ReceiveHQ

Legal · GDPR

Data Processing Agreement

This Data Processing Agreement ("DPA") governs the processing of personal data by Cortena B.V. ("Cortena", "Processor") on behalf of customers of ReceiveHQ, in connection with the ReceiveHQ inbound email service. It forms part of the customer agreement for ReceiveHQ and is incorporated by reference into that agreement.

DPA / AVV · ReceiveHQ · last reviewed September 2026 · based on Cortena DPA v2.0

1. Definitions

  • "Agreement" means this Data Processing Agreement and all annexes, forming part of the subscription or terms between Cortena and the Customer for ReceiveHQ.
  • "Controller" means the Customer, who determines the purposes and means of processing personal data.
  • "Processor" means Cortena B.V., who processes personal data on behalf of the Controller through ReceiveHQ.
  • "Customer Personal Data" means any personal data processed by Cortena on behalf of the Customer pursuant to or in connection with ReceiveHQ.
  • "Data Protection Laws" means the General Data Protection Regulation (EU) 2016/679 (GDPR), and any applicable national implementing legislation, as amended or replaced from time to time.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • "Sub-processor" means any third party appointed by Cortena to process Customer Personal Data in connection with the provision of ReceiveHQ.
  • "Services" means the ReceiveHQ inbound email reception, storage, parsing, and webhook (or blackhole) delivery platform operated by Cortena.
  • "EEA" means the European Economic Area.

2. Processing of Customer Personal Data

2.1 Documented instructions

Cortena shall process Customer Personal Data only on documented instructions from the Customer, unless required to do so by applicable law. The customer agreement for ReceiveHQ, together with any written instructions provided by the Customer (including endpoint configuration), constitutes the Customer's documented instructions for the purposes of this DPA.

2.2 Scope and purpose

Cortena processes Customer Personal Data solely for the purpose of providing and maintaining ReceiveHQ as described in the customer agreement. Cortena shall not process Customer Personal Data for any other purpose, including but not limited to training or improving AI models, benchmarking, or developing products or features for other customers.

2.3 Nature of processing

The processing activities carried out by Cortena include: SMTP reception of inbound email; parsing of MIME messages; temporary and retained storage of raw mail and parse artifacts; delivery of parsed payloads to Customer-configured HTTPS webhooks (or blackhole storage without forward); console access for authorised users; and associated operational support.

2.4 Categories of data

Customer Personal Data processed by Cortena may include: email headers and envelope data; message bodies and attachments; sender and recipient addresses and names; authentication and account identity data of Customer users; and technical logs related to reception and delivery.

2.5 Duration

Cortena processes Customer Personal Data for the duration of the customer agreement, unless applicable law requires longer retention. Operational object storage for raw mail and delivery logs is subject to a retention window described in product documentation (currently 14 days for MinIO raw/logs objects, unless otherwise agreed).

3. Processor personnel

Cortena shall ensure that all personnel with access to Customer Personal Data are subject to binding confidentiality obligations. Access to Customer Personal Data is strictly limited to those personnel who need access to perform the Services. Cortena shall take reasonable steps to ensure the reliability of any employee, contractor, or sub-processor with access to Customer Personal Data.

4. Security

4.1 Technical and organisational measures

Cortena implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures include:

  • Encryption of data in transit (TLS) and at rest (encrypted volumes)
  • Private Kubernetes infrastructure hosted on bare-metal servers in Germany
  • Strict access controls and multi-factor authentication for production systems
  • CIDR-restricted SMTP ingest and optional Basic auth on customer webhooks
  • Least-privilege access controls across console and operational systems

4.2 Risk assessment

In determining the appropriate level of security, Cortena takes into account the risks presented by the processing, including the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

4.3 Updates

Security measures are reviewed and updated periodically as the platform evolves. See also the public hosting declaration.

5. Sub-processing

5.1 Authorised sub-processors

The Customer authorises Cortena to appoint sub-processors to assist in providing ReceiveHQ. Cortena's current list of approved sub-processors is published at /sub-processors.

5.2 Sub-processor obligations

Cortena shall impose data protection obligations on each sub-processor that are materially equivalent to those set out in this DPA. Cortena remains fully liable to the Customer for the performance of any sub-processor's obligations under this DPA, to the extent that Cortena failed to exercise reasonable care in selecting or supervising that sub-processor.

5.3 Changes to sub-processors

Cortena will notify the Customer of any intended addition or replacement of a sub-processor with at least 30 days prior written notice. If the Customer objects to a new sub-processor on reasonable data protection grounds, the Customer may raise the objection in writing within 30 days of notification. The Parties shall negotiate in good faith to resolve the issue. If no resolution is reached, either Party may terminate the affected part of the Services on reasonable written notice.

6. Data subject rights

6.1 Assistance

Taking into account the nature of the processing, Cortena shall assist the Customer by implementing appropriate technical and organisational measures to enable the Customer to fulfil its obligations to respond to requests from data subjects exercising their rights under applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).

6.2 Notification of requests

Cortena shall promptly notify the Customer if it receives a request from a data subject in respect of Customer Personal Data. Cortena shall not respond to any such request except on the documented instructions of the Customer, or as required by applicable law.

7. Personal data breach

7.1 Notification

Cortena shall notify the Customer without undue delay — and in any event within 72 hours — upon becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall include, to the extent available: a description of the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences of the breach, and measures taken or proposed to address the breach.

7.2 Cooperation

Cortena shall cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of any Personal Data Breach. Cortena shall provide the Customer with all information reasonably necessary to allow the Customer to meet its own notification obligations to supervisory authorities and data subjects under applicable Data Protection Laws.

8. Data protection impact assessments

Cortena shall provide reasonable assistance to the Customer with any Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities that the Customer reasonably considers to be required by Article 35 or Article 36 of the GDPR, where such assessments relate to the processing of Customer Personal Data by Cortena through ReceiveHQ.

9. Deletion and return of Customer Personal Data

9.1 On termination

Upon termination or expiry of the customer agreement, Cortena shall, at the Customer's choice, delete or return all Customer Personal Data within 30 days of the date of termination. This obligation applies to all copies of Customer Personal Data processed by Cortena and its sub-processors.

9.2 Legal retention requirements

Cortena shall not be required to delete Customer Personal Data to the extent that applicable law requires its retention. In such cases, Cortena shall notify the Customer and shall ensure that the retained data is protected in accordance with this DPA.

10. Audit rights

10.1 Information and cooperation

Cortena shall make available to the Customer, upon reasonable written request, all information necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR.

10.2 Audits and inspections

Cortena shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to the following conditions: (a) the Customer provides reasonable prior written notice of at least 30 days; (b) the audit is conducted during normal business hours and in a manner that minimises disruption to Cortena's operations; (c) the Customer bears the costs of any such audit unless the audit reveals a material non-compliance by Cortena.

10.3 Alternative assurance

Where Cortena has obtained relevant third-party certifications or completed independent security assessments, Cortena may satisfy audit requests by providing the relevant reports or certifications, to the extent they cover the scope of the Customer's audit requirements.

11. International data transfers

11.1 EEA processing

Cortena stores and processes ReceiveHQ Customer Personal Data (inbound mail content, parse artifacts, delivery records, and related application data) within Germany and the EEA, using infrastructure operated by Hetzner Online GmbH (Germany). That core mail and application data does not leave the EEA as part of ReceiveHQ's hosting and processing operations.

11.2 Sub-processors

Approved sub-processors for ReceiveHQ are published at /sub-processors. Core hosting is Hetzner Online GmbH (Germany). Where enabled, Abusix.com may process connection metadata only to validate the sender's mailserver and domain (no mail content).

11.3 No unauthorised transfers

Cortena shall not transfer Customer Personal Data to any country outside the EEA without the Customer's prior written consent, unless required by applicable law.

12. Confidentiality

Each Party shall keep this DPA, and all information received from the other Party in connection with it, strictly confidential. Neither Party shall disclose such information to a third party without the prior written consent of the other Party, except: (a) to the extent required by applicable law or court order; or (b) to the extent that the information is already in the public domain through no breach of this DPA.

13. Governing law and jurisdiction

This DPA is governed by the laws of the Netherlands. Any disputes arising in connection with this DPA shall be submitted to the exclusive jurisdiction of the competent courts of Amsterdam, the Netherlands, consistent with the governing law provisions of the customer agreement.

Contact and requests

For all data protection enquiries, DPA requests, or to exercise rights under this agreement:

This page is the public DPA for ReceiveHQ. Where this page and a separately signed DPA differ for a given customer, the signed DPA governs for that customer.