Data Processing Agreement
Effective date: September 25, 2026 Last updated: September 25, 2026
This Data Processing Agreement (the "DPA") is entered into between:
- the Customer, being the Business Customer that has accepted the Pombus Terms of Service (the "Customer" or "Controller"); and
- Willian Clayton de Almeida, an individual (natural person) domiciled in the Federative Republic of Brazil, enrolled with the Brazilian Individual Taxpayer Registry (CPF) under No. 277.866.058-51, with correspondence address provided upon request to dpo@pombus.com, who operates the Service under the trade name "Pombus" ("Pombus" or "Operator"). Pombus is not a legal entity; the Operator under this DPA is the individual named above.
Background
- (A) The Customer uses the Pombus service at pombus.com (the "Service") under the Pombus Terms of Service (the "Terms").
- (B) In providing the Service, Pombus processes personal data contained in the Customer's email on the Customer's behalf.
- (C) This DPA sets out the terms that govern that processing, as required by Article 39 of the Brazilian General Data Protection Law (Law No. 13,709/2018 — "LGPD") and, where applicable, Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679 — "GDPR") and the UK GDPR.
How this DPA is concluded. This DPA is incorporated into and forms part of the Terms, and is accepted when the Customer accepts the Terms. The Customer may request a countersigned copy by writing to dpo@pombus.com.
1. Definitions and Interpretation
1.1. "Applicable Data Protection Law" means the LGPD and the regulations of the Brazilian National Data Protection Authority ("ANPD") and, to the extent they apply to the processing of Customer Personal Data, the GDPR, the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA"), and any other data protection law applicable to that processing.
1.2. "Controller", "Operator", "Data Subject", "Processing", "Personal Data", and "Sensitive Personal Data" have the meanings given in the LGPD (controlador, operador, titular, tratamento, dado pessoal, and dado pessoal sensível). Where the GDPR applies, they have the meanings of "controller", "processor", "data subject", "processing", "personal data", and "special categories of personal data" (including personal data relating to criminal convictions and offences).
1.3. "Customer Personal Data" means Personal Data contained in Customer Content that Pombus processes on the Customer's behalf under the Agreement, as described in Annex A.
1.4. "Personal Data Incident" means a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a incidente de segurança under Article 48 of the LGPD and ANPD Resolution CD/ANPD No. 15/2024, and a "personal data breach" under Article 4(12) of the GDPR).
1.5. "Pombus Controller Data" means the Personal Data that Pombus processes as controller, as described in Section 1.2 of the Privacy Policy and in Section 15 of this DPA.
1.6. "SCCs" means, as applicable: (a) the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"); (b) the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (the "UK Addendum"); and (c) the standard contractual clauses approved by ANPD Resolution CD/ANPD No. 19/2024 (the "ANPD SCCs").
1.7. "Sub-operator" means any third party engaged by Pombus that processes Customer Personal Data (a sub-operador under the LGPD and a "sub-processor" under the GDPR).
1.8. Capitalized terms not defined in this DPA have the meanings given in the Terms.
2. Scope, Roles, and Precedence
2.1. Roles. For Customer Personal Data, the Customer is the Controller and Pombus is the Operator. If the Customer itself processes Customer Personal Data on behalf of a third-party controller, the Customer is an operator, Pombus is its Sub-operator, and the Customer warrants that the relevant controller has authorized the Customer's instructions and the engagement of Pombus.
2.2. Out of scope. This DPA does not apply to Pombus Controller Data, which Pombus processes as an independent controller under the Privacy Policy and Section 15.
2.3. Precedence. This DPA prevails over the Terms on matters concerning the processing of Customer Personal Data. If this DPA conflicts with the SCCs, the SCCs prevail.
2.4. Duration. This DPA applies for as long as Pombus processes Customer Personal Data, including after the Agreement ends and until deletion under Section 16.
2.5. Consumers. This DPA applies only to Business Customers. A Customer who uses a Mailbox for exclusively personal, non-economic purposes is not a controller under Article 4, I, of the LGPD, and this DPA does not apply to that Customer. Pombus processes the content of a Consumer's Mailbox as described in Section 1.3 of the Privacy Policy and Section 4A.12 of the Terms, remains fully subject to the LGPD for that processing, and applies to that content, as a matter of policy, the restrictions in Sections 5.3, 5.5, 6, 7, 12, and 14 and the measures in Annex B.
3. Details of the Processing
The subject matter, nature, purpose, and duration of the processing, the categories of Personal Data, and the categories of Data Subjects are described in Annex A.
4. Customer's Obligations
4.1. Lawfulness. The Customer is responsible for having a valid legal basis under Applicable Data Protection Law (including Articles 7 and 11 of the LGPD and Articles 6 and 9 of the GDPR) for the processing of Customer Personal Data, for giving Data Subjects all required notices, and for obtaining any required consent. This includes the legal basis for the international transfers described in Section 9.
4.2. Instructions and content. The Customer's instructions must comply with Applicable Data Protection Law. The Customer is responsible for the accuracy, quality, and lawfulness of Customer Personal Data and of the means by which it was obtained.
4.3. Sensitive data and minors. The Customer must not route Sensitive Personal Data through the Service, or use the Service to direct communications specifically at children or adolescents, unless the Customer has established a valid legal basis, has complied with Article 14 of the LGPD where applicable, and Pombus has agreed in writing (Section 4.3 of the Terms).
4.4. Customer-side security. Security is a shared responsibility. The Customer is responsible for the measures within its control, including choosing API Key scopes, keeping API Keys and Account credentials secure, maintaining DNS authentication for its Verified Domains, and securing its own applications and Agents.
4.5. Agents. The Customer acknowledges that processing initiated through its API Keys, whether by the Customer or by its Agents, is processing on the Customer's instructions under Section 5.2.
5. Pombus's Obligations: Documented Instructions
5.1. Instructions. Pombus will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Pombus is subject. In that case, Pombus will inform the Customer of the legal requirement before processing, unless the law prohibits it.
5.2. What counts as instructions. The Customer's documented instructions consist of:
- (a) the Agreement, including the Terms, the AUP, this DPA, and Annex A;
- (b) the Customer's configuration of the Service through the console;
- (c) API calls made with the Customer's API Keys by the Customer or its Agents (for example, to read, reply to, send, or delete messages); and
- (d) any other written instruction the parties agree.
Instructions outside the scope of the Agreement require the parties' agreement and may be subject to additional Fees.
5.3. Processing incidental to the Service. The Customer instructs Pombus to carry out the following processing as an inherent part of the Service:
- (a) delivering, receiving, storing, routing, and logging messages, and signing outbound messages with DKIM;
- (b) scanning inbound and outbound messages for spam, malware, and other security threats, including through Amazon SES;
- (c) detecting, investigating, and preventing abuse and enforcing the AUP, including reviewing metadata and, where reasonably necessary to investigate a specific abuse report, security incident, or legal request, the relevant message content, which only authorized personnel may access;
- (d) processing delivery, bounce, and complaint notifications and maintaining the Suppression List;
- (e) providing support at the Customer's request;
- (f) complying with applicable law; and
- (g) operating the shared domain pombus.com for Mailboxes provisioned as Pombus Addresses: maintaining the domain's DKIM, SPF, and DMARC; receiving and processing DMARC aggregate and failure reports and abuse, feedback-loop, and postmaster reports about the domain; handling mail addressed to unassigned, reserved, quarantined, or reclaimed pombus.com names; and renaming, migrating, quarantining, or reclaiming Pombus Addresses under Sections 4.5 and 5.5 of the AUP and Sections 9.7, 12.1, and 13.7 of the Terms. Where this processing concerns the domain as a whole rather than the Customer's own messages, Pombus carries it out as controller under Section 15.1(g) to (i) and Section 15.4.
5.4. Unlawful instructions. Pombus will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the processing concerned until the instruction is confirmed or modified. This is not a duty to provide legal advice.
5.5. No other use. Pombus will not sell Customer Personal Data, will not use it to train or fine-tune artificial intelligence or machine learning models, and will not process it for its own purposes, except as described in Section 15 and Section 8.6 of the Terms (aggregated, anonymized statistics).
5.5A. Delivery to the Customer's Agents and AI providers. When the Customer or its Agents retrieve Customer Content through the API, or when Pombus delivers it through webhooks, MCP (Model Context Protocol) connections, or any other integration the Customer configures, Pombus delivers that content to the destination the Customer chooses, on the Customer's instructions under Section 5.2. The Customer chooses the AI model provider, if any, that processes that content through its Agents. That provider is engaged by the Customer, is not a Sub-operator of Pombus, and processes the content under its own terms with the Customer; Pombus is not responsible for its processing. Pombus does not use Customer Content to train or fine-tune artificial intelligence or machine learning models (Section 5.5).
5.6. Records. Pombus will keep records of the processing it carries out on the Customer's behalf, as required by Article 37 of the LGPD and Article 30(2) of the GDPR.
5.7. Data Protection Officer. Pombus has appointed Willian Clayton de Almeida as its Data Protection Officer (Encarregado), who can be reached at dpo@pombus.com. The Encarregado is the individual who operates Pombus. As a natural person processing personal data for economic purposes, Pombus is a small-scale processing agent under ANPD Resolution CD/ANPD No. 2/2022 and appoints an Encarregado notwithstanding the exemption in Article 11 of that Resolution, in accordance with ANPD Resolution CD/ANPD No. 18/2024.
5.8. CCPA. To the extent the CCPA applies, Pombus acts as a "service provider" and will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship with the Customer; or (d) combine it with personal data received from other sources, except as the CCPA permits.
6. Confidentiality of Personnel
Pombus will ensure that personnel authorized to process Customer Personal Data: (a) access it only on a need-to-know basis and under the principle of least privilege; (b) are bound by appropriate contractual or statutory confidentiality obligations that continue after their engagement ends; and (c) receive appropriate guidance on data protection and security.
7. Security
7.1. Measures. Pombus will implement and maintain the technical and organizational measures described in Annex B, which are designed to be appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing (Articles 46 and 49 of the LGPD; Article 32 of the GDPR).
7.2. Updates. Pombus may update these measures provided that the update does not materially reduce the overall level of protection of Customer Personal Data.
7.3. Measures being implemented. Annex B distinguishes between measures in place and measures that Pombus applies or may apply as they are progressively implemented. Pombus will, on request, confirm the current status of any measure listed in Annex B.
8. Sub-operators
8.1. General authorization. The Customer gives Pombus general written authorization to engage Sub-operators. The Customer approves the Sub-operators listed in Annex C.
8.2. Flow-down. Pombus will engage each Sub-operator under a written contract that imposes data protection obligations providing at least the level of protection required by Applicable Data Protection Law and substantially the same as this DPA. The Customer acknowledges that large infrastructure providers offer their data protection terms on a standard, non-negotiable basis, and that Pombus has assessed those terms as providing sufficient guarantees.
8.3. Responsibility. Pombus remains responsible to the Customer for the performance of its Sub-operators' data protection obligations, subject to Section 17.
8.4. Notice of changes. Pombus will give at least 30 days' notice before a new Sub-operator begins processing Customer Personal Data, by updating subprocessors.html and emailing the Account owner.
8.5. Objection. The Customer may object to a new Sub-operator in writing, on reasonable data protection grounds, within 15 days after the notice. The parties will discuss the objection in good faith, and Pombus may propose an alternative. If the objection is not resolved within 30 days, the Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid, unused Fees under Section 5.7 of the Terms.
8.6. Emergency replacement. Where replacing a Sub-operator is urgently needed to preserve the continuity or security of the Service, Pombus may do so immediately and will notify the Customer as soon as possible afterwards. Section 8.5 applies from that notice.
8.7. Information. On request, Pombus will provide a summary of the data protection terms it has in place with a Sub-operator. Pombus may redact commercial information.
8.8. Destinations chosen by the Customer. Applications, Agents, AI model providers, and other destinations to which Customer Content is delivered at the Customer's instruction under Section 5.5A are not Sub-operators of Pombus and are not listed in Annex C.
9. International Transfers
9.1. Instruction to transfer. The Customer acknowledges that the Service necessarily involves transferring Customer Personal Data (a) to the United States, where Amazon SES and SNS (us-east-1) send mail and deliver event notifications; and (b) to the countries where Cloudflare operates its global edge network, for inbound routing, API and web delivery, and the web application data and encrypted backups held in Cloudflare D1 and R2. Customer Personal Data at rest remains in Brazil. The Customer instructs Pombus to carry out those transfers (Section 6.3 of the Privacy Policy).
9.2. LGPD. Transfers of Customer Personal Data out of Brazil will be carried out under a mechanism permitted by Article 33 of the LGPD, in accordance with ANPD Resolution CD/ANPD No. 19/2024. Where Pombus transfers data to a Sub-operator on the Customer's behalf, Pombus will ensure that the ANPD SCCs, or another valid mechanism under Article 33 (such as an adequacy decision issued by the ANPD), are in place with that Sub-operator.
9.3. Transparency to Data Subjects. As Controller, the Customer is responsible for informing Data Subjects about international transfers as required by Applicable Data Protection Law, including the transparency obligations of ANPD Resolution CD/ANPD No. 19/2024.
9.4. GDPR. Where the GDPR applies to the transfer of Customer Personal Data from the Customer to Pombus, and the transfer is not covered by an adequacy decision of the European Commission for Brazil, the EU SCCs are incorporated into this DPA by reference, as follows:
- (a) Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) applies where the Customer is a processor;
- (b) Clause 7 (docking clause) applies;
- (c) Clause 9(a): Option 2 (general written authorization) applies, with the notice period in Section 8.4;
- (d) Clause 11(a): the optional language does not apply;
- (e) Clause 13: the competent supervisory authority is the one determined by the Customer's establishment or representative in the EU;
- (f) Clauses 17 and 18: the law and courts of Ireland;
- (g) Annex I of the EU SCCs is completed by Annex A, Annex II by Annex B, and Annex III by Annex C of this DPA.
For onward transfers from Pombus to Sub-operators in the United States, Pombus relies on the Sub-operator's certification under the EU-U.S. Data Privacy Framework, where available, or on the EU SCCs (Module Three).
9.5. UK and Switzerland. For transfers subject to the UK GDPR, the UK Addendum applies, completed with the information in this DPA. For transfers subject to Swiss law, the EU SCCs apply with the adjustments required by the Swiss Federal Data Protection and Information Commissioner.
9.6. Transfer assessments. Pombus will provide reasonable information to help the Customer carry out any transfer impact assessment the Customer is required to perform.
9.7. Invalidated mechanisms. If a transfer mechanism is invalidated or ceases to apply, the parties will cooperate to adopt a valid alternative. If none can be adopted within a reasonable time, the Customer may suspend the affected transfer or terminate the affected Service, and Section 5.7 of the Terms applies.
10. Data Subject Requests
10.1. Assistance. Taking into account the nature of the processing, Pombus will assist the Customer, through appropriate technical and organizational measures and insofar as possible, in responding to requests from Data Subjects exercising their rights under Article 18 of the LGPD and Chapter III of the GDPR.
10.2. Self-service. Pombus provides or may provide functions in the API and console for the Customer to access, export, and delete messages; where a function is not available, Pombus will assist on request.
10.3. Requests received by Pombus. If Pombus receives a request from a Data Subject regarding Customer Personal Data, it will not respond on the merits, except to direct the Data Subject to the Customer, and will forward the request to the Customer within 5 business days where Pombus can identify the Customer concerned, unless the law requires otherwise.
10.4. Suppression List. Because the Suppression List exists to stop mail being sent to an address, Pombus may keep the minimum information needed to maintain a suppression (for example, a hashed address) even after a deletion request, so that the Data Subject's objection continues to be honored.
10.5. Costs. Pombus may charge reasonable costs for assistance that goes beyond the self-service tools, where requests are manifestly unfounded or excessive.
11. Assistance with Compliance
Using the information available to it, Pombus will provide reasonable assistance to the Customer with: data protection impact assessments (relatório de impacto à proteção de dados pessoais, Article 38 of the LGPD; Article 35 of the GDPR); prior consultations with supervisory authorities (Article 36 of the GDPR); and inquiries from the ANPD or other competent authorities concerning Customer Personal Data.
12. Personal Data Incidents
12.1. Notice. Pombus will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Incident affecting Customer Personal Data. This period is intended to allow the Customer to meet its own deadlines, including the three business days set by ANPD Resolution CD/ANPD No. 15/2024 and the 72 hours set by Article 33 of the GDPR.
12.2. Content. The notice will include, to the extent then known, and supplemented in phases as information becomes available:
- (a) the nature of the incident, including the Mailboxes, API Keys, and systems affected;
- (b) the categories and approximate number of Data Subjects and records concerned;
- (c) the likely consequences;
- (d) the measures taken or proposed to contain and mitigate the incident;
- (e) the relevant timeline, including when the incident occurred and when Pombus became aware of it; and
- (f) a contact point for further information.
12.3. Response. Pombus will take reasonable steps to contain, investigate, and mitigate the incident, preserve relevant evidence, and provide the information the Customer reasonably needs for its own incident records and communications.
12.4. Communications. As Controller, the Customer is responsible for notifying the ANPD, other supervisory authorities, and Data Subjects about incidents affecting Customer Personal Data. Pombus will not make such notifications on the Customer's behalf without the Customer's approval, unless the law requires it.
12.5. No admission. A notice under this Section is not an admission of fault or liability.
12.6. Incidents on the Customer's side. If the Customer suspects that its API Keys or Account credentials have been compromised, it must notify Pombus under Section 6.2 of the AUP. Pombus will assist with revocation and will provide the relevant audit log records.
12.7. Channel. Pombus will send notices to the Account owner's email address and to any security contact the Customer designates in the console.
13. Audits and Information
13.1. Information. Pombus will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA.
13.2. Standard evidence. Pombus will answer a reasonable security questionnaire from the Customer once every 12 months and will provide documentation of the measures in Annex B. The Customer may obtain independent audit reports and certifications for Pombus's infrastructure Sub-operators (such as AWS, Cloudflare, and Hostinger) directly from those providers, under their terms.
13.3. Audits. The Customer may carry out an audit, itself or through an independent auditor who is bound by confidentiality and is not a Pombus competitor, only if: (a) the information under Section 13.2 is not sufficient to demonstrate compliance; (b) a Personal Data Incident has occurred; or (c) a competent authority or the law requires it. The Customer must give at least 30 days' notice (except under items (b) and (c)). Audits take place during business hours, no more than once every 12 months (except under items (b) and (c)), at the Customer's cost, and must not give access to other customers' data or unreasonably disrupt the Service. The facilities of infrastructure Sub-operators are covered by their own reports under Section 13.2.
13.4. Remediation. Pombus will remedy any material non-compliance found in an audit within a reasonable time.
14. Government and Legal Requests
14.1. Handling. If Pombus receives a legally binding request from a public authority for disclosure of Customer Personal Data, Pombus will:
- (a) assess its legal validity, including whether, under the Marco Civil da Internet, it is supported by a court order where one is required;
- (b) where possible, direct the authority to request the data from the Customer;
- (c) notify the Customer promptly, unless the law prohibits it;
- (d) disclose only the minimum data necessary to comply; and
- (e) challenge the request where there are reasonable grounds to consider it unlawful.
14.2. No backdoors. Pombus has not created, and will not voluntarily create, mechanisms designed to give public authorities access to Customer Personal Data outside of legal process.
15. Pombus Controller Data
15.1. Independent controller. Pombus processes the following data as an independent controller, for security, abuse prevention, deliverability, billing, legal compliance, and the establishment or defense of legal claims (Sections 1.2 and 3.1 of the Privacy Policy):
- (a) account, billing, and authentication data, and web application session and preference data, including user avatars;
- (b) API Key metadata;
- (c) the audit log, which records sends with timestamps, the originating API Key and Mailbox, and sender and recipient addresses;
- (d) delivery, bounce, and complaint event data received through Amazon SNS;
- (e) the Suppression List;
- (f) application access logs, which Pombus keeps for at least six months following the standard of Article 15 of the Marco Civil da Internet (which binds providers organized as legal entities and may be extended to Pombus by court order under Article 15, §1) and to respond to legal orders and security incidents;
- (g) the names of Pombus Addresses assigned to Accounts and their status (active, quarantined, reclaimed), and the domain identity data of Customer Domains (DNS verification status and DKIM, SPF, and DMARC status);
- (h) DMARC aggregate and failure reports for the pombus.com domain, and abuse, feedback-loop, and postmaster reports concerning pombus.com addresses, which may contain message headers and, in failure reports, message samples; and
- (i) mail addressed to unassigned, reserved, quarantined, or reclaimed pombus.com names, which is discarded at delivery and not stored.
15.2. Message content. Pombus does not process the message bodies or attachments of the Customer's Mailboxes as controller. Any access to message content for the purposes of Section 5.3(c) or to comply with law is governed by Sections 5.3 and 14. Message samples contained in DMARC failure reports and mail under Section 15.1(i) are processed only for the purposes of Section 15.4.
15.3. Separate responsibility. Each party is separately responsible for its own compliance as controller of its own data. The parties are not joint controllers.
15.4. Shared domain. The processing in Section 15.1(g) to (i) concerns the pombus.com domain as a whole and is carried out by Pombus as controller for domain authentication, deliverability, and abuse prevention, on the basis of its legitimate interest (Article 7, IX, of the LGPD) and, for Customers subject to the GDPR, Article 6(1)(f) of the GDPR. Where a report or message under Section 15.1(h) or (i) relates to the Customer's Mailbox, Pombus uses it only for those purposes and, where it supports a measure against the Customer, discloses the relevant information to the Customer under Section 12.2 of the Terms.
16. Return and Deletion
16.1. During the term. The Customer may export and delete Customer Content through the API and console, or with Pombus's assistance on request, at any time.
16.2. On termination. The Customer may export Customer Content during the 30-day period set out in Section 13.5 of the Terms. After that period, Pombus will delete Customer Personal Data from its production systems within 30 days and from backups within a further 30 days, because each backup is deleted automatically at the end of its 30-day retention window. Backups are made daily, encrypted (GPG, AES-256) with a passphrase kept off the server, and stored in Cloudflare R2 under object lock, which keeps them immutable during the retention window. Deletion in the content-addressed blob store is designed to remove a blob once no message references it. On request, Pombus will confirm deletion in writing.
16.3. Format. Exports are provided in standard, machine-readable formats.
16.4. Exceptions. Pombus may retain Customer Personal Data where applicable law requires it, and Pombus Controller Data as described in Section 15 and Section 7 of the Privacy Policy. Retained data remains subject to this DPA's confidentiality and security obligations and will be used only for the purpose that justifies its retention.
17. Liability
17.1. Terms apply. Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions in Section 15 of the Terms, including Section 15.4 (data protection cap).
17.2. Data Subjects and authorities. Nothing in this DPA limits either party's liability to Data Subjects or authorities where Applicable Data Protection Law or the SCCs do not permit such a limitation. Between the parties, each party is liable for damage caused by its own breach of Applicable Data Protection Law or of this DPA. Under Article 42, §1, I, of the LGPD, Pombus is jointly liable only where it breaches its obligations under data protection law or fails to follow the Customer's lawful instructions. A party that pays compensation beyond its share of responsibility has a right of recourse against the other under Article 42, §4, of the LGPD.
17.3. Customer-caused damage. Pombus is not liable for damage resulting from the Customer's instructions, Customer Content, the actions of the Customer's Agents, or the Customer's own breach of Applicable Data Protection Law.
18. Term, Governing Law, and Miscellaneous
18.1. Term. This DPA has the same term as the Terms and survives as provided in Section 2.4.
18.2. Governing law and forum. This DPA is governed by the law and forum provisions of Section 17 of the Terms, except that the SCCs are governed by the law and forum they specify.
18.3. Amendments. Pombus may update this DPA to reflect changes in Applicable Data Protection Law, ANPD regulations, or transfer mechanisms, with notice under Section 18 of the Terms. No update may materially reduce the protection of Customer Personal Data without the Customer's consent. The Customer may object and terminate under Section 18.2 of the Terms.
18.4. Severability. If any provision of this DPA is held invalid, the remaining provisions remain in effect.
18.5. Contacts. Pombus: Willian Clayton de Almeida, dpo@pombus.com; postal notices to Willian Clayton de Almeida, at the correspondence address provided upon request to dpo@pombus.com. Customer: the privacy contact designated in the console, or, if none, the Account owner.
18.6. Assignment to a legal entity. If Pombus assigns the Agreement to a legal entity under Section 19.2 of the Terms, this DPA is assigned together with it, without any action by the Customer. From the effective date stated in the assignment notice, references to "Pombus" and to the "Operator" are to the assignee, which assumes all of the Operator's obligations under this DPA, including for processing carried out before that date; Pombus will state the assignee's legal name, CNPJ, and address in the notice and reflect them in Annex A and, where the EU SCCs apply, in Annex I of the EU SCCs. The assignment does not change the instructions, the Sub-operators, the measures in Annex B, or the location of processing, and any such change remains subject to Sections 7, 8, and 9.
Signatures (only where the Customer requests a countersigned copy)
| Customer | Pombus | |
|---|---|---|
| Name | Willian Clayton de Almeida | |
| Title | Operator | |
| Date | ||
| Signature |
Annex A — Description of the Processing
| Item | Description |
|---|---|
| Controller | The Customer (identification and contact details as registered in the Account). |
| Operator | Willian Clayton de Almeida, an individual, CPF 277.866.058-51, correspondence address: provided upon request to dpo@pombus.com. DPO: Willian Clayton de Almeida, dpo@pombus.com. (Replaced by the assignee's details on an assignment under Section 18.6.) |
| Subject matter | Provision of the Service: hosting Mailboxes, either as Pombus Addresses on the shared domain pombus.com or on the Customer's Verified Domains, and enabling the Customer, its Authorized Users, and its Agents to receive, read, reply to, and send individual email messages through the web application, the API, and webhooks. |
| Categories of Data Subjects | (a) The Customer's correspondents: recipients of outbound messages, senders of inbound messages to the Customer's Mailboxes, and other addressees; (b) individuals mentioned in message content or attachments; (c) the Customer's personnel whose names or addresses appear in Mailboxes; (d) where the Customer embeds the Service in its own product, that product's end users; (e) for Pombus Addresses, senders of mail addressed to the Customer's name on pombus.com, including, to the extent retained under Section 15.1(i), mail received after the name reverts and is quarantined. |
| Categories of Personal Data | Email addresses; display names; message headers (including message IDs, timestamps, and IP addresses of relaying servers in Received headers); subject lines; message bodies; attachments; any Personal Data contained in them, as determined by the Customer and its correspondents; and delivery metadata (delivery status, bounce reasons, complaint feedback) linked to messages. |
| Sensitive Personal Data | Not intended. The Customer must not route Sensitive Personal Data through the Service unless agreed in writing (Section 4.3). Because Pombus cannot control the content of inbound mail sent by third parties, any Sensitive Personal Data received incidentally is protected by the measures in Annex B. |
| Nature of the processing | Receipt, recording, storage, organization, retrieval through the API, transmission, DKIM signing, routing, spam and malware scanning, logging, and deletion. |
| Purpose | To provide, secure, and support the Service under the Agreement, as set out in Sections 5.2 and 5.3. |
| Duration | The term of the Agreement plus the export and deletion periods in Section 16. During the term, message content is retained until the Customer deletes it. |
| Frequency of transfer | Continuous, for as long as the Service is used. |
| Location of processing | Mail transit and events: United States (Amazon SES and SNS, us-east-1). Inbound routing at the edge, API and web delivery: Cloudflare's global edge network. Web application session and preference data (Cloudflare D1) and user avatars (Cloudflare R2): Cloudflare global network; no location restriction configured. Message content, attachments, and message metadata at rest: LUKS-encrypted volume on a server operated by Pombus at Hostinger, Brazil. Audit logs and application access logs: infrastructure operated by Pombus or by the Sub-operators listed in Annex C. Backups: Cloudflare R2 (Cloudflare global network; no location restriction configured), encrypted before upload. |
| Sub-operators | See Annex C. |
| Competent authority | ANPD; for GDPR-scope processing, the authority determined under Section 9.4(e). |
Annex B — Technical and Organizational Measures
B.1. Measures in place
- Mandatory domain authentication. The Service is designed to block sending from a Customer Domain until it is verified with DKIM signing, SPF (including a custom MAIL FROM domain), and DMARC (AUP Section 4.2). The shared domain pombus.com is authenticated by Pombus with DKIM, SPF (custom MAIL FROM domain), and a published DMARC policy.
- Least-privilege API Keys. API Keys are issued with scopes (read, read and reply, read and send) and can be revoked.
- Append-only audit log. Sends are recorded in an append-only, timestamped audit log tied to the originating API Key and Mailbox.
- Automatic suppression. Recipients that generate hard bounces or spam complaints are automatically suppressed, based on Amazon SES and SNS event notifications.
- Encryption in transit. HTTPS is mandatory for API and web access, through Cloudflare; TLS for mail transport with other mail servers where supported by the other server. For inbound mail to pombus.com, Pombus publishes an MTA-STS policy (https://mta-sts.pombus.com/.well-known/mta-sts.txt) in testing mode, covering the domain's MX hosts (*.mx.cloudflare.net), with SMTP TLS reporting (TLS-RPT) sent to dmarc@pombus.com. In testing mode, sending servers report TLS failures but do not refuse delivery; Pombus intends to move the policy to enforce mode once the reports show clean TLS delivery.
- Encryption at rest for message content. Message bodies, attachments, and message metadata are stored in a SQLite database and a compressed (gzip), content-addressed blob store located inside a LUKS-encrypted volume (full-volume encryption at rest) on a server operated by Pombus at Hostinger, Brazil, within an isolated container. The volume is unlocked on the server itself by keyfile/TPM, under the Operator's exclusive control; Hostinger does not receive the key.
- Inbound routing without edge storage. Inbound mail received through Cloudflare Email Routing is passed by a Cloudflare Worker to Pombus's storage backend; the Worker does not retain message bodies. All inbound mail for pombus.com, and for Customer Domains whose MX records point to Cloudflare, follows this path; Amazon SES is not used for inbound mail.
- Separation of stores. Cloudflare R2 holds user avatar images and the encrypted backups described in Section 16.2, and Cloudflare D1 holds only web application session and preference data; neither holds unencrypted message content. Cloudflare encrypts those stores at rest under its own controls.
- Infrastructure security. The Service runs on Amazon Web Services, Cloudflare, and a virtual private server at Hostinger, each of which maintains physical, environmental, and network security controls under its own policies and, where applicable, certifications and reports. Pombus hardens the server it operates with a firewall, key-based administrative access only, automatic security updates, and container isolation.
- Tenant separation. Each Customer's data is logically separated from other Customers' data.
B.2. Measures Pombus applies or may apply (being implemented progressively)
| Measure | Status |
|---|---|
| Sending limits per Account, according to the Customer's plan | Applied or being implemented |
| Maximum recipients per message: up to 10 for messages sent through an API Key; up to 100 for messages sent through the web application | Applied or being implemented |
| Automated pausing of a Mailbox or Account when its bounce rate reaches 3% or its complaint rate reaches 0.08% | Applied or being implemented |
| Operator kill-switch to halt sending immediately | Applied or being implemented |
| Rate-limiting of API requests and sending | Applied or being implemented |
B.3. Organizational measures
- A Data Protection Officer (Encarregado) has been appointed (Section 5.7).
- Personnel confidentiality and need-to-know access (Section 6).
- Personal Data Incident notification procedure (Section 12).
- Due diligence on Sub-operators before engagement (Section 8).
- Records of processing (Section 5.6).
- Data minimization and retention in line with Section 7 of the Privacy Policy.
B.4. Measures planned, not yet represented as in place
The following measures are part of the Pombus security roadmap. They are listed for transparency and are not represented as implemented until this Annex is updated to say so:
- Multi-factor authentication for the customer console and for Pombus administrative access.
- Hashed storage of API Keys.
- Periodic vulnerability scanning and penetration testing.
- Centralized security monitoring and alerting.
- Formalized secure development practices (code review, dependency scanning, secrets management).
- Independent security certification or attestation, such as a SOC 2 report. Pombus does not currently hold any such certification or report.
Annex C — Sub-operators
| Sub-operator | Service | Processing activity | Customer Personal Data concerned | Location | Transfer mechanism |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. | Amazon SES | Sending outbound email and DKIM signing; spam and malware scanning | Full message content and metadata, held transiently while in transit | United States (us-east-1) | AWS Data Processing Addendum, which includes the EU Standard Contractual Clauses; Pombus will adopt the ANPD standard contractual clauses as they become available from these providers |
| Amazon Web Services, Inc. | Amazon SNS | Delivery, bounce, and complaint notifications | Event metadata, including recipient addresses; no message content | United States (us-east-1) | As above |
| Cloudflare, Inc. | Email Routing and Workers | Receiving inbound email at the edge for pombus.com and for Customer Domains whose MX records point to Cloudflare, and passing it to Pombus's storage backend through a Worker that does not retain message bodies | Full message content and metadata, held transiently | Global edge network, which may include the United States and other regions | Cloudflare Data Processing Addendum, which includes the EU Standard Contractual Clauses; Pombus will adopt the ANPD standard contractual clauses as they become available from these providers |
| Cloudflare, Inc. | Workers, Pages, DNS, TLS termination, DDoS protection | API request handling and web application delivery | API requests and responses, which may contain message content and metadata, held transiently | Global edge network | As above |
| Cloudflare, Inc. | D1 | Storage of web application session and preference data | None. Pombus Controller Data only (Section 15.1(a)); no message content | Cloudflare global network; no location restriction configured | As above |
| Cloudflare, Inc. | R2 | Storage of user avatar images and of the encrypted backups described in Section 16.2 | Encrypted backups of message content and metadata (Cloudflare does not hold the passphrase); avatars are Pombus Controller Data only (Section 15.1(a)) | Cloudflare global network; no location restriction configured | As above |
| Hostinger | Virtual private server hosting | Hosting the server and LUKS-encrypted volume on which message content, attachments, and message metadata are stored at rest, inside a Docker container. The provider has physical and hypervisor access to the machine but does not receive the volume encryption key | Full message content and metadata at rest, in encrypted form | Brazil | Hostinger data processing terms; data at rest remains in Brazil |
Note 1: The payment processor Stripe processes only Pombus Controller Data (billing) and is not a Sub-operator for Customer Personal Data. It is disclosed in the Privacy Policy.
Note 2: Applications, Agents, and AI model providers to which Customer Content is delivered at the Customer's instruction are chosen by the Customer and are not Sub-operators of Pombus (Sections 5.5A and 8.8).
Note 3: The current version of this list is published at subprocessors.html (see legal/subprocessors.md), and changes are notified under Section 8.4.