GDPR & Data Processing

Last updated: 24 June 2026

Beagle Software ehf. (“PostBeagle”) is committed to compliance with the EU General Data Protection Regulation (the “GDPR”) and the Icelandic Act on Data Protection and the Processing of Personal Data (No. 90/2018). This page explains how we handle personal data on behalf of our customers and how we help you meet your own obligations. It supplements our Privacy Policy.

1. Controller and processor roles

Understanding who plays which role is central to the GDPR:

DataYour roleOur role
Your account, billing and usage dataData subjectController
Contact & subscriber data you upload to send campaignsControllerProcessor

As a processor, we process your contact data only on your documented instructions and for the purpose of providing the Service.

2. Data Processing Agreement (DPA)

We make a Data Processing Agreement available to all customers, incorporating the GDPR Article 28 obligations and, where applicable, the European Commission’s Standard Contractual Clauses for international transfers. To request a copy or an executed DPA, contact us at [email protected].

3. Sub-processors

We engage a limited number of trusted sub-processors to help deliver the Service. Each is bound by data protection terms consistent with the GDPR. Our current sub-processors are:

Sub-processorPurposeLocation
RailwayCloud hosting for the PostBeagle application and its supporting servicesAmsterdam, Netherlands (EU)
SupabaseManaged database hosting for account, contact, and campaign dataDublin, Ireland (EU)
netcupServer hosting for outbound email delivery and internal service infrastructureGermany (EU)
CloudflareObject storage for uploaded media, content delivery, bot protection at signup (which processes IP addresses), and inbound email routing for bounce and complaint handlingUnited States / global edge network
Lemon SqueezyPayment processing, billing, and subscription management (Merchant of Record)United States
DeepSeekOptional AI assistance for subject lines and email design. Receives only the campaign copy, brand settings, and product details you submit to those features - not your contacts or subscriber dataChina

We will give customers reasonable notice of any new sub-processor so that you have the opportunity to object on legitimate data-protection grounds.

4. Data subject rights

The GDPR gives individuals rights over their personal data - access, rectification, erasure, restriction, portability and objection. Where PostBeagle is the controller, contact us at [email protected] to exercise these rights. Where we process data on behalf of a customer, we provide tools and assistance so that customer (the controller) can fulfil data-subject requests directly.

5. International transfers

Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards - such as Standard Contractual Clauses or an adequacy decision - to ensure an equivalent level of protection.

6. Security measures

We maintain appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, network security, logging and monitoring, and regular review of our practices. Further detail is available on request as part of our DPA.

7. Data breach notification

In the event of a personal data breach affecting data we process on your behalf, we will notify you without undue delay after becoming aware of it, and provide the information you need to meet your own notification obligations under the GDPR.

8. Data retention and deletion

We retain personal data only as long as necessary to provide the Service or comply with legal obligations. On termination, we will delete or return contact data processed on your behalf in accordance with the DPA, except where retention is required by law.

9. Data protection contact

For any data-protection matter, contact our privacy team at [email protected]. You also have the right to lodge a complaint with the Icelandic Data Protection Authority (Persónuvernd) (www.personuvernd.is) or your local supervisory authority.