Data processing agreement
The article 28 GDPR agreement between the customer (controller) and Ankarex (processor) on the data of recipients of messages, tests and lookups.
In a nutshell
- When you send messages, run tests or look up numbers, the data of those people is yours: you are the controller and Ankarex the processor acting on your instructions.
- We only use that data to provide the service, protect it and comply with the law; never for our own marketing.
- We apply security measures, use sub-processors with safeguards, help you with data subjects' rights and notify you without delay of any breach.
- This agreement is accepted together with the terms and is as valid as a signed one.
The summary does not replace the full text.
1. Subject matter, parties and term
This agreement governs the processing of personal data that Ankarex (“Processor”) carries out on behalf of the Customer (“Controller”) when providing the Service described in the Terms and conditions of service, in accordance with article 28 of Regulation (EU) 2016/679 (GDPR) and the applicable national law.
It is accepted electronically at sign-up or when accepting a new version in the console, forms part of the Terms and conditions of service and remains in force for as long as the Processor processes data on behalf of the Controller.
2. Description of the processing
- Nature and purpose: receiving, storing, transmitting to carriers and providers, filtering and abuse control, reporting and retaining the data necessary to send SMS, run delivery and route tests, resolve HLR lookups and deliver webhooks, on the Controller's instructions.
- Categories of data subjects: message recipients, holders of the numbers looked up or tested and, where applicable, people mentioned in the content.
- Categories of data: phone numbers, content of messages and templates, personalisation variables, senders, dates, delivery states and error codes, network, carrier and country of the numbers, results of tests and lookups.
- Special categories: not foreseen. The Controller undertakes not to enter them without prior written agreement.
- Duration: that of the contractual relationship, plus the retention periods of clause 10.
3. Controller's instructions
The Processor will process the data only on the documented instructions of the Controller, which are those resulting from these documents and from the configuration and use the Controller makes of the Service (sends, lists, schedules, webhooks, exports and deletions). If in its opinion an instruction infringes the law, the Processor will say so and may decline to carry it out.
Operations necessary to protect the Service and the data subjects (filters, blocks, traffic holds, abuse investigation) and those required by law are not contrary to the instructions; in the latter case the Processor will inform the Controller unless the law prohibits it.
4. Controller's obligations
- Have a legal basis for each processing and, where applicable, the data subjects' consent, and be able to prove it.
- Inform the data subjects of the processing and of the involvement of messaging service providers.
- Enter only necessary and accurate data and keep it up to date, including opt-outs.
- Handle data subjects' requests as controller.
- Comply with the User responsibility and acceptable use policy.
5. Processor's obligations
- Process the data only to provide the Service and in accordance with the instructions, without using it for its own purposes other than security, fraud prevention and compliance with legal obligations.
- Ensure that persons authorised to process the data have committed to confidentiality.
- Apply the security measures in the Annex and review them periodically.
- Assist the Controller, taking into account the nature of the processing, with data subjects' rights, impact assessments and prior consultations.
- Notify the Controller, without undue delay and at the latest within 48 hours of becoming aware, of any security breach affecting the data, with the information available.
- Make available to the Controller the information necessary to demonstrate compliance with this agreement and allow audits under clause 8.
- Keep a record of the processing activities carried out on behalf of the Controller.
6. Sub-processors
The Controller gives the Processor general authorisation to use sub-processors to provide the Service, in particular: hosting and infrastructure providers, carriers, aggregators and SMPP providers, HLR lookup providers, transactional email providers and text generation tool providers. By the nature of the Service, the number and content of each message necessarily reach the carriers of the destination network.
The Processor will impose on each sub-processor data protection obligations equivalent to those of this agreement and will remain liable for their compliance. It will keep an up-to-date list, available on request at [email protected], and report relevant changes; the Controller may object on reasonable grounds within fifteen days and, if no solution is reached, terminate the contract.
7. International transfers
Where processing involves transfers outside the European Economic Area, the Processor will ensure appropriate safeguards (adequacy decision, standard contractual clauses of the European Commission and supplementary measures). The Controller acknowledges that sending a message to a number in a third country requires disclosing the number and content to the carriers of that country to carry out its own instruction.
8. Audits
The Controller may verify compliance with this agreement first through the documentation and certifications the Processor makes available. If insufficient, it may carry out an audit, at most once a year, with thirty days' notice, during business hours, itself or through an independent auditor bound by confidentiality, without access to other customers' data or to information that would compromise security, and at its own cost.
9. Data subjects' rights
If a data subject contacts the Processor to exercise rights over data processed on behalf of the Controller, the Processor will forward the request to the Controller without delay. However, to protect the data subject, the Processor may block their number so that it no longer receives messages from the Controller or from the platform.
10. Retention, return and deletion
Message, test and lookup records are kept online for at least thirty days and then archived for as long as necessary for invoicing, claims and legal obligations. The Controller can export its data from the console while it is available.
When the Service ends, the Processor will delete or return the data, at the Controller's choice, except data it must keep blocked by legal obligation or to defend claims, which will be deleted at the end of those periods.
11. Liability
Each party is liable for its own breaches of data protection law. The Processor's liability is subject to the limitations of the Terms and conditions of service to the extent the law allows. The Controller shall hold the Processor harmless against claims arising from the lack of a legal basis or consent for the data it enters.
Annex. Security measures
- Encryption in transit (TLS) on the website, console, API and, where the provider supports it, on provider connections (including mutual TLS).
- Secrets and provider credentials encrypted at rest; one-way password hashing; passkeys with public keys.
- Role and permission based access control, least privilege and administrative routes available only from a session.
- API keys with scopes and IP allowlists; immediate revocation.
- Activity logging of authenticated operations without copying message content.
- Rate limits, progressive brakes against brute-force attacks and protection against abnormal traffic.
- Encrypted backups and restore procedures.
- Separation of development and production environments; fictitious test data.
- Security incident management and notification procedure.
- Training and confidentiality duty of staff with access.