European Data Processing Addendum

 

This Data Processing Addendum ("DPA") applies where the End Customer is established in the European Economic Area, the United Kingdom, or Switzerland, or where the processing of End Customer Personal Data is otherwise subject to applicable European data protection laws. Where applicable, this DPA forms part of the Principal Agreement between the End Customer and Stimulus. The Principal Agreement remains binding and in effect, with this DPA forming an extension of its terms. MailArchiva is copyright Jamie Band © 2006–2026. Stimulus Tech is a licensed global distributor of the MailArchiva software.

 

1. Definitions.

 

The following definitions apply to this DPA. Capitalized terms not otherwise defined have the same meaning as in the Principal Agreement.

 

(a) "End Customer Personal Data" refers to any personal data processed by Stimulus on behalf of the End Customer to provide the Services under the Principal Agreement.

 

(b) "Applicable Data Protection Laws" refers to the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and any laws implementing, replacing, amending, or supplementing them, to the extent applicable to the processing of End Customer Personal Data under this DPA.

 

(c) "GDPR" refers to the EU General Data Protection Regulation 2016/679.

 

(d) "UK GDPR" refers to the GDPR as incorporated into the laws of the United Kingdom under the European Union (Withdrawal) Act 2018, as amended or replaced from time to time.

 

(e) "Stimulus Infrastructure" refers to: (i) Stimulus’s physical facilities; (ii) hosted cloud infrastructure; and (iii) Stimulus’s corporate network and the non-public internal network, software, and hardware necessary to provide the Services and controlled by Stimulus, to the extent used to provide the Services.

 

(f) "Restricted Transfer" means the transfer of End Customer Personal Data from Stimulus to a sub-processor that would be prohibited by Applicable Data Protection Laws without appropriate safeguards required under Applicable Data Protection Laws.

 

(g) "Services" refers to the services provided to the End Customer by Stimulus under the Principal Agreement.

 

(h) "Standard Contractual Clauses" refers to the latest version of the standard contractual clauses for the transfer of personal data to processors established in third countries under the GDPR.

 

(i) "UK Addendum" refers to the United Kingdom Addendum to the EU Commission Standard Contractual Clauses.

 

(j) The terms "consent," "controller," "data subject," "Member State," "personal data," "personal data breach," "processor," "sub-processor," "processing," "supervisory authority," and "third party" have the meanings given to them in Article 4 of the GDPR.

 

2. Compliance with Applicable Data Protection Laws

 

(a) Each Party shall comply with its respective obligations under Applicable Data Protection Laws in relation to the processing of End Customer Personal Data under this DPA.

 

3. Details and Scope of the Processing

 

The Agreement outlines the terms for processing the End Customer Personal Data in compliance with Article 28(3) of the GDPR. The parties may amend these terms as necessary to meet legal requirements. The scope and duration of the Personal Data processing is defined in the Principal Agreement, while the nature and purpose of processing involves Stimulus providing data archiving services to the End Customer, which includes providing services, resolving technical issues, and responding to support requests. The Personal Data processed includes name, email, telephone numbers, physical addresses, IP address, calendar, contact, file and email content. The data subjects to whom the Personal Data relates are the senders and recipients of the email and file, calendar and contact entry owners.

Stimulus will process the End Customer Personal Data only to fulfill its obligations under the Principal Agreement and in accordance with the documented instructions in this DPA or as instructed by the End Customer. If Stimulus finds that an End Customer instruction contradicts the provisions of the Principal Agreement or the DPA or infringes GDPR or other data protection regulations, Stimulus will notify the End Customer and may defer performing the instruction until it has been amended or agreed upon. The End Customer is solely responsible for managing and utilizing the Personal Data submitted or transmitted through the Services, including verifying recipient addresses, notifying recipients of email's insecure nature, limiting the disclosed information, and encrypting the Personal Data if required by law. If the End Customer chooses not to configure mandatory encryption, the Services may transmit unencrypted email in plain text over public networks. The Stimulus Infrastructure stores the uploaded information in an encrypted format.

 

4. Controller and Processor

 

(a) Under this DPA, the End Customer is the controller of their own Personal Data while Stimulus is the processor, except when the End Customer themselves act as a processor, in which case Stimulus becomes a sub-processor.

(b) Stimulus shall designate a privacy contact to assist the End Customer with data protection matters relating to the Services, to the extent reasonably required under Applicable Data Protection Laws. The privacy contact may be reached at privacy@stimulustech.io.

(c) The End Customer guarantees that:

(i) The processing of their Personal Data is legally grounded as required by Applicable Data Protection Laws and that they have obtained and will maintain all necessary rights, permissions, registrations, and consents in compliance with Applicable Data Protection Laws, related to Stimulus's processing of their Personal Data under this DPA and the Principal Agreement.

(ii) They are authorized to transfer their Personal Data to Stimulus and allow it to process their Personal Data, so that Stimulus can lawfully use, process, and transfer the End Customer Personal Data to provide the Services and fulfill other obligations under this DPA and the Principal Agreement.

(iii) They will notify their Data Subjects about their use of Processors in processing their Personal Data, to the extent required by Applicable Data Protection Laws.

(iv) They will respond to Data Subject inquiries about the processing of their Personal Data in a reasonable time and provide timely instructions to the Processor as appropriate.

 

5. Confidentiality

 

Stimulus is responsible for ensuring that all of its personnel, as well as any sub-processors it employs, who are authorized to process the End Customer Personal Data, are bound by confidentiality obligations or professional/statutory obligations of confidentiality. Additionally, they must receive appropriate training on the relevant security and data protection requirements.

 

6. Technical and Organizational Measures

 

(a) Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Stimulus shall implement appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.

 

(b) Stimulus shall provide reasonable assistance to the End Customer, at the End Customer’s cost, in relation to the End Customer’s security obligations under Applicable Data Protection Laws, taking into account the nature of the processing and the information available to Stimulus.

 

7. Data Subject Requests

 

Where Stimulus receives a request from a data subject relating to End Customer Personal Data, Stimulus shall, to the extent legally permitted, notify the End Customer within a reasonable time. Stimulus shall not respond to such request except on the documented instructions of the End Customer or as required by law. Taking into account the nature of the processing, Stimulus shall provide reasonable assistance to the End Customer, at the End Customer’s cost, to enable the End Customer to respond to data subject requests to the extent required by Applicable Data Protection Laws.

 

8. Personal Data Breaches

(a) If Stimulus becomes aware of a personal data breach affecting End Customer Personal Data, Stimulus shall notify the End Customer without undue delay. Taking into account the nature of the processing and the information available to Stimulus, Stimulus shall provide reasonable information to assist the End Customer in meeting any breach notification obligations under Applicable Data Protection Laws.

 

9. Data Protection Impact Assessments

(a) Taking into account the nature of the processing and the information available to Stimulus, Stimulus shall provide reasonable assistance to the End Customer, at the End Customer’s cost, with data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Applicable Data Protection Laws.

 

10. Audits

(a) Upon reasonable written request, Stimulus shall make available information reasonably necessary to demonstrate compliance with this DPA. Any audit or inspection shall be subject to reasonable notice, confidentiality obligations, security requirements, and shall not unreasonably interfere with Stimulus’s business operations.

 

11. Return or Destruction of the End Customer Personal Data

 

(a) The return, export, retention, and deletion of the End Customer Personal Data following termination or cancellation of the Principal Agreement shall be governed by the Principal Agreement.

(b) Where required by Applicable Data Protection Laws, Stimulus shall delete or return the End Customer Personal Data after termination or cancellation of the Principal Agreement, except where retention is required by law or permitted under the Principal Agreement.

(c) Any additional costs associated with the return, export, retention, or deletion of the End Customer Personal Data following termination or cancellation of the Principal Agreement shall be the responsibility of the End Customer, in accordance with the Principal Agreement or any applicable written quote.

 

12. Data Transfers

 

(a) The Standard Contractual Clauses and, if required, the UK Addendum, which designate Stimulus as the data importer and the End Customer as the data exporter, are incorporated into this DPA. If Stimulus engages a sub-processor that involves a Restricted Transfer, Stimulus shall ensure that the onward transfer provisions of the Standard Contractual Clauses and/or UK Addendum are included in the Principal Agreement, or are otherwise entered into, between Stimulus and the sub-processor. The End Customer agrees to exercise its audit right in the Standard Contractual Clauses by instructing Stimulus to conduct the audit set out in Paragraph 10.

(b) The End Customer acknowledges and agrees that, in connection with the provision of Services under the Agreement, Stimulus may transfer Personal Data within its company group. These transfers are necessary to provide the Services globally and are justified for internal administration purposes.

(c) For transfers of Personal Data from the European Union, the European Economic Area, and/or their member states, Switzerland, and the United Kingdom to countries that do not ensure an adequate level of Data Protection under Data Protection Laws of the foregoing territories, and to the extent that such transfers are subject to Data Protection Laws and Regulations and in order to implement appropriate safeguards, the following safeguards are taken: (i) Standard Contractual Clauses as per the European Commission’s Decision 2021/914/EU of June 4, 2021, (ii) UK Addendum, and (iii) additional safeguards with respect to security measures including data encryption, access controls, logical separation, and data minimization principles.

 

13. Sub-processing

 

(a) The End Customer authorizes Stimulus to engage the sub-processors listed in Annex 3 and any replacement or additional sub-processors appointed in accordance with this clause 13.

 

(b) Sub-processors will be bound by written agreements imposing data protection obligations no less protective than those required by this DPA to the extent applicable to the services provided by the sub-processor.

 

(c) Stimulus will notify the End Customer in writing before appointing any new sub-processor. If the End Customer objects to the proposed appointment with reasonable grounds within ten (10) business days of receiving the notice, Stimulus will not appoint the sub-processor until reasonable steps have been taken to address the objections and the End Customer has been provided with a reasonable written explanation of the steps taken. If the parties cannot resolve the appointment of a sub-processor within a reasonable period, either party may terminate the Principal Agreement for cause.

 

(d) Stimulus shall remain responsible for the performance of its sub-processors’ obligations in relation to End Customer Personal Data to the extent required by Applicable Data Protection Laws.
 

14. Governing law and jurisdiction

 

(a) The parties agree to abide by the jurisdiction designated in the Principal Agreement for any disputes or claims arising under this DPA, including disputes concerning its validity, termination, or the effects of its invalidity.

(b) This DPA, along with any non-contractual or additional obligations arising out of or related to it, shall be governed by the laws of the country or territory specified in the Principal Agreement for such purposes.

15. Order of precedence

 

(a) In the event of any inconsistency between this DPA and the Principal Agreement, this DPA shall prevail only in relation to the processing of personal data to the extent required by Applicable Data Protection Laws.

(b) The Principal Agreement shall prevail in relation to commercial terms, fees, payment, suspension, termination, service access, Export Fees, post-termination Service Fees, and service-specific data export procedures.

 

16. Severance

 

If any provision of this DPA is deemed invalid or unenforceable, the rest of the DPA shall still remain valid and in effect. The invalid or unenforceable provision will either be (i) modified as necessary to make it valid and enforceable, while preserving the parties' intentions as closely as possible or, if modification is not possible, (ii) interpreted as if the invalid or unenforceable part had never been included in the DPA.

 

17. Termination

 

(a) This DPA shall remain in effect for as long as Stimulus processes End Customer Personal Data on behalf of the End Customer. Termination of the Principal Agreement shall not affect any provision of this DPA that is intended to survive termination, including provisions relating to confidentiality, security, return or deletion of personal data, data transfers, and audit or compliance obligations.
(b) No amendment or variation to this DPA shall be considered binding on the Parties unless it is in writing and signed by authorized representatives of each Party.


IN WITNESS WHEREOF, this DPA and the Annexes are entered into and become a binding part of the Principal Agreement with effect from the date first set out above.

 

Stimulus Tech

Signature:


Name:


Title:

 

The End Customer


Signature:


Name:


Title:


Date Signed:

 

ANNEX 1

 

STANDARD CONTRACTUAL CLAUSES

With regard to the Standard Contractual Clauses the Parties agree that:


(a) Module 2 (Controller-to-Processor) will apply where Stimulus acts as End Customer’s data processor; Module 3 (Processor-to-Processor) will apply where Stimulus acts as End Customer sub-processor. For each Module, where applicable:

(b) Clause 7 (Docking clause) is incorporated;

(c) For the purposes of Clause 9.a) (Use of sub-processors), Option 2: General written authorization shall apply. The data importer has the data exporter’s general authorization for the engagement of sub-processors from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least ten (10) business days in advance;

(d) The optional wording in Clause 11 (Redress) on independent resolution bodies is not incorporated;

(e) For the purpose of Clause 13 (Supervision), the Irish Data Protection Commission shall act as the competent supervisory authority.

(f) Option 1 of Clause 17 (Governing law) shall apply and the laws of Ireland shall govern the Standard Contractual Clauses.

 

ANNEX 2

 

INFORMATION SECURITY – TECHNICAL AND ORGANISATIONAL MEASURES

 

Where personal data is processed or used automatically, Stimulus implements technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure, taking into account the nature of the processing, the risks involved, the state of the art, and the costs of implementation.

 

Physical Access Control

 

To help prevent unauthorised physical access to personal data processing systems, Stimulus uses reputable data centre and cloud infrastructure providers that maintain physical security controls, which may include controlled access, surveillance, monitoring, and other industry-standard safeguards.

 

System Access Control

 

To help prevent unauthorised use of data processing systems, Stimulus applies access control measures appropriate to the Services, which may include:

 

• role-based access controls and the principle of least privilege;

• unique user accounts for authorised personnel;

• multi-factor authentication for administrative or sensitive access where appropriate;

• network access controls, security groups, or equivalent restrictions;

• monitoring tools designed to detect suspicious or unauthorised activity;

• controls designed to mitigate common network-based threats; and

• onboarding and offboarding procedures for personnel with access to relevant systems.

 

Data Access Control

 

To help ensure that only authorised users access personal data, Stimulus applies data access controls appropriate to the Services, which may include:

 

• password and authentication controls;

• access restrictions based on job role and business need;

• session timeout or workstation locking controls where appropriate;

• logging and monitoring of relevant access and security events;

• patch management and vulnerability management processes; and

• logical separation of customer environments.

 

Data Transmission Control

 

To help protect personal data during transmission and storage, Stimulus applies measures appropriate to the Services, which may include:

 

• encryption of personal data at rest where supported by the relevant system or storage provider;

• encryption of data in transit using industry-standard transport encryption;

• secure communication channels between customer applications and Stimulus infrastructure;

• encrypted backups where applicable; and

• periodic review of encryption and transmission controls.

 

Input Control

 

To support traceability of relevant system activity, Stimulus maintains logging and monitoring controls appropriate to the Services. Such logs may record access, modifications, security events, and administrative activity, subject to system capabilities, retention settings, and operational requirements.

 

Availability Control

 

To help protect personal data against accidental loss or destruction, Stimulus applies availability and resilience measures appropriate to the Services, which may include:

 

• use of reputable third-party object storage providers;

• backups of configuration, index, or operational data where applicable;

• monitoring and alerting for relevant infrastructure components;

• patching and vulnerability remediation processes; and

• logical separation of customer environments.

 

Stimulus may update or modify these technical and organisational measures from time to time, provided that such updates do not materially reduce the overall level of security provided for End Customer Personal Data under the Services.

 

ANNEX 3

 

AUTHORIZED SUB-PROCESSORS AS OF THE DPA EFFECTIVE DATE

 

Infrastructure Sub-Processors

 

Company: Hetzner Online GmbH
Server Location: Germany
Description of Activities: Compute infrastructure for mailarchiva.eu
Appropriate Safeguards for transfers: SCCs, encryption, access controls

 

Company: Backblaze
Server Location: Amsterdam, Netherlands
Description of Activities: Object storage for mailarchiva.eu
Appropriate Safeguards for transfers: SCCs, encryption, access controls

 

Company: Wasabi
Server Location: Amsterdam, Netherlands
Description of Activities: Object storage for mailarchiva.eu
Appropriate Safeguards for transfers: SCCs, encryption, access controls

 

Company: OVH Cloud Inc.
Server Location: Oregon, United States
Description of Activities: Compute infrastructure for archiva.com
Appropriate Safeguards for transfers: SCCs, encryption, access controls

 

Company: Backblaze
Server Location: California and Arizona, United States
Description of Activities: Object storage for archiva.com
Appropriate Safeguards for transfers: SCCs, encryption, access controls

 

Group Company Sub-Processors

 

Company: Stimulus Software LLC

Headquarters: United States

 

Description of Activities: Where applicable, billing, invoicing, payment administration, customer account administration, and related business operations. This may include processing limited customer contact, billing, and account information, but does not include hosting or storage of archived email data.

Appropriate Safeguards for transfers: SCCs, encryption, access controls, confidentiality obligations

Create your own Knowledge Base