RelyKit
Docs Pricing Flows SDK Webhooks
Sign in Get started

RelyKit

Data processing agreement

The terms on which we process personal data on your behalf. Offered here in full so you can read it before asking anybody to sign anything.

Last updated 2026-09-17

  • What this covers
  • Our instructions
  • Whose data, and what kind
  • Sub-processors
  • Security measures
  • If something goes wrong
  • Where the data goes
  • When you leave

What this covers

You are the controller. RelyKit is the processor. This covers the personal data we process because you asked us to send mail — chiefly the email addresses of your recipients and the record of what happened to each message.

It applies from the moment you send your first message and lasts as long as your account does. If your own terms with your customers are stricter than this, yours win.

Our instructions

We process recipient data only to do the thing you asked: deliver the message, record what happened to it, and keep an address off the list once it has bounced or complained. We do not do anything else with it.

Specifically, we will not:

  • Sell, rent or share recipient data with anybody.
  • Send anything to your recipients on our own behalf.
  • Use your recipients' addresses to build any list, profile or model.
  • Use the content of your messages to train anything.

If a law compels us to process data in a way you have not instructed, we will tell you before doing so unless the law forbids us from telling you.

Whose data, and what kind

WhoseThe people you send to, and the staff of yours who use the dashboard.
WhatEmail addresses; message subjects and bodies while retained; delivery outcomes; whatever you choose to put in a message or a tag.
How longMessage content for 30 days. Delivery records for as long as the account exists.
Special categoriesNone sought. If you send health, financial or similar data in message bodies, that is your decision and your lawful basis; tell us, because it changes what we would advise about retention.

Sub-processors

You approve these two by accepting this agreement. There are no others.

WhoWhat they doWhere
Amazon Web ServicesDelivers the mail and carries delivery eventsus-east-1
DigitalOceanHosts the application and the databaseNew York

We will tell you at least thirty days before adding another, and you may object. If you do and we cannot resolve it, you may end the agreement without penalty.

Note what is not in that list when you run RelyKit against your own AWS account: the sending happens under your own AWS agreement, with your own terms, and Amazon is your sub-processor rather than ours.

Security measures

The measures in place, stated so they can be checked rather than assumed.

  • TLS on every connection, inbound and outbound. Authentication is refused over an unencrypted SMTP connection.
  • Credentials — API keys, session tokens, sign-in links, recovery codes — stored only as hashes.
  • Passwordless sign-in by single-use link, with optional time-based second factor.
  • The database accepts connections only from the application server.
  • Message content deleted automatically after 30 days.
  • Administrative actions recorded with actor, subject and what changed.
  • Daily database backups retained seven days.

We will give you the information you reasonably need to satisfy yourself of this, and will cooperate with an audit at your cost and on reasonable notice.

If something goes wrong

We will tell you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with what we know: what happened, whose data, what we are doing, and what we suggest you do. We will not wait until we understand it fully before telling you that it happened.

Where the data goes

The application and database run in New York. Mail is sent through Amazon SES in us-east-1. Delivery inevitably sends the message to wherever your recipient's mail provider is, which is not something any sender controls.

For transfers out of the UK or EEA we rely on the standard contractual clauses, which form part of this agreement by reference.

When you leave

Delete your account and everything belonging to it is removed: message content, delivery records, domains, keys, suppression lists and your application. It is one operation and it is irreversible.

If you would rather take a copy first, ask before deleting and we will export everything we hold. Backups age out within seven days; we do not keep anything beyond that once an account is gone.

This page describes what the software actually does, which is checked against the code it describes. It is not legal advice, and it has not been reviewed by a lawyer. If you are relying on it for a procurement decision, ask us and we will tell you plainly where it stands.

RelyKit

Transactional email you can run yourself, on top of Amazon SES.

Product

  • How it works
  • Deliverability
  • Dashboard

Developers

  • API reference
  • Flows
  • Node SDK
  • OpenAPI

Trust

  • Privacy
  • Data processing
  • Health