email address and by updating Annex 2.

9.3 You may object to the change on reasonable data protection grounds within those 30 days by writing to privacy@printandmailcompany.com. We will then try to find a solution with you in good faith. If we cannot find one, you may stop using the Service and close your account before the change takes effect, and we refund your unused credit in accordance with the Terms. If you don't object within the 30 days, the change is deemed approved.

9.4 If we must replace a Sub-processor urgently for reasons beyond our control, for example because of a security risk or because the provider discontinues its service, we may do so with shorter notice. We inform you as soon as possible, and your right to object under section 9.3 applies accordingly.

9.5 We impose on every Sub-processor, by contract, data protection obligations that provide at least the same level of protection as this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures (Art. 28(4) GDPR). We remain responsible to you for our Sub-processors' compliance with their obligations.

9.6 The following are not our Sub-processors:

- **POST Luxembourg** and the postal operators of destination countries. They provide postal services as independent controllers. Handing letters to them is the purpose of the Service and happens on your instruction;
- **Google**, if users of your account sign in with Google, and the **providers of AI assistants** that you connect to the Service. They act for you or as independent controllers.

## 10. International transfers

10.1 We store Customer Personal Data in the EU (see Annex 2).

10.2 Some Sub-processors are established in the USA or belong to groups with entities outside the EEA, and may access or process data from there, for example for support, security or email delivery. We transfer Customer Personal Data to third countries only in accordance with Chapter V GDPR, in particular on the basis of the EU–US Data Privacy Framework for certified recipients or the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), with additional measures where necessary.

10.3 We hand every letter to POST Luxembourg in Luxembourg. POST Luxembourg forwards letters addressed to other countries to the postal operator of the destination country as part of the international postal service. You decide which letters are sent to which countries.

## 11. Assistance

11.1 **Data subject requests.** Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights (Arts. 12 to 23 GDPR). If a data subject contacts us directly about Customer Personal Data, we forward the request to you without undue delay. Unless you instruct us otherwise, we don't respond to it ourselves, except to tell the data subject that we have forwarded it.

11.2 You can view and cancel your letters in your account. On request we also help you in other ways, for example by finding the letters sent to a particular recipient or by deleting specific files or letter details before the standard deletion dates.

11.3 **Other obligations.** Taking into account the nature of the processing and the information available to us, we assist you in complying with Arts. 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), in particular by providing this DPA, Annex 1 and any other information you reasonably need.

11.4 **Costs.** Our assistance is free of charge where it consists of providing our standard documentation or is required because of a breach by us. For other assistance that requires significant effort, we may charge reasonable costs, which we tell you in advance.

## 12. Personal data breaches

12.1 We notify you of any personal data breach affecting Customer Personal Data without undue delay, and at the latest within 48 hours after becoming aware of it.

12.2 Our notification describes, as far as known at the time:

- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures we have taken or propose to take to address the breach and mitigate its possible adverse effects; and
- a contact person for further information.

If we cannot provide all the information at once, we provide it in stages without further undue delay.

12.3 We take reasonable steps to contain, investigate and mitigate the breach, and we support you in meeting your obligations to notify the supervisory authority and data subjects (Arts. 33 and 34 GDPR). You remain responsible for those notifications.

12.4 We send notifications to your account email address or to another contact you name in writing.

12.5 Notifying or responding to a breach is not an acknowledgement of fault or liability.

## 13. Deletion and return of data

13.1 Letter files (uploaded PDFs, composed letters and print files) are deleted automatically 30 days after the letter was posted, or 30 days after upload if the letter was never sent.

13.2 Letter details (recipient's name and address, return address, status, dates and tracking number) are deleted or anonymised 12 months after posting or cancellation. Data we keep as an independent controller under section 6.4 is not affected.

13.3 You can ask us to delete specific files or letter details earlier by writing to support@printandmailcompany.com. If you do this before a letter has been posted, the letter can no longer be sent.

13.4 When you stop using the Service and close your account, we delete all remaining Customer Personal Data, unless EU or Member State law requires us to keep it. You keep the original documents you provided. If you ask before your account is closed, we provide an export of your letter details (such as recipient, date, status and tracking number) in a common electronic format.

13.5 Letters returned to us as undeliverable are not opened. We inform you and securely destroy them after 30 days.

13.6 Residual copies in backups are deleted in the regular backup cycle, normally within 30 days.

## 14. Demonstrating compliance and audits

14.1 We make available to you the information necessary to demonstrate compliance with Art. 28 GDPR, in particular this DPA, Annex 1, the list of Sub-processors and, where available and shareable, our Sub-processors' certifications or audit reports. We answer reasonable written questions about how we protect Customer Personal Data.

14.2 You agree to rely first on the information described in section 14.1. If it is not sufficient to demonstrate our compliance, or if a supervisory authority requires it, you or an independent auditor you appoint may carry out an on-site audit of the facilities and processes used to process Customer Personal Data. The auditor must be bound by confidentiality and must not be one of our competitors.

14.3 On-site audits:

- must be announced with reasonable notice, normally at least 30 days, or less after a personal data breach;
- take place during normal business hours without unreasonably disrupting our operations, and must protect the confidentiality of other customers' data and of our trade secrets;
- are limited to once per calendar year, unless a personal data breach affecting your data has occurred or a supervisory authority requires an audit; and
- are carried out at your expense. If an audit reveals a material breach of this DPA by us, we bear our own costs of the audit and remedy the breach without undue delay.

14.4 This section does not limit inspections by supervisory authorities.

## 15. Liability

15.1 Each party is liable to data subjects in accordance with Art. 82 GDPR. As processor, we are liable for damage caused by processing only where we have not complied with obligations of the GDPR specifically directed to processors, or where we have acted outside or contrary to your lawful instructions.

15.2 Between the parties, the limitations of liability in the Terms apply to the extent permitted by law. They do not limit either party's liability towards data subjects under Art. 82 GDPR, and they do not apply where mandatory law excludes such limitations. If one party has paid full compensation to a data subject, it may claim back from the other party the part of the compensation that corresponds to the other party's share of responsibility for the damage (Art. 82(5) GDPR).

## 16. Term and termination

16.1 This DPA applies for as long as we process Customer Personal Data on your behalf. It ends automatically once all Customer Personal Data has been deleted.

16.2 Provisions that by their nature are intended to continue, such as confidentiality, deletion and liability, continue to apply after this DPA ends.

## 17. Final provisions

17.1 **Changes.** We may amend this DPA where required by law or by a supervisory authority, or to reflect changes to the Service, provided that the level of protection of Customer Personal Data is not reduced. We inform you of material changes at least 30 days in advance. Changes of Sub-processors are governed by section 9.

17.2 **Notices.** Notices to us go to privacy@printandmailcompany.com. Notices to you go to your account email address.

17.3 **Governing law and jurisdiction.** This DPA is governed by Luxembourg law. The place of jurisdiction is as set out in the Terms.

17.4 **Severability.** If any provision of this DPA is invalid, the remaining provisions remain valid. The invalid provision is replaced by a valid provision that comes closest to its purpose, and in any event the requirements of Art. 28 GDPR apply.

## Annex 1: Technical and organisational measures

### 1. Encryption

- All connections to our website, API and MCP server are encrypted with TLS.
- Data at rest, including databases, file storage and backups, is encrypted by our providers using industry-standard encryption.
- Passwords and API keys are stored only in hashed form. Sign-in cookies are sent only over encrypted connections and cannot be read by scripts on the page.
- Access tokens issued to AI assistants expire after a short time.

### 2. Access control

- All access to customer accounts and letters requires authentication. AI assistants connect via OAuth 2.1 with PKCE, and only after the customer has approved their access.
- Administrator accounts and access to our providers' consoles (hosting, database, storage) are protected with multi-factor authentication and limited to named, authorised persons.
- Access is role-based: customers and administrators have separate roles, and each person receives only the rights they need for their tasks (least privilege).
- Access rights are reviewed regularly and removed without delay when no longer needed, for example when someone leaves.
- Credentials and secrets are kept in our hosting provider's encrypted configuration, not in source code.

### 3. Separation of customer data

- Every letter, file and address is linked to one customer account, and every request is checked against that account.
- Production and development environments are separate. Customer data is not used for development or testing.

### 4. Logging and monitoring

- Security-relevant events and administrative actions, such as changes to a letter's status, refunds and account blocks, are recorded in an audit log.
- Server logs are kept for 30 days.
- Request limits protect against brute-force attacks and abuse.
- Errors and availability are monitored.

### 5. Data minimisation and deletion

- Automated checks are limited to technical properties (page size, margins, page count, colour); the content of letters is not analysed.
- Letter files are deleted automatically 30 days after posting, or 30 days after upload if the letter is never sent. Letter details are deleted or anonymised after 12 months.
- Customer Personal Data is not used for profiling, advertising or AI training.

### 6. Physical security of production

- Letters are printed in a secure production area in Luxembourg with restricted physical access. Only authorised staff have access, and visitors are always accompanied.
- Printed letters are never left unattended and are kept in a secured area until they are handed to POST Luxembourg.
- A production reference printed on each envelope is used to check that every letter goes into the right envelope.

### 7. Confidential destruction

- Misprints, test prints, spoiled pages and returned letters are destroyed by cross-cut shredding (at least security level P-4 under ISO/IEC 21964, formerly DIN 66399) or by a certified document destruction service.
- Letters returned as undeliverable are not opened and are destroyed after 30 days.

### 8. Staff

- Everyone with access to Customer Personal Data has signed a confidentiality undertaking.
- Staff are instructed in data protection and in the confidential handling of letters.

### 9. Availability and recovery

- We use managed infrastructure providers with redundant data centres in the EU.
- The database is backed up automatically with point-in-time recovery, and restore procedures are tested regularly.

### 10. Incident response

- A documented procedure covers detection, containment, assessment, notification of affected customers within 48 hours, notification of authorities where required, and follow-up measures.
- Personal data breaches are recorded in an internal breach register.

### 11. Sub-processor management

- Data processing agreements are in place with all Sub-processors.
- Sub-processors are selected for their security guarantees, such as recognised certifications (for example ISO/IEC 27001 or SOC 2), and reviewed when their services change.

### 12. Maintenance and review

- Security updates for our software and its dependencies are applied promptly.
- We review these measures at least once a year and after any significant incident.

## Annex 2: Sub-processors

| Sub-processor | Purpose | Data concerned | Location of processing | Transfer safeguard |
|---|---|---|---|---|
| Vercel Inc. (USA) | Hosting of website, application, API and MCP server | All Customer Personal Data handled by the application | EU (Frankfurt, Germany); Vercel's global network delivers content | EU–US Data Privacy Framework or Standard Contractual Clauses |
| Neon Inc. (USA) | Database | Recipient and return addresses, letter details | EU | EU–US Data Privacy Framework or Standard Contractual Clauses |
| Cloudflare, Inc. (USA) | File storage (Cloudflare R2) | Uploaded PDFs, composed letters, print files | EU (R2 EU jurisdiction) | EU–US Data Privacy Framework or Standard Contractual Clauses |
| Resend (USA) | Service emails to you | Letter reference, recipient's name, destination country, tracking number | USA or EU, depending on the sending region | EU–US Data Privacy Framework or Standard Contractual Clauses |
| Stripe Payments Europe, Limited (Ireland) | Payment processing only | Payment data relating to you; no letter content or recipient data | EU and other Stripe locations | Standard Contractual Clauses or EU–US Data Privacy Framework (Stripe group) |

POST Luxembourg and the postal operators of destination countries are not Sub-processors (see section 9.6).