Data Processing Addendum
Last updated 1 August 2026
This addendum forms part of the Terms of Service and applies where you use MastroSDR to process personal data covered by the GDPR, UK GDPR or similar law.
Roles
For prospect data you upload and emails you generate, you are the controller and we are the processor. For your own account and billing data, we are the controller. We process customer personal data only on your documented instructions, which for these purposes means your use of the product and this addendum.
Subject matter and duration
We process personal data for as long as your account is open, plus a short deletion window described below.
Nature and purpose
Storing prospect records, generating outreach email from them, delivering that email through the provider you connect, and recording delivery outcomes. Generation uses the AI provider you connect; if you have not connected one and your plan includes an AI allowance, it uses ours until that allowance runs out.
Categories of data subject
Your prospects and contacts, and your own users.
Categories of personal data
Business contact details (name, work email, company, website, location), the content of emails you generate and send, and delivery events. You should not upload special category data; the product is not designed for it.
Our obligations
- Process personal data only on your instructions, unless the law requires otherwise.
- Ensure people authorized to process it are bound by confidentiality.
- Apply appropriate technical and organizational measures (see Security).
- Help you respond to data subject requests, and with impact assessments and regulator consultations, taking into account the information available to us.
- Tell you without undue delay if we become aware of a personal data breach affecting your data.
- Delete or return personal data at the end of the service, subject to the exception below.
- Make available the information needed to demonstrate compliance with this addendum.
Your obligations
- Ensure you have a lawful basis to upload and contact each person in your lists.
- Provide any notice and obtain any consent required where you operate.
- Respond to data subject requests relating to your prospects; you control that data.
- Not upload special category data or data about children.
Subprocessors
You give general authorization for us to use the subprocessors listed on our subprocessors page. We will notify account owners before adding a new one that processes customer personal data, and you may object on reasonable data protection grounds. We remain responsible for their performance.
The AI and email providers you connect are your choice and your contractual relationship. We pass data to them because you instructed us to by connecting the key. The provider behind the AI allowance included with a paid plan is ours rather than yours, and is listed on the subprocessors page; connecting your own AI key stops it processing your data from that point on.
International transfers
Where personal data is transferred outside the UK or EEA, we rely on an appropriate transfer mechanism such as the Standard Contractual Clauses. The destination depends on the hosting region and the providers you connect.
Deletion
On account closure we delete customer personal data within 30 days. That includes the suppression list: closing a workspace removes its do-not-contact entries along with everything else, because we do not keep a record of individuals once the controller relationship ends. While a workspace is open, suppression entries cannot be deleted by anyone, which is what stops someone who opted out being contacted again inside it.
Audit
We will respond to reasonable written information requests needed to confirm compliance, no more than once a year unless a regulator requires otherwise.