Data processing agreement

This data processing agreement is part of the terms and applies whenever a customer (the controller) uses GoodToReach, run by AddonNordic ApS, Solvangen 15, 9210 Aalborg SØ, Denmark, CVR 46495985 (the processor), to process personal data. It is written to meet Article 28 of the GDPR.

What we process, and why

On your instructions we process the data you import and the data created when emails are sent: recipient email addresses, names of contact persons where you provide them, company names, countries and registration numbers, the emails you write and approve, replies, opt-outs, bounces, and the time and result of each send. The purpose is to check whether a recipient may be emailed, to send your approved emails from your mailbox, to read replies and opt-outs, and to keep the proof. The data subjects are employees and representatives of the companies you write to, and your own users.

Your instructions

We process personal data only on your documented instructions, which are given through the platform: importing recipients, approving a batch, connecting or disconnecting a mailbox, and deleting data. We do not use the data for any other purpose. If we believe an instruction breaks the law, we tell you before acting on it.

Our duties

  • Everyone who works with the data is bound by confidentiality.
  • We protect the data with access control, encryption of mailbox passwords, encrypted transport, and backups kept in the EU.
  • We help you answer requests from data subjects, including access, correction, deletion and objection. Replies, “no” answers and unsubscribe clicks are handled automatically.
  • We tell you without undue delay, and at the latest within 48 hours, if we become aware of a personal data breach that concerns your data.
  • We help you with data protection impact assessments and consultations with a supervisory authority where our processing is relevant.
  • We make the information needed to show that we meet these duties available to you, and allow audits once a year with 30 days’ notice, at your cost, during working hours.

Sub-processors

We use these sub-processors, all in the EU:

  • Railway (EU West) hosts the sending engine and its database.
  • Lovable and Supabase (EU) host the platform and user accounts.
  • Stripe handles payment; it receives your billing details, not your recipient lists.
  • The official company registers answer our lookups with public company data.
  • Your own mailbox provider sends the emails; you choose it.

We tell you by email at least 30 days before adding or replacing a sub-processor. You can object within that period; if we cannot find a solution, you can cancel without cost.

Transfers

We keep the data in the EU. We do not transfer it to a country outside the EU or EEA unless the law requires it, and then only with a valid transfer basis.

Deletion

When the agreement ends, we delete your workspace data within 30 days. Two things are kept: the list of addresses that have opted out, so their choice stays respected across all senders, and the sending proof for each batch, so you and we can document what was sent and on what basis. You can ask for a copy before deletion.

Duration

This agreement lasts as long as you have an account, and until the data is deleted.

Version 1, 7 October 2026.

Check a company before you write

Free. No account. The answer comes from the official company register in ten seconds.

Check a company free