Skip to content

Legal

Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between PostTo and the customer ("Customer", "you") and applies to the extent PostTo processes Personal Data on your behalf as a processor in connection with the PostTo service ("Service"). It reflects the parties' agreement regarding such processing in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR") and other applicable data protection law.

1. Parties and roles

PostTo is operated by Lindgaard.net, org. nr. 987 032 596, Solstien 42, 8445 Melbu, Norway (the "Processor", "we", "us", "our").

For Personal Data contained in submissions received through your endpoints ("Submission Data"), you are the Controller and PostTo is the Processor acting on your behalf. Your end-users submit data to your forms; PostTo processes that data only to provide the Service to you.

For account-holder data (the information you provide when you register and use the dashboard), PostTo acts as an independent Controller. That processing is described in our Privacy Policy and is not governed by this DPA.

In the event of a conflict between this DPA and the Terms regarding the processing of Submission Data, this DPA prevails.

2. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR. "Sub-processor" means any third party engaged by PostTo to process Submission Data. "Standard Contractual Clauses" means the clauses adopted by the European Commission for the transfer of Personal Data to third countries.

3. Subject matter, nature, and purpose of processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1. PostTo processes Submission Data solely to receive, validate, filter for spam, store, and deliver form submissions to the destinations you configure, and to provide the related dashboard, webhook, and notification functionality.

4. Processing on documented instructions

PostTo processes Submission Data only on your documented instructions, including with regard to transfers, unless required to do otherwise by EU or member-state law (in which case PostTo will inform you of that legal requirement before processing, unless the law prohibits it). Your instructions are constituted by the Terms, this DPA, and the configuration choices you make in the dashboard (such as destination addresses, retention period, field mapping, and whether AI classification is enabled).

PostTo will inform you if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

5. Confidentiality

PostTo ensures that persons authorised to process Submission Data are bound by an appropriate obligation of confidentiality and process the data only as necessary to provide the Service.

6. Security of processing

PostTo implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. A summary of these measures is set out in Annex 2 and in section 7 of our Privacy Policy.

7. Sub-processors

You grant PostTo general authorisation to engage Sub-processors to process Submission Data. The current list of Sub-processors is published in section 5 of our Privacy Policy and forms Annex 3 to this DPA.

PostTo will inform you of any intended addition or replacement of a Sub-processor, giving you a reasonable opportunity to object on reasonable data-protection grounds before the new Sub-processor begins processing Submission Data. PostTo imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable to you for a Sub-processor's performance of those obligations.

AI classification (Anthropic). Anthropic is engaged as a Sub-processor only where you enable AI spam classification on an endpoint. This feature is optional and off by default. Baseline spam filtering is performed entirely on PostTo's own infrastructure and involves no Sub-processor. See section 6 of the Terms for details.

8. Assistance with data subject rights

Taking into account the nature of the processing, PostTo assists you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR. The dashboard provides tools to search, export (as CSV), and permanently purge Submission Data so that you can satisfy access, portability, and erasure requests directly.

9. Personal data breach

PostTo notifies you without undue delay after becoming aware of a Personal Data Breach affecting Submission Data, and provides information reasonably available to it to assist you in meeting your obligations under Articles 33 and 34 GDPR.

10. Data protection impact assessments

PostTo provides reasonable assistance to you with any data protection impact assessments and prior consultations with Supervisory Authorities that you are required to carry out under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to PostTo.

11. International transfers

PostTo's primary infrastructure is located in Europe. Where a Sub-processor processes Submission Data outside the EEA, PostTo relies on Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the GDPR, as described in section 10 of our Privacy Policy.

12. Return or deletion of data

Submission bodies (Personal Data) are automatically purged after the retention period set by your plan: 7 days (Free), 30 days (Starter), 90 days (Pro), 365 days (Scale). You may also purge Submission Data manually at any time from the dashboard.

On termination of the Service, PostTo deletes all Submission Data within 30 days, unless EU or member-state law requires storage of the Personal Data. Non-personal metadata and records required for legal, tax, or accounting purposes are retained as described in our Privacy Policy.

13. Audits and information

PostTo makes available to you all information necessary to demonstrate compliance with the obligations in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by you or an auditor mandated by you. Audits are subject to reasonable prior notice, confidentiality obligations, and must not unreasonably disrupt PostTo's operations. PostTo may satisfy an audit request by providing relevant third-party certifications or audit reports where available.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms.

15. Term

This DPA takes effect when you accept the Terms and continues for as long as PostTo processes Submission Data on your behalf.

16. Governing law

This DPA is governed by the laws of Norway, consistent with section 15 of the Terms, without prejudice to mandatory data protection law applicable in your jurisdiction.


Annex 1 — Details of the processing

Annex 2 — Technical and organisational measures

Annex 3 — Sub-processors

The current list of authorised Sub-processors, their purpose, and data location is maintained in section 5 of our Privacy Policy. PostTo notifies Customers of changes to this list as described in section 7 above. That table also lists processors PostTo engages for purposes outside the scope of this DPA (e.g. Plausible Analytics, used only for cookieless analytics on PostTo's own marketing pages); those entries do not process Submission Data and are not Sub-processors as defined in section 2.


See also: Privacy Policy · Terms of Service