Last updated: June 2026
This Data Processing Agreement (the "DPA") sets out the terms on which DMARC Engine ("DMARC Engine", "we", "us", the "Processor") processes personal data on behalf of a customer (the "Customer", "you", the "Controller") in connection with the DMARC Engine hosted email-authentication platform (the "Service"). The Service helps organisations configure, monitor and enforce DMARC, SPF, DKIM, MTA-STS and BIMI, including done-for-you progression to a p=reject enforcement policy.
This DPA forms part of, and is incorporated by reference into, the agreement between you and DMARC Engine for use of the Service (the "Terms", available at /terms). By accepting the Terms and using the Service, you enter into this DPA on behalf of yourself and, to the extent required by applicable data protection law, in the name and on behalf of your authorised affiliates. Where the Customer acts as a processor on behalf of its own end-customers, this DPA applies on a back-to-back basis and the Customer warrants that it is authorised to instruct DMARC Engine as a sub-processor. It governs our processing of personal data and is intended to satisfy the requirements of Article 28 of the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation ("EU GDPR"). This DPA should be read together with our Privacy Policy.
Terms used in this DPA have the meanings given to them here, and otherwise the meanings given in the applicable data protection law:
As between the parties, the Customer is the Controller (or, where the Customer is itself a processor, the processor) of the Customer Personal Data, and DMARC Engine is the Processor. DMARC Engine processes Customer Personal Data only to provide, secure, maintain and support the Service in accordance with the Terms, this DPA and the Customer's documented instructions. The subject matter, duration, nature, purpose, types of personal data and categories of data subjects are described in Annex I.
DMARC Engine separately acts as a Controller in its own right for certain limited data (for example account registration data, billing data, support correspondence and security logs) as described in our Privacy Policy. This DPA governs only the processing carried out by DMARC Engine as a Processor on the Customer's behalf.
DMARC Engine shall:
The Customer provides a general authorisation for DMARC Engine to engage Sub-processors to process Customer Personal Data, subject to this section. A current list of Sub-processors is published at /sub-processors. Our primary infrastructure Sub-processor is Cloudflare, whose Workers, D1 (database), R2 (object storage) and Workers KV (cache) products run the Service, alongside a transactional email provider and a third-party payment processor.
Because the Service runs on globally distributed infrastructure, Customer Personal Data may be transferred to or accessed from countries outside the United Kingdom or the European Economic Area. Where such a transfer takes place to a country that is not the subject of an applicable adequacy decision, DMARC Engine will ensure an appropriate transfer mechanism is in place, such as the UK IDTA, the UK Addendum, or the European Commission's SCCs, together with any supplementary measures required to ensure that the data continues to receive an essentially equivalent level of protection. To the extent the SCCs or UK IDTA apply to a transfer between the Customer and DMARC Engine, they are incorporated into this DPA by reference, the Customer is the data exporter and DMARC Engine is the data importer, and the relevant annexes are populated by Annexes I to III of this DPA.
DMARC Engine will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will, to the extent known and reasonably available to us, describe the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information. We will take reasonable steps to mitigate the effects of, and to minimise any damage resulting from, the breach, and will cooperate with the Customer and provide reasonable assistance to enable the Customer to meet any obligation it has to notify a Supervisory Authority or affected data subjects. Our notification is not an acknowledgement of fault or liability.
Taking into account the nature of the processing, DMARC Engine will provide reasonable assistance, including by appropriate technical and organisational measures and through self-service functionality in the Service where available, to enable the Customer to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability and objection under Applicable Data Protection Law. If we receive a request directly from a data subject relating to Customer Personal Data, we will, unless legally required to respond, promptly inform the data subject to contact the Customer and notify the Customer of the request rather than responding ourselves, except to the extent necessary.
Upon termination or expiry of the Service, and at the Customer's choice, DMARC Engine will delete or return all Customer Personal Data and delete existing copies, unless storage is required by law. Following a short grace period after termination to allow account recovery and data export, Customer Personal Data is deleted or irreversibly anonymised in the ordinary course of operation. Residual copies held in routine backups are deleted or overwritten in line with our backup-rotation cycle, and remain protected by this DPA until then. Retention periods for specific categories of data are described in our Privacy Policy.
DMARC Engine will make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under Article 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. To minimise disruption and to protect the confidentiality and security of other customers' data, the Customer agrees that such requests will, in the first instance, be satisfied by DMARC Engine providing relevant documentation, security summaries and, where available, the certifications and audit reports of our infrastructure providers. The Service runs on Cloudflare infrastructure, which maintains SOC 2 Type II and ISO 27001 certifications. DMARC Engine's own first-party certification status is not independently certified; our controls are designed to align with ISO 27001 and SOC 2 principles. An on-site audit may be conducted no more than once per year, on reasonable prior written notice, during business hours, subject to confidentiality undertakings, and limited to systems and facilities relevant to the processing of the Customer's Personal Data.
Each party's liability arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Terms, and any reference in the Terms to the liability of a party means the aggregate liability of that party under the Terms and this DPA together. In the event of any conflict or inconsistency between this DPA and the Terms in relation to the processing of personal data, this DPA prevails. In the event of any conflict between this DPA and the SCCs or UK IDTA, those transfer clauses prevail to the extent of the conflict in respect of the transfers they govern.
This DPA is governed by and construed in accordance with the laws of England and Wales, without prejudice to any mandatory provisions of Applicable Data Protection Law. Where the SCCs or UK IDTA apply, the governing law and forum specified in those clauses apply to the matters they govern.
This Annex describes the processing carried out by DMARC Engine as Processor on behalf of the Customer.
| Subject matter | Provision of the DMARC Engine hosted email-authentication platform, including configuration, monitoring and enforcement of DMARC, SPF, DKIM, MTA-STS and BIMI, and ingestion and analysis of DMARC reports. |
|---|---|
| Duration | For the term of the Terms, plus any post-termination period necessary for deletion or return of data and as described in section 9 and our Privacy Policy. |
| Nature and purpose | Hosting, storage, transmission, analysis, aggregation, alerting and display of email-authentication data; ingesting and parsing DMARC aggregate (RUA) and failure (RUF) reports; managing DNS configuration and delegation; sending service notifications; and providing support and security. |
| Types of personal data | Account and contact details of the Customer's authorised users (name, email, organisation, role); domain and DNS configuration and delegation tokens; and DMARC report data, which routinely contains source IP addresses, sending hostnames, authentication (SPF/DKIM/DMARC) results, message counts and limited envelope and header metadata, and in the case of failure reports may include limited message-header content. This data can relate to identifiable individuals and is therefore treated as personal data. |
| Special category data | None is intentionally processed. The Customer must not configure the Service to ingest special category data, and should not direct reports containing such data to the Service. |
| Categories of data subjects | The Customer's authorised users and administrators; and the senders and recipients of email reflected in DMARC reports for the Customer's domains, and other individuals whose data may appear within report metadata. |
| Frequency | Continuous, for the duration of the Service. |
DMARC Engine implements and maintains technical and organisational measures appropriate to the risk, designed to align with ISO 27001 and SOC 2 principles. These include:
https://dmarcengine.com/.well-known/security.txt with reports accepted via our contact page and at security@dmarcengine.com.For a fuller description of these controls, see our Security page. We may update specific measures from time to time provided the overall level of protection is not materially reduced.
The Customer authorises DMARC Engine to engage the Sub-processors listed, with their roles and processing locations, on our dedicated page at /sub-processors. That page is maintained as the current, authoritative list and is incorporated into this DPA by reference. Changes to the list are governed by section 5 (Sub-processing).
This DPA is provided in good faith and in the interests of transparency, and may be updated from time to time to reflect changes in our practices, sub-processors or legal requirements; the "Last updated" date above will reflect any revision. A countersigned copy of this DPA is available on request via legal@dmarcengine.com, and customers should have their own legal counsel review this DPA before relying on it. For any questions about this DPA or our data processing, contact legal@dmarcengine.com, or our privacy team at privacy@dmarcengine.com.