Source
Data processing agreement (dpa) — found from the homepage — Omnisend
Checked for Omnisend on 30 Sep 2026
- Page
- https://www.omnisend.com/data-processing-agreement/
- Checked
- 30 Sep 2026, 12:50 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:21ebe644eecd1f574b7f0cce1f0610c0568cf21ba6ebf833ebba985c4731a3f1
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
DPA updated Report an error
“Last updated: September 22, 2025”
-
Entities Report an error
“The group consists of these companies: Name of the Company UAB Omnisend Omnisend Limited Omnisend, Inc.”
-
Lithuania entity Report an error
“Legal entity code: 302530363 06567194 EIN 301200039 Address: Verkių g. 25C-1, LT-08223 Vilnius, Republic of Lithuania”
-
UK entity Report an error
“Unit A3, Gateway Tower, 32 Western Gateway, London, E16 1YL England”
-
US entity Report an error
“677 King Street 3rd Floor Charleston, SC 29403 United States”
-
Scc module two Report an error
“This DPA incorporates the European Commission (decision C(2021)3972) Standard Contractual Clauses (the “Standard Contractual Clauses”) Module Two (Controller to Processor)”
-
UK addendum Report an error
“this DPA incorporates UK International Data Transfer Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force from 21 March 2022”
-
Data categories Report an error
“The categories of Customer Personal Data Processed by Omnisend pursuant to the Agreements consists of: contact information (name, surname, company, email, phone, and physical address), navigational data, purchase data, data related to reviews left, bank details, email data, and Services usage data”
-
Special categories excluded Report an error
“Special Categories Data will not be processed by and transferred to Omnisend by the Customer;”
-
Subprocessor notice days Report an error
“Omnisend shall notify Customer if it adds or removes Sub-Processors at least 10 days prior to any such changes if Customer opts in to receive such notifications by subscribing here.”
-
Subprocessor objection termination Report an error
“Customer may terminate the affected Services by providing Omnisend with a written notice within one (1) month of Omnisend’s notice, which termination will not affect Customer’s obligation to pay amounts accrued to Omnisend prior to, and including, the effective termination date.”
-
Audit rights Report an error
“Customer may, upon thirty (30) days’ prior written request and no more than once per calendar year unless otherwise required by applicable law, during regular business hours, without interrupting Omnisend’s business operations, and subject to Omnisend’s onsite confidentiality and security procedures and policies, conduct an inspection of the relevant portions of the Records”
-
Breach notification Report an error
“If Omnisend becomes aware of a Persona Data Breach, Omnisend will, promptly and without undue delay: (i) notify Customer of the Personal Data Breach; and (ii) take reasonable steps to mitigate the effects and to minimize any damage resulting from the Personal Data Breach.”
-
Data deletion or return Report an error
“After the end of the provision of the Services, Omnisend shall, at the choice of the Customer, delete all Customer Personal Data processed on behalf of the Customer and certify to the Customer that it has done so, or return to the Customer all Personal Data processed on its behalf and delete existing copies.”
-
Security SSO MFA Report an error
“prevent unauthorized persons from accessing systems used to Process Customer Personal Data, including through enforced Single Sign-On (SSO) and Multi-Factor Authentication (MFA);”
-
Security rbac Report an error
“prevent Processing systems from being used without proper authorization, including through role-based access controls (RBAC) and access provisioning protocols;”
-
Security siem Report an error
“establish audit trails and event logging (including use of Security Information and Event Management (SIEM) systems) to record and monitor access and activity related to Customer Personal Data;”
-
Penetration testing Report an error
“maintain proactive security testing, vulnerability scanning, and incident response procedures, including annual penetration tests and internal phishing simulation campaigns, as further described in Annex I.”
-
DPA precedence Report an error
“In the event of a conflict between the DPA and the Personal Data processing provisions of the Agreements, the provisions of this DPA shall prevail solely with respect to the Processing of Customer Personal Data.”
-
Data subject third party rights Report an error
“Data Subjects may invoke and enforce this DPA, as third-Party beneficiaries, against the Customer and/or Omnisend, with the following exceptions:”
-
Subprocessor purposes Report an error
“Omnisend will transfer Customer Personal Data to Sub-Processors specified in the Annex III for these purposes: 3.1.7.1 to ensure collaboration / communication functionalities; 3.1.7.2 to ensure marketing / eCommerce solutions; 3.1.7.3 to ensure accounting and payment solutions; and 3.1.7.4 analytics and data assessment.”
-
Liability Report an error
“Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of this DPA.”
-
Data subject assistance Report an error
“Omnisend will provide reasonable assistance to Customer with any data protection impact assessments, and prior consultations with Supervisory Authorities, which Customer reasonably considers to be required by the Data Protection Laws”
-
Public authority notification Report an error
“Omnisend agrees to notify the Customer and, where possible, the Data Subject promptly (if necessary, with the help of the Customer) if it: 14.1.1. receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of Personal Data transferred pursuant to this DPA”
2 facts read from this page are not shown because they could not be confirmed on the page as captured.
Scores citing this record
- The CRM Manager List ownership, import & exit
- The CRM Manager European sovereignty
- The Data Protection Officer List ownership, import & exit
- The Data Protection Officer European sovereignty
- The Deliverability Engineer List ownership, import & exit
- The Deliverability Engineer European sovereignty
- The Shop Owner List ownership, import & exit
- The Shop Owner European sovereignty
- The Integrator List ownership, import & exit
- The Integrator European sovereignty
- The Skeptic List ownership, import & exit
- The Skeptic European sovereignty