goned mail

Data Processing Agreement

The Article 28 GDPR terms that apply when goned mail processes personal data on your behalf. This is Annex A to the Terms and is accepted together with them.

In effect from 8 September 2026 · version 2026-09-08

1. Parties and framework

This Data Processing Agreement (“DPA”) is entered into between the Customer, as controller (the “Controller”), and GENERAL OFFICE SOLUTIONS S.R.L., CUI 44854196, with its office at Sat Rancaciov, Com. Calinesti, nr. 9, Arges county, Romania, as processor (the “Processor”, “we”).

The DPA applies whenever, in providing the goned mail service (the “Service”), we process personal data on behalf of the Controller. It forms an integral part of the Terms of Service (/legal/terms) and is accepted together with them. In case of conflict with the Terms on data protection matters, this DPA prevails.

Capitalised terms not defined here have the meaning given in Regulation (EU) 2016/679 (“GDPR”).

2. Subject matter, duration, nature and purpose of processing

  • -Subject matter: hosting, transmitting, receiving, storing and filtering email messages and related data, through the Service.
  • -Duration: for the term of the contract between the parties, plus the retention periods set out in the Terms and this DPA.
  • -Nature of processing: storage, retrieval, transmission, anti-spam filtering, backup, and deletion operations, carried out by automated means.
  • -Purpose: solely to provide the Service to the Controller and to carry out its instructions.
  • -The categories of data and data subjects are described in Annex 1.

3. Controller's instructions

We process personal data only on the Controller's documented instructions, including with regard to international transfers, unless a legal obligation requires otherwise; in that case, we inform you before processing, unless the law prohibits this on important grounds of public interest.

The Controller's configuration of the Service (creating mailboxes, adding domains, filtering settings, portal actions) and the Terms constitute the complete initial instructions. Additional instructions may be given in writing to hello@goned.studio; if an instruction exceeds what the Service allows or is contrary to law, we will tell you.

We inform you without delay if, in our opinion, an instruction infringes the GDPR or other data protection provisions.

4. Confidentiality

We ensure that persons authorised to process the personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is necessary to provide the Service.

5. Security of processing

We implement the appropriate technical and organisational measures required by Article 32 GDPR, described in Annex 2. We may update these measures provided the level of security is not reduced.

6. Sub-processors

  • -The Controller gives a general authorisation for engaging sub-processors. The current list is in Annex 3.
  • -We impose on each sub-processor, by contract, data protection obligations equivalent to those in this DPA, in particular regarding security of processing.
  • -We remain liable to the Controller for our sub-processors' performance of their obligations.
  • -We inform you at least 30 days before any intended change adding or replacing a sub-processor, by email or through the portal. You may object on reasonable data protection grounds within that period; if we cannot reach a solution, you may terminate the affected part of the Service without penalty, as your sole remedy.

7. Assistance to the Controller

  • -Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to data subject requests to exercise their rights (Articles 12-23 GDPR).
  • -If we receive a request directly from a data subject regarding data processed on your behalf, we forward the request to you without delay and do not respond ourselves except on your instruction.
  • -We assist you in ensuring compliance with the obligations in Articles 32-36 GDPR (security, breach notification, impact assessment, prior consultation), taking into account the information available to us.

8. Personal data breach notification

We inform you without undue delay and, in any case, within 48 hours of becoming aware of a personal data breach affecting data processed on your behalf.

The notification includes, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information cannot be provided at the same time, it is provided in phases without further undue delay.

9. Deletion or return of data

On termination of the Service, at the Controller's choice, we delete or return to you all personal data processed on your behalf and delete existing copies, unless the law requires storage.

In practice: we make the data available for export for 30 days after termination; after that period, we delete it from active systems. Data remaining in backups is overwritten or deleted within the normal backup rotation cycle, within at most 180 days.

On request, we confirm the deletion in writing.

10. Audit

We make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by it.

Audits take place at most once a year (unless a supervisory authority requires otherwise or following a confirmed breach), on at least 30 days' prior notice, during business hours, without disrupting operations and respecting the confidentiality of other customers. We may first respond by providing existing documentation and security reports.

11. International transfers

Data is processed mainly within the European Economic Area. Where a sub-processor processes data outside the EEA, the transfer is covered by a valid mechanism under Chapter V GDPR, in particular the European Commission's standard contractual clauses or an adequacy decision. Per-sub-processor details are in Annex 3.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms, to the extent permitted by law. Nothing in this DPA limits liability towards a data subject or a supervisory authority under the GDPR.

13. Duration

This DPA takes effect for as long as we process personal data on the Controller's behalf and ends on completion of the deletion or return operations set out in section 9.

Annex 1 - Details of processing

Categories of data subjects

  • -users of the Controller's mailboxes (employees, collaborators, members);
  • -people who correspond with those users (senders and recipients of messages);
  • -any other person whose data is included in the content of messages, attachments or contacts, at the Controller's choice.

Categories of personal data

  • -identification and contact data: names, email addresses, phone numbers, email signatures;
  • -communication content: subject, message bodies, attachments, metadata (headers, timestamps, sending IP addresses);
  • -connection data: usernames (email addresses), IMAP, POP3 and SMTP access logs;
  • -any categories of data, including special categories under Article 9 GDPR, that the Controller or data subjects choose to include in message content. Including such data is at the Controller's discretion and responsibility.

Nature and purpose of processing

Receiving, transmitting, anti-spam filtering, storing, indexing for search, backing up and deleting email messages and related data, for the sole purpose of providing the email hosting service to the Controller.

Duration of processing

For the term of the contract, plus the retention and deletion periods in section 9 and in the Terms.

Annex 2 - Technical and organisational measures

  • -Encryption in transit: TLS required for IMAP (993), SMTP submission (587, STARTTLS) and all web traffic; TLS also required to the outbound delivery infrastructure. Certificates renewed automatically.
  • -Authentication: passwords stored as cryptographic hashes; self-service password reset; administrative access over secure channels, on a non-standard port.
  • -Access control and separation of privileges: administrative access is limited to strictly necessary personnel; privileged operations on the mail server are carried out through dedicated services with rights limited to predefined commands.
  • -Isolation: services run in containers; the portal is exposed only locally, behind a reverse proxy.
  • -Anti-abuse: anti-spam filtering (Rspamd), automatic blocking of repeated authentication attempts (fail2ban), sending rate limits, monitoring of per-account volumes and of blocklists.
  • -Monitoring and alerting: daily health checks, mail queue monitoring, DMARC report monitoring.
  • -Backups: daily backup of the email infrastructure, stored separately, transmitted encrypted; tested restore capability.
  • -Vulnerability management: automatic application of operating-system security updates; periodic configuration reviews.
  • -Logging: access and authentication logs retained for security investigations, for a limited period.
  • -Minimisation: we do not collect data beyond what is needed to provide the Service; we do not use message content for any other purpose.

Annex 3 - Approved sub-processors

Sub-processorProcessingLocationTransfer safeguards
Hetzner Online GmbHServer hosting; storage of mailboxes, portal data and backupsGermany (EEA)Not applicable - processing in the EEA
Amazon Web Services EMEA SARL (Amazon SES)Delivery (relay) of outbound email messagesIreland (eu-west-1 region, EEA); possibly USAEuropean Commission standard contractual clauses; EU-US Data Privacy Framework
Stripe Payments Europe, LimitedProcessing of payments and billing data. Does not access mailbox contentIreland (EEA); USA (Stripe, Inc.)European Commission standard contractual clauses; EU-US Data Privacy Framework

Contact

Questions about this DPA or additional instructions: hello@goned.studio.