BOZURO Bozuro Marketing automation
Product▾
Platform Overview Email Marketing SMS Marketing Flows & Automation Signup Forms & Popups Customer Data Platform
Pricing Integrations
Resources▾
Blog
Sign in Start free
Product Platform Overview Email Marketing SMS Marketing Flows & Automation Signup Forms & Popups Customer Data Platform Pricing Integrations Resources Blog
Sign in Start free
Legal

Data Processing Agreement

Last updated: June 7, 2026

This Data Processing Agreement ("DPA") forms part of the Bozuro Terms of Service and applies whenever Bozuro processes personal data on your behalf — for example, the contacts you import and the customers you message through email and SMS.

It describes the roles of the parties and the safeguards we apply. In this DPA, you (the customer) are the controller and Bozuro is the processor of Customer Personal Data.

On this page

  1. 1 Definitions
  2. 2 Relationship with the Agreement
  3. 3 Roles of the parties
  4. 4 Details of processing
  5. 5 Customer instructions
  6. 6 Sub-processors
  7. 7 Data subject rights
  8. 8 Security measures
  9. 9 Audits
  10. 10 Personal data breach notification
  11. 11 International data transfers
  12. 12 Return & deletion of data
  13. 13 Term & liability
  14. 14 General & contact

1. Definitions

Capitalized terms not defined here have the meaning given in the Terms of Service.

  • "Customer Personal Data" — personal data within Customer Data that Bozuro processes on your behalf.
  • "Data Protection Laws" — laws applicable to the processing of personal data, including the GDPR, the UK GDPR, and US state privacy laws.
  • "Controller", "Processor", "Data Subject", "Processing" — as defined in the GDPR.
  • "Sub-processor" — a third party engaged by Bozuro to process Customer Personal Data.
  • "Security Incident" — a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data.

2. Relationship with the Agreement

This DPA supplements the Terms of Service. Where there is a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA controls. Except as modified here, the Terms remain in full effect.

3. Roles of the parties

You are the controller (or, where you act on behalf of another controller, the processor) of Customer Personal Data, and Bozuro is the processor. Under US state privacy laws, Bozuro acts as a service provider / processor and does not sell or share Customer Personal Data, and does not use it except to provide the Service.

4. Details of processing

The processing is described as follows:

  • Subject matter & duration — provision of the Service for the term of the Agreement and until deletion of Customer Personal Data.
  • Nature & purpose — hosting, storing, segmenting, and sending email and SMS communications, and related analytics, on your instructions.
  • Types of personal data — contact identifiers (name, email, phone), engagement and order data, and any custom attributes you choose to upload.
  • Categories of data subjects — your contacts, customers, subscribers, and prospects.

5. Customer instructions

Bozuro processes Customer Personal Data only on your documented instructions, including as set out in the Agreement and as you configure the Service — unless required to do otherwise by law, in which case we will inform you where permitted. You are responsible for the lawfulness of your instructions and for having a legal basis for the processing.

6. Sub-processors

You authorize Bozuro to engage Sub-processors to provide the Service. We use Sub-processors by category, including cloud hosting and infrastructure providers and email and SMS delivery carriers and aggregators. A current list is available on request.

We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give you reasonable notice of any new Sub-processor and an opportunity to object on reasonable data-protection grounds.

7. Data subject rights

Taking into account the nature of the processing, Bozuro will assist you with appropriate technical and organizational measures — including the self-service tools in the Service — to respond to requests from Data Subjects to exercise their rights. If we receive such a request directly, we will forward it to you and will not respond except on your instruction or as required by law.

8. Security measures

Bozuro maintains technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and at rest (AES-256);
  • Role-based access controls and least-privilege access;
  • Network and application security controls and logging;
  • Regular review of our security practices.

Formal certifications such as SOC 2 are on our roadmap; contact us for our current security posture.

9. Audits

On reasonable prior written notice, and no more than once per year (unless required by a supervisory authority), Bozuro will make available information necessary to demonstrate compliance with this DPA — for example, through documentation or a completed security questionnaire — subject to confidentiality obligations.

10. Personal data breach notification

Bozuro will notify you without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, and will provide information reasonably available to help you meet your own notification obligations, and cooperate in investigation and mitigation.

11. International data transfers

Where Bozuro transfers Customer Personal Data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum and the Swiss amendments as applicable.

12. Return & deletion of data

On expiry or termination of the Agreement, Bozuro will, at your choice, return or delete Customer Personal Data within a reasonable period (and no later than 90 days), except where retention is required by law. You may also export your data from within the Service before that period ends.

13. Term & liability

This DPA takes effect when you begin using the Service and continues until all Customer Personal Data has been deleted or returned. Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

14. General & contact

If any provision of this DPA is found invalid, the remainder stays in effect. This DPA is governed by the same law as the Terms of Service. For a countersigned DPA, the current Sub-processor list, or the applicable Standard Contractual Clauses, contact [email protected].

A countersigned copy of this DPA, our current sub-processor list, and the applicable Standard Contractual Clauses are available on request from [email protected].

BOZURO Bozuro

Repeat revenue, on autopilot. Bozuro unifies customer data, email, and SMS so modern ecommerce brands turn one-time buyers into loyal regulars.

Follow us
Facebook Twitter / X LinkedIn Instagram YouTube

Product

  • Platform Overview
  • Email Marketing
  • SMS Marketing
  • Flows & Automation
  • Signup Forms & Popups
  • Customer Data Platform
  • Integrations

Company

  • About
  • Customers
  • Solutions
  • Pricing
  • Contact
  • Blog

Resources & Legal

  • Glossary
  • Security & Trust
  • Privacy
  • Terms
  • DPA

Get the growth playbook

Email & SMS tactics, benchmarks, and product news — twice a month, straight to your inbox.

© 2026 Bozuro, Inc. All rights reserved