How SpamKill processes personal data on behalf of customers, including sub-processors, security measures, and data subject rights.
Last updated: September 21, 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service between SpamKill Inc. ("Company") and the Customer (together as the "Parties"). This DPA reflects the Parties' agreement with respect to the terms governing the processing of personal data under the Agreement.
SpamKill Inc. processes personal data submitted through protected web forms to filter out spam bot submissions, and processes payments for subscribers through third-party sub-processors. Filtering is performed in flight on the Customer's instructions; submission content is retained afterwards only where the Customer has enabled a storage option described under Security Measures.
The data subjects include:
End-user submission content is not retained by default. SpamKill evaluates a form submission in flight and passes it to the destination the Customer has configured — their CRM, inbox or backend. Once that decision is made, the submission content is not kept by SpamKill.
Where the Customer enables retention, submission content is stored end-to-end encrypted. This works identically however the Customer's forms are protected — SpamKill's form builder, the WordPress plugin, or the form converter.
This applies to submissions SpamKill blocks. Submissions that pass the filter are delivered to the destination the Customer has configured and are not retained by SpamKill.
Because SpamKill holds the private key only in that locked form and never receives the passphrase, SpamKill cannot decrypt or restore stored submission content, and cannot do so on the Customer's behalf if the Customer's encryption passphrase becomes unavailable. This is a property of the design rather than a policy position. The encryption passphrase is distinct from the Customer's account login credentials, which are managed in the ordinary way and can be reset.
Subscriber data — the Customer's own account, billing and support information — is stored strictly for purposes essential to delivering our services, including billing, communication, and product updates. We implement robust security protocols to safeguard all stored data.
SpamKill Inc. has a comprehensive data breach response plan in place, ensuring timely notifications and mitigation actions in compliance with applicable laws.
SpamKill Inc. uses the following sub-processors:
Sub-processors only have access to data strictly necessary for the services they provide.
SpamKill Inc. is a company registered and operating in Canada. While we are based in Canada, the processing and storage of data may occur in data centers located in the United States. SpamKill Inc. ensures that all data processing and storage is conducted in accordance with applicable Canadian data protection laws, and where relevant, ensures compliance with cross-border data transfer requirements.
SpamKill Inc. honors data deletion requests promptly and ensures data subjects can access, correct, or delete their data in accordance with applicable laws.
Because stored submission content is encrypted under a key SpamKill does not hold, SpamKill can delete a stored record on request but cannot read, export or correct what it contains. Requests that require access to the plaintext are fulfilled by the Customer, who holds the key and acts as controller for that data; SpamKill will pass such a request on and assist as processor.
End-user submission content is not retained unless the Customer has enabled one of the storage options described under Security Measures.
Where the Customer has enabled retention, submissions are kept encrypted for the period stated for the Customer's plan — 31 days for held-submission review — and are then deleted. The Customer may delete a stored record sooner at any time.
All other data is retained only as necessary and is deleted upon request, except for payment-related data, which is kept for accounting and compliance purposes.
SpamKill Inc. complies with GDPR, PIPEDA, and other relevant data protection laws.
For Canadian data subjects, the Office of the Privacy Commissioner of Canada (OPC) serves as the supervisory authority. For EU data subjects, the relevant Data Protection Authority in the applicable EU member state will apply.
The liability of SpamKill Inc. is governed by the terms set out in our Terms and Conditions.
For any privacy-related inquiries, please contact SpamKill Inc.: