Data Processing Agreement
Last updated: 2 August 2026
This DPA describes how SabNode processes personal data on your behalf as your processor, and the safeguards we apply — for compliance with the DPDP Act, the GDPR and similar laws.
1. Scope & roles
This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Customer”, the controller) and SabNode (the processor) for your use of the Service. It governs SabNode’s processing of personal data that Customer submits to the Service (“Customer Data”), and applies to the extent required by the DPDP Act, the GDPR and other applicable data-protection laws.
2. Nature & purpose of processing
SabNode processes Customer Data only to provide, secure and support the Service, and only on Customer’s documented instructions (including through use of the product).
- Subject matter — provision of SabNode’s messaging, CRM, email, automation and related products.
- Duration — for the term of the agreement and until deletion/return of Customer Data.
- Data subjects — Customer’s contacts, leads, recipients, employees and end-users.
- Data types — identifiers, contact details, message and email content, CRM records and metadata that Customer chooses to process.
3. SabNode obligations
- Process Customer Data only on Customer’s instructions and for the purposes above;
- Ensure persons authorised to process Customer Data are bound by confidentiality;
- Implement appropriate technical and organisational security measures (Section 4);
- Assist Customer, taking into account the nature of processing, with data-subject requests, security, breach notification and impact assessments; and
- Make available information necessary to demonstrate compliance.
4. Security measures
SabNode maintains measures including:
- Encryption of Customer Data in transit (TLS) and at rest;
- Role-based access control, least-privilege and authentication controls;
- Network isolation, secrets management and encrypted credential storage;
- Signed, immutable audit logs and monitoring/alerting; and
- Backup, recovery and secure software-development practices.
See our security overview for more detail.
5. Sub-processors
Customer authorises SabNode to engage sub-processors (for hosting/storage, payment processing, message and email delivery, and analytics) to provide the Service. SabNode imposes data-protection obligations on each sub-processor no less protective than this DPA and remains responsible for their performance. A current list is available on request from privacy@sabnode.com, and SabNode will give notice of new sub-processors so Customer may object on reasonable grounds.
6. Data-subject rights
Taking into account the nature of the processing, SabNode will provide product features and reasonable assistance to help Customer respond to requests from data subjects to access, correct, delete, restrict, port or object to processing of their personal data.
7. Personal-data breach notification
SabNode will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably available to help Customer meet its notification obligations to authorities and data subjects.
8. Audits
SabNode will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor, subject to reasonable notice, confidentiality and frequency limits.
9. International transfers
Where SabNode transfers Customer Data across borders, it will do so with appropriate safeguards required by applicable law (such as contractual data-protection clauses), consistent with the DPDP Act and the GDPR.
10. Return & deletion of data
On termination of the agreement, and at Customer’s choice, SabNode will delete or return Customer Data and delete existing copies within a reasonable period, unless retention is required by law. Customer can export Customer Data from the product before deletion.
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
12. How to sign & contact
To execute a countersigned copy of this DPA, or for questions, email privacy@sabnode.com. This DPA is incorporated into and forms part of your agreement with SabNode.
Questions about this document? Email privacy@sabnode.com.