Legal
Data Processing Addendum
When Snagr emails your customers, it processes their personal data on your instructions. This addendum is the Article 28 contract that governs it. It applies automatically to every account — you do not need to sign anything to be covered.
Last updated 22 September 2026
Scope
This addendum (the DPA) forms part of the Terms of Service between Snagr (Processor) and the account holder (Controller). Where it conflicts with the Terms on a data-protection matter, this DPA wins.
It covers only Customer Personal Data — the personal data Snagr reads from the Controller’s connected Polar organisation and uses to send recovery email. It does not cover the Controller’s own account data, for which Snagr is an independent controller under the Privacy Policy.
If your organisation requires a countersigned copy on paper, email tejas@snagr.sh and we will execute one on these terms.
1. Subject matter and details of processing
| Item | Detail |
|---|---|
| Subject matter | Detecting abandoned checkouts, failed renewals and cancellations in the Controller's store, and sending the recovery email sequences the Controller configures. |
| Duration | For as long as the Controller's account is open and a Polar organisation is connected. |
| Nature and purpose | Collection, storage, structuring, use, transmission by email, and erasure — solely to operate the service and report on its results. |
| Categories of data subject | The Controller's customers and prospective customers who began a checkout, hold a subscription, or previously purchased. |
| Categories of personal data | Email address, name, Polar customer identifier, checkout and order records (product, amount, currency, status, timestamps), email content sent to the data subject, and delivery and engagement events. |
| Special category data | None. The Controller must not configure Snagr in a way that transmits special category or criminal-offence data. |
2. Roles and instructions
- The Controller determines the purposes and means of processing Customer Personal Data. Snagr processes it only on documented instructions — which are given through the configuration you set in the dashboard, plus this DPA and the Terms.
- Snagr will tell the Controller if an instruction appears to infringe data-protection law, and may pause that processing until resolved.
- The Controller warrants that it has a lawful basis for the processing, that its own privacy notice discloses the use of a processor such as Snagr, and that any consent it relies on was validly obtained.
- Snagr will not sell Customer Personal Data, use it for its own marketing, or use it to train machine-learning models.
3. Confidentiality
Access to Customer Personal Data is limited to the person who operates Snagr, who is bound by this DPA not to disclose it except as described here.
4. Security
Snagr implements appropriate technical and organisational measures under Article 32, described in full in the security overview. In summary: TLS in transit, encryption at rest by our infrastructure providers, hashed passwords, least-privilege production access, and tenant isolation enforced at the query layer.
5. Subprocessors
The Controller gives general authorisation for Snagr to engage subprocessors. The current list — 8 of them — is published at /legal/subprocessors and is kept current.
- Snagr imposes on each subprocessor data-protection obligations at least as protective as those in this DPA.
- Snagr remains fully liable to the Controller for a subprocessor's performance.
- Snagr gives at least 30 days notice before a new subprocessor begins processing. The Controller may object on reasonable data-protection grounds within that period; if no workable alternative exists, the Controller may terminate the affected service and receive a pro-rata refund of prepaid fees.
6. Data subject rights
Snagr will, taking into account the nature of the processing, assist the Controller with requests to access, rectify, erase, restrict, port or object. In practice the Controller can satisfy most requests directly from the dashboard.
Where a data subject contacts Snagr instead, Snagr will not respond substantively but will forward the request to the Controller without undue delay — except for an unsubscribe, which Snagr honours immediately by adding the address to the Controller’s suppression list, because delaying it would cause continued unwanted mail.
7. Personal data breach
Snagr will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Snagr will assist the Controller with its own notification duties under Articles 33 and 34.
8. Impact assessments and audits
Snagr will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36.
Snagr will make available the information needed to demonstrate compliance with Article 28 and will allow audits by the Controller or a mutually agreed independent auditor, no more than once a year unless a regulator or a breach requires otherwise, on 30 days notice, during business hours, and subject to confidentiality. The Controller bears its own costs.
9. International transfers
Snagr operates from India and its subprocessors are located in the United States. For transfers of personal data out of the EEA, UK or Switzerland, the parties incorporate the European Commission Standard Contractual Clauses (Decision 2021/914) by reference, with:
- Module Two (controller to processor) applying;
- Clause 7 (docking) and Clause 9 option 2 (general authorisation, 30 days notice) selected;
- Clause 11 optional redress mechanism not selected;
- Clause 17 governed by the law of Ireland, with Clause 18 venue in Ireland;
- Annexes I, II and III populated by the tables in clauses 1 and 4 of this DPA and by the published subprocessor list.
For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to those Clauses.
10. Deletion and return
On disconnection
When the Controller disconnects a Polar organisation, Snagr deletes the OAuth tokens immediately and the associated store, checkout, order and customer records.
On termination
Snagr deletes remaining Customer Personal Data from the live database when the account is deleted, except where law requires retention. Residual copies in backups typically expire within 30 days.
- Suppression records stay in place for as long as the Controller’s account exists, so a suppressed address cannot be emailed again by that merchant. They are removed with the account if it is deleted.
- Aggregated, anonymised statistics that cannot be linked back to any individual may be retained.
The Controller should export anything it needs before deleting the account; after deletion the live data cannot be recovered.
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where the law does not permit that.