Data processing agreement

Last updated: 31 July 2026

This agreement is concluded under art. 28 GDPR between you (the controller) and L'Alternative Fabrique, publisher of Spore (the processor). It supplements the terms of service and applies whenever you send us messages intended for natural persons.

1. Roles of the parties

You determine the purposes and means of processing the personal data contained in the messages you send us, as well as the choice of recipients: you are the controller. We process that data solely on your behalf and on your instructions, for the sole purpose of delivery: we are your processor.

That qualification applies only to your message content and your recipients' data. For your account data — email address, billing, declared domains, API keys, access logs — we act as controller, under the conditions described in the legal notice.

2. Subject matter, duration and nature of processing

  • Subject matter: delivery, on your behalf, of the transactional messages you submit to the API, to the recipients you designate.
  • Nature of operations: receipt of the message through the API, queuing, cryptographic signing (DKIM), submission to the recipient's mail server, recording of the outcome of each delivery attempt, bounce and unsubscribe handling, population of suppression lists.
  • Purpose: provision of the service only. Your message content is never used for statistical, commercial or advertising purposes, nor to train any model.
  • Duration: that of your contract, plus the deletion periods in article 7.

Spore measures neither opens nor clicks: no tracking pixel and no link rewriting is inserted into your messages, and no reading-behaviour data is collected.

3. Categories of data and data subjects

We control neither your message content nor your choice of recipients. The data processed is what you choose to send us or what results from delivery:

  • recipients' email addresses, and any associated display name;
  • the subject and body of messages, including any personalisation variables you inject;
  • the attachments you attach to messages;
  • SMTP delivery logs: timestamp, destination server, message identifier, code and response of the recipient server, for each delivery attempt;
  • bounce reasons and diagnostic codes returned by recipient servers;
  • suppression lists: addresses that produced a hard bounce, a complaint or an unsubscribe request, with the associated reason.

The data subjects are the recipients of your messages: your users, customers, subscribers or correspondents.

Depending on your use, your message content may include data falling under art. 9 GDPR. Transmitting such data is your responsibility alone and requires a specific legal basis on your side; the service is not designed for that use.

4. Our obligations

We undertake to:

  • process the data only on your documented instructions — the use of the service and your account settings being the expression of those instructions — including for any transfer to a third country;
  • ensure the confidentiality of the data and that persons authorised to process it have committed to confidentiality;
  • implement and maintain the security measures described in article 6;
  • notify you without undue delay, and at the latest within seventy-two hours of becoming aware of it, of any personal data breach affecting the data processed on your behalf, with the information needed for your own notification to the supervisory authority and, where applicable, to the data subjects;
  • assist you, as far as possible and taking into account the nature of the processing, in responding to data subject requests — access, rectification, erasure, restriction, objection, portability;
  • assist you in meeting your obligations under art. 32 to 36 GDPR: security, breach notification, impact assessment and prior consultation;
  • immediately inform you if an instruction appears to us to infringe the GDPR or another data protection provision, and suspend its execution pending review;
  • make available to you the information needed to demonstrate compliance with this agreement, under article 8.

5. Sub-processors

You give general authorisation to the sub-processors listed below. We will inform you by email of any addition or replacement at least thirty days before it is implemented; you may then object on legitimate grounds and, failing a solution, terminate free of charge.

ProviderRoleLocation
OVH SASHosting of the service, the database and the sending servers (MTA)France
Mollie B.V.Payment processing — billing data onlyNetherlands (European Union)

Your recipients' addresses, your message content and delivery logs are processed and stored exclusively in France, at OVH SAS. They are not shared with any other provider and do not leave the European Union.

The up-to-date list of sub-processors, with details of the data each one processes, is published and maintained on the sub-processors page.

The payment provider processes only your account billing data, excluding any recipient data or message content.

No sub-processor is established outside the European Union. Processing your data and your recipients' data therefore involves no transfer to a third country, and relies on no transfer mechanism within the meaning of Chapter V of the GDPR.

6. Security

Taking into account the state of the art, implementation costs and the risks, we implement in particular:

  • encryption of communications in transit (TLS) between your systems, the API and our internal components;
  • enforced STARTTLS on SMTP submission to the sending servers;
  • encryption at rest of DKIM private keys, using AES-256 envelope encryption under a master key held separately from the database;
  • strict per-customer data isolation (tenant isolation), checked on every operation against a resource;
  • authentication by session or by revocable API key, at any time from your account;
  • Kubernetes network policies restricting inter-component communication to what is strictly necessary;
  • automatic suppression of hard-bounced addresses, limiting the circulation of invalid addresses;
  • restriction of administrative access to those who need it, logging of technical access, and security updates of infrastructure components.

7. Retention and deletion

Message content, recipient addresses and per-attempt SMTP delivery logs are retained for the operational period needed to debug delivery — reconstructing a message's path, handling a bounce, answering a complaint — and are then deleted: [À COMPLÉTER : durée de conservation — à aligner sur la rétention réellement configurée].

Suppression lists are retained for as long as your account exists. That retention is necessary: it prevents re-sending to an address that bounced, complained or unsubscribed, and thereby protects both the data subjects and the shared sending reputation. It is limited to the address, the date and the suppression reason.

At the end of the contract, or on your request, the data processed on your behalf is deleted from our active systems, then from backups according to their rotation cycle: [À COMPLÉTER : durée de conservation — à aligner sur la rétention réellement configurée]. No copy is kept beyond that, save where retention is legally required or necessary to establish, exercise or defend legal claims.

Billing data, for which we are the controller, follows the regime described in the legal notice: ten years' retention under art. L. 123-22 of the French Commercial Code.

8. Audit

We make available to you the information needed to demonstrate compliance with this agreement. You may request, once a year and on reasonable notice, documentary evidence of our technical and organisational measures.

An on-site audit is available only where there is serious cause — a data breach affecting you, a characterised breach of this agreement, or an order from a supervisory authority — at the requester's expense, on reasonable notice, and under conditions that do not compromise the security or confidentiality of our other customers' data.

9. Contact

For any question about this agreement, data protection or a data subject request, write to contact@sporee.fr.

Abuse reports go through a separate channel: abuse@sporee.fr (see the acceptable use policy).

Language

This English version is provided for information. The French version is the authoritative one and prevails in the event of any discrepancy.