Bitelio

Data Processing Agreement

Last Updated: July 13, 2026

This Data Processing Agreement ("DPA") is incorporated into, and forms an integral part of, the Terms of Service concluded between you ("Customer", "Data Controller") and Overthings, S.L., a Spanish limited liability company with Tax ID (CIF) B57925703 and registered office at Pl. Alexandre Jaume 3, 2, 07002 Palma (Illes Balears), Spain, which operates the Bitelio service ("Bitelio", "Processor", "we", "us"). It sets out the terms under which Personal Data is processed in compliance with the GDPR.

GDPR Requirement: Article 28 of the GDPR makes an agreement of this kind mandatory. Your use of Bitelio's hosted service constitutes your acceptance of, and agreement to be bound by, this DPA.

1. Definitions

Capitalized terms in this DPA carry the meanings given to them in the GDPR. In particular:

  • "Personal Data" refers to any information concerning an identified or identifiable natural person that is processed through Bitelio
  • "Data Controller" refers to the Customer, being the party that decides why and how Personal Data is processed
  • "Data Processor" refers to Overthings, S.L., operating the Bitelio service, which carries out the processing of Personal Data on the Data Controller's behalf
  • "Sub-processor" refers to any third party that Bitelio engages to carry out processing of Personal Data
  • "Data Subject" refers to the natural persons to whom the processed Personal Data relates (your contacts and subscribers)
  • "GDPR" refers to Regulation (EU) 2016/679 (the General Data Protection Regulation)

2. Scope & Applicability

Hosted Service

This DPA governs the use of Bitelio's hosted service at bitelio.com, which is the sole manner in which the Bitelio service is made available.

Agreement Hierarchy

This DPA complements the Bitelio Terms of Service and Privacy Policy. Where those documents conflict on matters of data processing, the following order of precedence applies:

  1. This DPA prevails first
  2. The Terms of Service apply next
  3. The Privacy Policy applies last

Acceptance

By using Bitelio's hosted service, you confirm that you have read and understood this DPA and consent to be bound by its terms. It thereby becomes a legally binding contract between the Customer and Overthings, S.L.

3. Processing Details

In accordance with GDPR Article 28(3), the processing activities are described as follows:

Subject Matter

The processing of Personal Data to the extent needed to deliver email automation, transactional email, marketing campaign, and workflow automation services.

Duration

Personal Data is processed for as long as your Bitelio subscription or account remains active, and until you request deletion of your account. API logs are additionally retained for 30 days, after which they are removed automatically.

Nature & Purpose

  • Storage and administration of contact databases
  • Dispatch of transactional, marketing, and workflow-triggered emails
  • Recording of email delivery, opens, clicks, bounces, and complaints (in accordance with your settings)
  • Administration of email templates and automation workflows
  • Handling of email events and webhooks
  • Generation of analytics and reporting

Type of Personal Data

  • Email addresses (mandatory)
  • Names and custom contact fields (optional and defined by the Customer)
  • Email content, including subject lines, message bodies, and attachments
  • Subscription status and preferences
  • Email activity records (opens, clicks, bounces, complaints)
  • Timestamps and associated metadata

Categories of Data Subjects

  • Subscribers and contacts belonging to the Customer
  • Individuals who receive transactional emails
  • Individuals who receive marketing campaigns
  • Individuals who receive workflow automation emails

4. Data Processor Obligations

In its capacity as Data Processor, Bitelio undertakes the following:

Processing Instructions

  • To process Personal Data solely on the Customer's documented instructions (as given through the API, the dashboard, and similar means)
  • To refrain from processing Personal Data for any other purpose unless the Customer has given prior written consent
  • To inform the Customer immediately if, in Bitelio's view, an instruction infringes the GDPR or other EU data protection laws

Confidentiality

  • To ensure that every person authorized to process Personal Data is subject to a duty of confidentiality
  • To keep all Personal Data processed through Bitelio confidential
  • To withhold Personal Data from third parties unless disclosure is required by law or the Customer has consented

Cooperation

  • To support the Customer in handling Data Subject rights requests (see Section 7)
  • To support the Customer in meeting its GDPR obligations concerning security, breach notification, and data protection impact assessments
  • To supply the information needed to demonstrate compliance with Article 28

5. Security Measures

Pursuant to GDPR Article 32, Bitelio maintains technical and organizational measures designed to provide a level of security proportionate to the risk involved:

Technical Safeguards

  • Passwords hashed using industry-standard algorithms and never held in plaintext
  • API access restricted to HTTPS (TLS 1.2 or higher)
  • TLS/SSL encryption applied to database connections
  • Cookies configured as HttpOnly and secure, with appropriate SameSite attributes
  • Authentication tokens subject to limited validity periods
  • Rate limiting in place to counter brute force attempts

Organizational Safeguards

  • Access controls that restrict which personnel can reach Personal Data
  • Automated monitoring of bounce and complaint rates
  • Ongoing application of security updates and patches
  • Per-project data segregation (isolated multi-tenancy)

Data Residency

  • Primary data storage located in the EU/EEA (Hetzner infrastructure)
  • Databases and file storage kept within the EU/EEA
  • Email delivery may pass through non-EU regions (see Section 9)

6. Sub-Processors

The Customer grants Bitelio authorization to use the sub-processors listed below for the processing of Personal Data:

Sub-ProcessorServiceLocationPurpose
Amazon Web Services (AWS SES)Email DeliveryGlobal (data in transit only)Sending emails to recipients
Stripe, Inc.Payment ProcessingUSA (PCI-DSS compliant)Billing for paid accounts
Hetzner Online GmbHInfrastructure HostingEU/EEA (Germany)Database and application hosting

Sub-Processor Obligations

  • Every sub-processor is subject to data protection commitments equivalent to those set out in this DPA
  • Bitelio remains fully answerable to the Customer for how its sub-processors perform
  • Each sub-processor has entered into a Data Processing Agreement with Bitelio

Changes to Sub-Processors

  • Bitelio will give 30 days advance notice by email before adding or replacing any sub-processor
  • The notice will be delivered to the email address linked to your account
  • Should you object on reasonable data protection grounds, you may terminate your account within 30 days
  • The current sub-processor list will be kept up to date on this page (refer to the "Last Updated" date)

7. Data Subject Rights

Bitelio will support the Customer in responding to Data Subject rights requests under GDPR Articles 15-22:

Self-Service via API

Most Data Subject requests can be handled by the Customer directly through the API:

  • Access (Art. 15): Retrieve a contact's data using GET /contacts/:id
  • Rectification (Art. 16): Correct a contact's data using PATCH /contacts/:id
  • Erasure (Art. 17): Remove a contact using DELETE /contacts/:id
  • Restriction (Art. 18): Set the contact's subscription status to "unsubscribed"
  • Portability (Art. 20): Access the data in JSON format through the API

Assistance from Bitelio

Where a request cannot be completed via the API, the Customer may write to legal@bitelio.com:

  • Include the Data Subject's email address and a description of the request
  • Bitelio will reply within 10 business days with the requested information or assistance
  • Verifying the Data Subject's identity before any information is disclosed remains the Customer's responsibility

Email Activity Data

  • Opens, clicks, bounces, and complaints are tied to the corresponding contact records
  • When a contact is deleted, the associated email activity is deleted along with it
  • API logs (which contain no Personal Data) are purged automatically after 30 days

8. Data Breach Notification

Notification Obligation

Should a Personal Data breach affect Customer data, Bitelio will:

  • Inform the Customer without undue delay, and in any event within 72 hours of becoming aware of the breach (in line with GDPR Art. 33)
  • Direct the notification to the primary email address on the Customer's account
  • Supply the information the Customer needs to satisfy any GDPR breach reporting duties of its own

Breach Information

Each notification will set out, insofar as the information is available:

  • The nature of the breach and what occurred
  • The categories and approximate number of Data Subjects concerned
  • The categories and approximate number of Personal Data records concerned
  • The consequences the breach is likely to have
  • The measures taken or planned to address the breach and limit its harm
  • A contact point for further information (legal@bitelio.com)

Customer Responsibility

  • Where GDPR Art. 33 so requires, notifying the competent supervisory authority is the Customer's responsibility
  • Where GDPR Art. 34 so requires, notifying the affected Data Subjects is likewise the Customer's responsibility
  • A breach notification from Bitelio to the Customer does NOT amount to legal or compliance advice

9. International Data Transfers

Primary Storage (EU/EEA)

  • Contact data, templates, workflows, and account data are all stored within the EU/EEA (Hetzner, Germany)
  • Stored Personal Data is not routinely transferred outside the EU/EEA

Data in Transit (Email Delivery)

In the course of delivering emails to recipients, Personal Data may pass through regions outside the EU:

  • AWS SES handles email delivery on a global basis
  • Such data is in transit only and is not retained long-term outside the EU/EEA
  • These transfers are safeguarded by the AWS Data Processing Agreement and Standard Contractual Clauses (SCCs)

Payment Data (Stripe)

  • Payment details, including credit cards, are handled by Stripe, a US-based provider
  • Stripe holds PCI-DSS Level 1 certification
  • These transfers are safeguarded by Stripe's Data Processing Agreement and Standard Contractual Clauses
  • Bitelio does NOT hold credit card numbers itself; Stripe tokenizes them

Standard Contractual Clauses

Every sub-processor handling Personal Data outside the EU/EEA has signed Standard Contractual Clauses (SCCs) approved by the European Commission, which supply the appropriate safeguards for international transfers required by GDPR Article 46.

10. Audits & Compliance

Information Provision

Bitelio will provide the Customer with the information needed to demonstrate that its GDPR Article 28 obligations are being met, including:

  • This DPA, which is publicly accessible
  • The Privacy Policy, which describes the processing activities
  • The sub-processor list set out in Section 6 above
  • Documentation of security measures, provided upon reasonable request

Audit Rights

The Customer is entitled to audit Bitelio's adherence to this DPA on the following conditions:

  • No more than one audit per year, unless a supervisory authority requires otherwise
  • A written request must be sent to legal@bitelio.com with 30 days notice
  • The audit must be carried out by an independent third-party auditor under confidentiality obligations
  • Audits take place during business hours and must keep operational disruption to a minimum
  • All audit costs are borne by the Customer
  • The scope is confined to GDPR compliance and does not extend to general security assessments

Alternative to Audits

Rather than carrying out a full audit, the Customer may ask to review sub-processor certifications and compliance documentation (such as SOC 2 or ISO 27001 reports) where these are available.

11. Data Deletion & Return

Account Deletion

Upon deletion of the Customer's Bitelio account (through the dashboard or by request):

  • All Personal Data is removed from production systems immediately
  • Deletion is permanent; there is no grace period or recovery window
  • The Customer should retrieve or back up its data through the API beforehand, as Bitelio does NOT offer a data export facility
  • The deletion covers contacts, emails, templates, workflows, campaigns, and email activity records

Backup Retention

  • Deleted data may persist in encrypted backups for up to 30 days, solely for disaster recovery purposes
  • Once the account is deleted, backup data can be neither accessed nor restored
  • Backups are overwritten automatically once the retention period elapses

Legal Retention

Where the law so requires (for instance, accounting records or fraud prevention), Bitelio may keep certain data:

  • Billing records: kept for the periods mandated by tax and accounting law (typically 7 years)
  • Fraud and abuse records: kept for security purposes (email addresses tied to suspended accounts)
  • Legal requests: data under a legal hold is kept for as long as the law requires

No Data Return

Bitelio does NOT export or return data upon termination. The Customer must retrieve its data through the API before deleting the account; once deletion has occurred, the data is unrecoverable.

12. Liability & Indemnification

Customer Responsibilities

As Data Controller, the Customer is responsible for:

  • Establishing a lawful basis for processing under the GDPR (such as consent, contract, or legitimate interest)
  • Securing any required consents from Data Subjects before adding them to Bitelio
  • Supplying Data Subjects with privacy notices as required by GDPR Article 13/14
  • Observing applicable anti-spam legislation (CAN-SPAM, CASL, GDPR, and others)
  • Confirming a Data Subject's identity before acting on a rights request
  • Informing supervisory authorities and Data Subjects of breaches where this is required

Bitelio's Liability

  • Bitelio is answerable to the Customer for its compliance with this DPA and with its GDPR Article 28 obligations
  • Bitelio bears the same liability for the acts and omissions of its sub-processors as for its own
  • The liability limitations set out in the Terms of Service remain applicable, save where the GDPR prohibits them (notably Art. 82)

Indemnification

  • The Customer will indemnify Bitelio against claims resulting from the Customer's violation of the GDPR or other data protection laws
  • Bitelio will indemnify the Customer against claims resulting solely from Bitelio's breach of this DPA or of GDPR Article 28

GDPR Fines

In accordance with GDPR Article 82(3), liability for damages is apportioned between Controller and Processor according to fault: each party answers only for the damage attributable to its own violation of the GDPR.

13. Term & Termination

Effective Date

This DPA takes effect on the date you first make use of Bitelio's hosted service and continues in force for as long as the Terms of Service remain in effect.

Termination

This DPA comes to an end automatically upon any of the following:

  • The Customer deletes its Bitelio account
  • The Terms of Service are terminated
  • All Personal Data has been erased in accordance with Section 11

Survival

The provisions on confidentiality, data deletion, and liability continue to apply after termination to the extent needed to give them effect.

DPA Updates

  • Bitelio may revise this DPA to reflect changes in the law, in its sub-processors, or in its processing activities
  • Material changes will be announced by email 30 days before they take effect
  • Continuing to use Bitelio after a change takes effect constitutes acceptance of it
  • The "Last Updated" date at the top of this page serves as the version reference

Questions or Requests?

If you have questions about this DPA or our data processing activities, or wish to exercise your audit rights, please reach out:

Email: legal@bitelio.com

Response Time: Within 10 business days

For Data Subject rights requests, Customers should rely on the API (see Section 7) or write to legal@bitelio.com, stating the Data Subject's email address and the nature of the request.