SonarSend Data Processing Addendum (DPA)

Effective September 15, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written agreement (the “Agreement”) between the customer (“Customer,” “Controller”) and Framework Learning, LLC, 1775 W. State St. #173, Boise, ID 83702, which operates SonarSend (“SonarSend,” “Processor”) and governs SonarSend’s Processing of Personal Data on Customer’s behalf. In case of conflict, this DPA prevails over the Agreement with respect to the subject matter here. Capitalized terms not defined here have the meaning in the Agreement.

1. Definitions#

Data Protection Laws” means all laws applicable to the Processing of Personal Data under the Agreement, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and applicable U.S. state privacy laws (e.g., the CCPA/CPRA). “Controller,” “Processor,” “Personal Data,” “Processing,” “Data Subject,” “Personal Data Breach,” “Sub-processor,” and “Standard Contractual Clauses (SCCs)” have the meanings given in the Data Protection Laws. “Customer Personal Data” means Personal Data contained in Customer Data or otherwise Processed by SonarSend on Customer’s behalf to provide the Service, including Personal Data concerning Customer’s Contacts, message recipients, and authorized users. Customer Personal Data does not include account, billing, security, marketing, or business-relationship data that SonarSend Processes as an independent Controller, as described in the Privacy Policy.

2. Roles and scope#

Customer is the Controller (or, where Customer is itself a processor, the processor acting on behalf of a third-party controller) and SonarSend is the Processor of Customer Personal Data. Each party will comply with its obligations under the Data Protection Laws. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex 1.

3. Processing instructions#

3.1 SonarSend will Process Customer Personal Data only (a) to provide and support the Service in accordance with the Agreement, (b) on Customer’s documented instructions (including via the Service’s features and APIs), and (c) as required by law (in which case SonarSend will inform Customer unless legally prohibited). Customer’s use and configuration of the Service, including directing messages to Contacts and transmitting content to Customer’s own Sending Provider, constitute documented instructions.

3.2 SonarSend will inform Customer if, in its opinion, an instruction infringes the Data Protection Laws.

3.3 Customer is responsible for the accuracy and legality of Customer Personal Data and for having the necessary rights, notices, and lawful bases to provide it to SonarSend and to instruct the Processing.

4. Confidentiality#

SonarSend ensures that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and Process the data only as instructed.

5. Security#

SonarSend will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against a Personal Data Breach, appropriate to the risk, as described in Annex 2. SonarSend may update its measures provided they do not materially decrease the overall level of protection.

6. Sub-processors#

6.1 General authorization. Customer provides general written authorization for SonarSend to engage Sub-processors to Process Customer Personal Data. A current list of Sub-processors is maintained in Annex 3, published at sonarsend.com/legal/dpa.

6.2 Flow-down. SonarSend will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable to Customer for its Sub-processors’ performance.

6.3 Changes and objection. SonarSend will notify Customer of intended additions or replacements of Sub-processors (e.g., by updating the list and/or email) with at least 30 days’ notice. Customer may object on reasonable data-protection grounds within that 30-day notice period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Service as its remedy.

7. Assistance to Controller#

Taking into account the nature of the Processing, SonarSend will assist Customer, by appropriate technical and organizational measures and insofar as reasonably possible, to: (a) respond to Data Subject requests to exercise their rights; (b) ensure security of Processing; (c) notify and communicate Personal Data Breaches; and (d) carry out data protection impact assessments and prior consultations. SonarSend will promptly forward to Customer any Data Subject request it receives relating to Customer Personal Data and will not respond directly except on Customer’s instruction or as legally required.

8. Personal Data Breach#

SonarSend will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to assist Customer in meeting its notification obligations, and will take reasonable steps to mitigate and remediate.

9. Deletion or return#

Upon termination or expiry of the Agreement, SonarSend will return Customer Personal Data by making it available for export for 14 days, as described in the Terms of Service, and will delete it and existing copies when Customer asks in writing, or otherwise in the ordinary course, except to the extent retention is required by law. Sections of the Service may allow Customer to export or delete data directly.

Backups. Copies of Customer Personal Data in SonarSend’s backups, including copies of data Customer deletes during the term, are not deleted individually. They are deleted as those backups expire in SonarSend’s ordinary backup rotation, and in any event within 90 days. Until then, SonarSend will (a) keep backups access-restricted and protected by the measures in Annex 2, and (b) not access or use Customer Personal Data in backups for any purpose other than disaster recovery.

10. Audits#

SonarSend will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor Customer mandates, subject to reasonable confidentiality, security, scheduling, and frequency conditions. SonarSend may satisfy this obligation by providing then-current third-party audit reports or certifications, where available.

11. International transfers#

Where SonarSend Processes Customer Personal Data originating from the EEA, UK, or Switzerland in a country without an adequacy decision, the Standard Contractual Clauses are incorporated into this DPA by reference and apply, with the appropriate Module(s), together with the UK International Data Transfer Addendum and the Swiss addendum as applicable. The Annexes to the SCCs are populated by Annexes 1–3 of this DPA. In case of conflict between the SCCs and this DPA, the SCCs prevail for transfers they govern.

12. U.S. state privacy laws#

Where applicable U.S. state privacy laws apply and SonarSend acts as a “service provider” or “processor”: SonarSend will Process Customer Personal Data only to provide the Service and for the business purposes in the Agreement; will not sell or share it, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than the Agreement, and will not combine it with data from other sources except as permitted by law. SonarSend certifies it understands and will comply with these restrictions.

13. Liability#

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement (including the limitation-of-liability cap). Nothing in this DPA limits liability that cannot be limited under the Data Protection Laws.

14. Term#

This DPA takes effect on the effective date of the Agreement and remains in effect until SonarSend ceases Processing Customer Personal Data.


Annex 1 — Details of Processing#

  • Roles: Customer = Controller; SonarSend = Processor. Where Customer acts as a processor on behalf of a third-party controller, SonarSend acts as Customer’s sub-processor.
  • Subject matter: Provision of the SonarSend email-marketing and automation Service.
  • Duration: For the term of the Agreement plus the deletion/return period in Section 9.
  • Nature and purpose: Hosting, storage, organization, segmentation, automation, sending-orchestration through Customer’s own Sending Provider, engagement tracking and analytics, and related support.
  • Categories of Data Subjects: Customer’s Contacts and message recipients (e.g., subscribers, leads, customers, and prospects of Customer); and Customer’s authorized users, but only to the extent SonarSend Processes their Personal Data on Customer’s behalf rather than as an independent Controller.
  • Categories of Personal Data: Contact identifiers (e.g., name, email address), any custom fields and attributes Customer chooses to store, engagement and activity data (opens, clicks, visits), IP address and device/technical data, and message content Customer creates.
  • Special categories of data: Not intended or requested. Customer should not upload special-category data except as separately agreed; if it does, it is responsible for the additional safeguards required by law.
  • Frequency: Continuous, for the duration of the Agreement.
  • Sub-processors: See Annex 3.

Annex 2 — Technical and Organizational Measures#

SonarSend maintains the following measures. SonarSend does not currently hold a third-party security certification (such as SOC 2 or ISO 27001).

1. Encryption

  • Connections to the Service’s public endpoints use TLS, and the Service enforces HTTPS in browsers (HTTP Strict Transport Security).
  • Connected Sending Provider credentials, integration authorization tokens, and outbound-webhook secrets are encrypted at rest with AES-256-GCM, using keys stored separately from the database.
  • Database backups copied to a separate storage provider are encrypted with AES-256-GCM before leaving the hosting environment.

2. Customer account security

  • Passwords are stored only as salted bcrypt hashes, subject to minimum length and complexity rules.
  • Two-factor authentication (TOTP) is available to all users, and a workspace can require it for all of its users.
  • Sessions expire after 24 hours and are revoked on sign-out, password change, or role change.
  • Sign-in, two-factor, and password-reset endpoints are rate-limited. Password-reset tokens are stored hashed, expire, and can be used only once.
  • API keys are stored only as one-way hashes.

3. Separation of customer data

  • Customer Personal Data is stored with Customer’s account identifier. Each request and background job is scoped to a single customer account, after the user’s membership of that account is verified.
  • The database enforces the same boundary independently: row-level security policies restrict the roles the application connects as to the account a query is scoped to, so a query that is missing that scope returns nothing rather than another customer’s data.
  • Automated tests run on proposed code changes to detect database access that is not scoped to a customer account.

4. SonarSend personnel and administrative access

  • SonarSend personnel who are not members of Customer’s workspace can access it only under a support grant. Each grant records a reason, expires automatically, can be revoked, and is read-only unless write access is specifically granted. Access under a grant is recorded in application logs.
  • SonarSend’s internal administration console runs separately from the Service, behind an identity-verifying access gateway, and requires two-factor authentication.
  • Personnel authorized to process Customer Personal Data are bound by confidentiality obligations.

5. Network and application security

  • Application servers accept traffic only through SonarSend’s edge network provider, which also provides protection against denial-of-service attacks.
  • The Service uses security headers (content security policy, HSTS, and framing restrictions), an allowlist of origins for browser requests, schema validation of API input, protection against server-side request forgery on outbound requests, and rate limiting.
  • Tracking links and outbound webhooks are cryptographically signed, and payment-provider webhooks are signature-verified.
  • Application containers run without root privileges. Secrets are held in the hosting provider’s configuration, never in source code, and production services refuse to start without their required secrets.

6. Monitoring

  • Application error monitoring, with signed tracking tokens and internal authentication headers redacted, and application logs.

7. Availability and resilience

  • Managed PostgreSQL with continuous point-in-time recovery, restorable to any moment within approximately the previous four weeks.
  • A daily encrypted database backup, stored with a separate provider and retained for 14 days.
  • Automatic retries, and dead-letter capture of failed background and event processing.

8. Secure development and change management

  • Source code is kept in version control. Proposed changes run automated builds, type checks, unit and integration tests, and the account-scoping audit described in item 3.
  • Production releases are promoted from a tested branch through a controlled deployment process.

9. Data minimization, retention, and deletion

  • Customer can suppress contacts, and can overwrite the personal data in an individual contact’s profile, from within the Service.
  • Retention limits are applied automatically: event history is kept for 18 months, anonymous website-visit sessions for 90 days, and outbound-webhook delivery logs for 30 days.
  • Backups are retained and deleted as described in Section 9.

10. Sub-processors and incidents

  • Sub-processors are bound by data-protection obligations as described in Section 6.2.
  • Personal Data Breaches are handled and notified as described in Section 8.

Annex 3 — Sub-processors#

SonarSend currently uses the following Sub-processors. Changes are notified as described in Section 6.3.

Sub-processorPurposeLocation
Railway CorporationApplication, PostgreSQL database, Redis, background-worker hosting, logs, database backups, and object storage for contact imports/exportsUnited States (US West)
Cloudflare, Inc.Edge/CDN, DNS, tracking-domain fronting (Cloudflare for SaaS), R2 object storage / encrypted backups, Cloudflare Web Analytics, and Workers/KV for the MCP connectorGlobal edge; R2 storage in Western North America (WNAM)
Stripe, LLCBilling, subscriptions, and payment processingUnited States
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsUnited States
AC PM, LLC (Postmark)Transactional account, authentication, security, notification, and service emails to Customer’s authorized users, including any Customer Personal Data contained in those communicationsUnited States

Notes: (1) Sentry processes error reports rather than Contact data. It’s listed because those reports can contain Customer Personal Data. (2) Staged contact imports and exports are stored in Railway object storage, covered by the Railway row. (3) Customer’s own Sending Provider (such as Amazon SES, SendGrid, or Mailgun) is not a SonarSend Sub-processor. It is Customer’s own vendor, and SonarSend transmits message content to it on Customer’s documented instructions (Section 3.1).