Legal · Data processing terms
Data processing agreement
This agreement governs personal data processed for an Everline business customer. It takes effect when incorporated into a signed order and the required processing schedule and operational safeguards have been completed and approved.
On this page
1. When this agreement applies
The parties are Everline Global, LLC (“Everline”) and the business customer identified in a signed order (“Customer”). This agreement governs personal data processed by Everline on the Customer’s documented instructions to provide the approved messaging service (“Customer Data”). It applies after the parties have incorporated it into their signed order and completed the schedules described below.
Before activation, the parties must approve the processing scope, service providers, locations, security measures, retention periods and required transfer terms. Customer Data may be supplied only through the agreed service after this approval. Publishing or viewing this agreement does not replace execution or authorize processing.
2. Roles and applicable law
The Customer determines the purposes and essential means of its recipient communications and acts as controller. Everline acts as processor to the extent it handles Customer Data solely on those instructions. If the Customer is itself a processor, it must identify the responsible controller and confirm its authority to appoint Everline as a subprocessor.
Applicable data protection law means the laws that govern the documented processing, including the GDPR or relevant local equivalents where they apply. The parties must identify any jurisdiction-specific requirements before activation. Everline's own inquiry, relationship, billing and legal records fall under its separate controller responsibilities and Privacy notice, not an unlimited right to reuse Customer Data.
3. Documented instructions and limits
Everline will process Customer Data only to provide the approved service on the Customer's documented instructions, including instructions concerning transfers. Those instructions consist of the signed order, completed schedules and authorized service requests within the agreed scope. A request to change a channel, destination, purpose or data category requires any necessary review before the change takes effect.
Everline will inform the Customer if an instruction appears to conflict with applicable data protection law and may pause the affected processing while the parties resolve the issue. If law requires processing beyond instructions, Everline will notify the Customer before that processing unless the law prohibits notice.
Everline will not sell Customer Data, use it for its own advertising, train general-purpose models on it, or disclose it for an unrelated purpose. Any independent legal obligation must be identified and limited to what that obligation requires.
4. The Customer's responsibilities
The Customer is responsible for a lawful basis for processing and communicating with recipients, appropriate notices, required channel permissions, accurate sender identities and compliance with suppression and opt-out requirements. It must give lawful, sufficiently clear instructions and limit submitted data to what the approved service needs.
The Customer must assess whether the service and documented safeguards are suitable for its data and must not submit special-category data, criminal-offence data, payment card details, children's data or other specially regulated information unless that specific processing has been assessed and expressly approved in writing. Authentication data must be minimized and handled according to the approved security schedule.
5. Personnel and confidentiality
Everline will restrict access to Customer Data to authorized personnel who need it for their assigned duties. Personnel must be subject to an appropriate duty of confidentiality and receive instruction relevant to their responsibilities. Access must be reviewed and removed when no longer needed.
These obligations continue after an individual's access ends and after the service terminates, for as long as confidential Customer Data remains protected by the agreement or applicable law.
6. Security measures to approve before activation
The parties must attach an operational security schedule describing measures actually available for the service and appropriate to the nature and risk of the processing. Approval requires an assessment of the relevant infrastructure and suppliers, with the implemented measures recorded in the service schedule.
- Identity and access management, privileged access, credential protection and access review.
- Transmission protection and applicable protection of stored data, including management of relevant keys and secrets.
- Separation of customer data, authorized support access and protection of endpoints and administrative systems.
- Security logging, incident handling, vulnerability management and change control.
- Availability, recovery and backup arrangements, where used, with the actual recovery and retention conditions.
- Data minimization, recipient suppression, deletion, and handling of short-lived authentication material.
- Verification and periodic review of the controls appropriate to the agreed risks.
Once effective, Everline must maintain the agreed measures and must not materially reduce the protection of Customer Data without an agreed lawful change. Any certification relied on in the service schedule must be supported by applicable evidence.
7. Subprocessors and service providers
Before any subprocessor handles Customer Data, the Customer must receive its legal identity, purpose, relevant locations, categories of data and the applicable safeguards. The completed schedule must distinguish subprocessors from carriers or other providers acting as independent controllers for defined purposes. A provider is not authorized until the required disclosure and written authorization are complete.
A subprocessor may be engaged only under the Customer's prior specific written authorization or a general written authorization that includes an agreed advance-notice and objection process. Under general authorization, the Customer must have a meaningful opportunity to object on reasonable data protection grounds before the new provider handles its data. If the parties cannot resolve an objection, the affected processing must not proceed; the parties may agree an alternative or terminate the affected service and reconcile unused amounts.
Everline must impose data protection obligations appropriate to the delegated processing, including confidentiality, security, deletion and assistance obligations, and remain responsible to the Customer for the subprocessor's performance of those obligations. The relevant register is described on the subprocessor page.
8. Requests from individuals
Everline will promptly inform the Customer when it receives a request concerning Customer Data and will not decide the substance of that request unless instructed or required by law. Taking account of the processing and information available, Everline will provide reasonable assistance so the Customer can handle access, correction, deletion, objection and other applicable rights within the required time.
The Customer must provide clear instructions and use available authorized service functions where appropriate. If extraordinary assistance requires additional work, any reasonable charge must be agreed in advance and must not obstruct compliance with mandatory obligations.
9. Personal data breaches
Everline will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. The notice will identify available facts about the nature of the incident, affected data and individuals, likely consequences, measures taken or proposed and an appropriate contact. Information may be supplied in phases as the investigation develops.
Everline will take appropriate steps to contain the incident, preserve relevant evidence and assist the Customer's lawful assessment, notices and remediation. The Customer remains responsible for decisions about notifications to individuals or authorities where it is the controller. No fixed response promise is created without an operational commitment documented in the signed schedule.
10. Demonstrating compliance and assistance
Everline will make available information reasonably necessary to demonstrate compliance with this agreement and allow and contribute to proportionate audits or inspections by the Customer or its authorized independent auditor. The parties should use relevant documentation first where it is sufficient, while preserving any audit access required by law.
Audits must protect other customers' information and system security. Reasonable notice, scope and confidentiality arrangements may be agreed, but they must not prevent an urgent investigation or a regulator's lawful access. Everline will also provide reasonable assistance with required impact assessments and prior consultation, taking account of the processing and information available to it.
11. International transfers
The parties must identify processing and access locations before activation. Where a transfer requires additional legal safeguards, they must complete the applicable mechanism, assessment and supplementary measures before the transfer occurs. This may require separately executed standard contractual clauses or a locally required addendum, with the correct parties, modules and annexes.
A link to this agreement does not execute standard contractual clauses, establish an adequacy finding or authorize transfer to any country. If the required safeguards cannot be maintained, the affected transfer must be paused and the parties must agree a lawful alternative or stop that processing.
12. Return, deletion and retained records
The signed schedule must specify the service retention periods, the Customer's export or return method, the deletion process at the end of service and the treatment of backups. On completion or termination, Everline will, at the Customer's choice and subject to applicable law, return or delete Customer Data and delete remaining copies according to that agreed process.
If law requires retention, Everline will identify the requirement where permitted, protect the retained data, restrict it to the required purpose and delete it when retention is no longer required. Backup exceptions must be limited, documented and subject to an agreed deletion cycle. On request, Everline will confirm completion of the applicable deletion steps.
13. Required processing schedule
The following details must be completed for the actual order, not inferred from the website:
| Item | Required agreement |
|---|---|
| Parties and contacts | Customer, responsible controller if different, Everline and authorized privacy/security contacts. |
| Purpose and operations | Approved business use, channels, sender identities, validation, routing, transmission, receipt handling and any agreed support access. |
| Individuals and data | Relevant recipients and business users; specific contact details, message content, consent records, delivery records and any authentication material actually required. |
| Duration and retention | Service term, retention by data category, return/export arrangements, deletion timing and backup handling. |
| Locations and suppliers | Processing and access countries, provider identities and roles, subprocessor authorization and any required transfer safeguards. |
| Operational safeguards | Approved implemented measures, incident contacts, assistance process and any agreed service commitments. |
14. Priority, changes and contact
When executed, this agreement governs the processing of Customer Data in preference to a conflicting general service term. Mandatory law and any binding transfer clauses retain their required priority. Changes to the scope or safeguards must be documented and must preserve the obligations that applicable law requires.
To complete the agreement and processing schedule for an order, email contact@everlinegloballlc.com. Processing begins only after execution, operational approval and service activation.
