diff --git a/apps/landing/src/components/Footer/Footer.tsx b/apps/landing/src/components/Footer/Footer.tsx index 5fb8603..3816108 100644 --- a/apps/landing/src/components/Footer/Footer.tsx +++ b/apps/landing/src/components/Footer/Footer.tsx @@ -128,6 +128,11 @@ export default function Footer() { Terms +
Last Updated: February 18, 2026
++ This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", "Data + Controller") and Plunk ("Processor", "we", "us") and governs the processing of Personal Data in + accordance with GDPR requirements. +
++ GDPR Requirement: This DPA is required under Article 28 of + the GDPR. By using Plunk's hosted service, you accept and agree to the terms of this DPA. +
++ Terms used in this DPA have the meanings set forth in the GDPR. Specifically: +
++ This DPA applies ONLY to customers using Plunk's hosted service (useplunk.com). Self-hosted + deployments are NOT covered by this DPA - you are solely responsible for GDPR compliance when + self-hosting. +
+ ++ This DPA supplements the Plunk Terms of Service and Privacy Policy. In case of conflict regarding data + processing: +
++ By using Plunk's hosted service, you acknowledge that you have read, understood, and agree to be bound + by this DPA. This constitutes a legally binding agreement between Customer and Plunk. +
++ As required by GDPR Article 28(3), the following details describe the processing activities: +
+ ++ Processing of Personal Data necessary to provide email automation, transactional email, marketing + campaigns, and workflow automation services. +
+ ++ Processing occurs for the duration of your Plunk subscription/account, plus 30 days for API logs + (which are automatically deleted), and until you request account deletion. +
+ ++ Plunk commits to the following obligations as Data Processor: +
+ ++ As required by GDPR Article 32, Plunk implements appropriate technical and organizational measures to + ensure a level of security appropriate to the risk: +
+ ++ Customer authorizes Plunk to engage the following sub-processors to process Personal Data: +
+ +| + Sub-Processor + | ++ Service + | ++ Location + | ++ Purpose + | +
|---|---|---|---|
| + Amazon Web Services (AWS SES) + | +Email Delivery | ++ Global (data in transit only) + | ++ Sending emails to recipients + | +
| Stripe, Inc. | ++ Payment Processing + | ++ USA (PCI-DSS compliant) + | ++ Billing for paid accounts + | +
| + Hetzner Online GmbH + | ++ Infrastructure Hosting + | ++ EU/EEA (Germany) + | ++ Database and application hosting + | +
+ Plunk will assist Customer in fulfilling Data Subject rights requests under GDPR Articles 15-22: +
+ ++ Customer can fulfill most Data Subject requests independently via API: +
++ If Customer cannot fulfill a request via API, contact legal@useplunk.com: +
++ In the event of a Personal Data breach affecting Customer data, Plunk will: +
++ Notifications will include (to the extent known): +
++ When emails are sent to recipients, Personal Data may transit through non-EU regions: +
++ All sub-processors that process Personal Data outside EU/EEA have executed Standard Contractual + Clauses (SCCs) approved by the European Commission, providing appropriate safeguards for international + transfers per GDPR Article 46. +
++ Plunk will make available to Customer information necessary to demonstrate compliance with GDPR + Article 28 obligations, including: +
++ Customer may audit Plunk's compliance with this DPA, subject to the following: +
++ In lieu of conducting a full audit, Customer may request and review sub-processor certifications and + compliance documentation (SOC 2, ISO 27001, etc.) where available. +
++ When Customer deletes their Plunk account (via dashboard or by request): +
++ Plunk may retain certain data if required by law (e.g., accounting records, fraud prevention): +
++ Plunk does NOT provide data export or return upon termination. Customer must retrieve data via API + before deleting account. Once deleted, data cannot be recovered. +
+Customer (Data Controller) is responsible for:
++ Under GDPR Article 82(3), liability for damages is allocated between Controller and Processor based on + fault. Each party is liable only for the damage caused by its own GDPR violation. +
++ This DPA is effective as of the date you first use Plunk's hosted service and remains in effect for + the duration of the Terms of Service. +
+ +This DPA terminates automatically when:
++ Obligations regarding confidentiality, data deletion, and liability survive termination to the extent + necessary to fulfill their purpose. +
+ ++ For questions about this DPA, data processing activities, or to exercise audit rights: +
++ Email: legal@useplunk.com +
++ Response Time: Within 10 business days +
++ For Data Subject rights requests, Customers should use the API (see Section 7) or contact + legal@useplunk.com with Data Subject's email address and nature of request. +
+Last Updated: February 18, 2026
++ This Privacy Policy explains how Plunk collects, uses, stores, and protects your personal information. + We are committed to transparency and your privacy rights under GDPR and EU law. +
+ Plunk is an open-source email automation platform. For the hosted service at useplunk.com, we act as: +
+
-
-
-
-
| - - - - Category - - - - | -- - - - Examples - - - - | -- - - - Collected - - - - | -
|
-
-
-
-
- A. Identifiers
-
-
-
-
- |
-
-
-
-
-
- Contact details, such as real
- name, alias, postal address,
- telephone or mobile contact
- number, unique personal
- identifier, online identifier,
- Internet Protocol address, email
- address, and account name
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- B. Personal information categories
- listed in the California Customer
- Records statute
-
-
-
-
- |
-
-
-
-
-
- Name, contact information,
- education, employment, employment
- history, and financial information
-
-
-
-
- |
-
-
-
-
- -
-
-
-
- YES
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- C. Protected classification
- characteristics under California
- or federal law
-
-
-
-
- |
-
-
-
-
-
- Gender and date of birth
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- D. Commercial information
-
-
-
-
- |
-
-
-
-
-
- Transaction information, purchase
- history, financial details, and
- payment information
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- E. Biometric information
-
-
-
-
- |
-
-
-
-
-
- Fingerprints and voiceprints
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- F. Internet or other similar
- network activity
-
-
-
-
- |
-
-
-
-
-
- Browsing history, search history,
- online
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- G. Geolocation data
-
-
-
-
- |
-
-
-
-
-
- Device location
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- H. Audio, electronic, visual,
- thermal, olfactory, or similar
- information
-
-
-
-
- |
-
-
-
-
-
- Images and audio, video or call
- recordings created in connection
- with our business activities
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- I. Professional or
- employment-related information
-
-
-
-
- |
-
-
-
-
-
- Business contact details in order
- to provide you our services at a
- business level or job title, work
- history, and professional
- qualifications if you apply for a
- job with us
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- J. Education Information
-
-
-
-
- |
-
-
-
-
-
- Student records and directory
- information
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-
|
-
-
-
-
- K. Inferences drawn from other
- personal information
-
-
-
-
- |
-
-
-
-
-
- Inferences drawn from any of the
- collected personal information
- listed above to create a profile
- or summary about, for example, an
- individual’s preferences and
- characteristics
-
-
-
-
- |
-
-
-
-
- -
-
-
-
-
-
-
-
- - |
-