Data Processing Agreement (DPA)
Last updated: June 2025 · GDPR Article 28
This DPA governs processing where SampleRelay acts as a data processor on behalf of users who are data controllers — particularly for buyer/contact data entered by brand users.
1. Parties
Data Controller: the SampleRelay user who enters third-party personal data.
Data Processor: SampleRelay, operated from Belgium. Email:
hello@samplerelay.com. The legal operator is identified at the foot of this page.
2. Subject Matter and Duration
SampleRelay processes personal data on the Customer's behalf for the duration of their use of the service.
3. Nature and Purpose
SampleRelay stores and displays buyer contact data entered by the Customer to enable tracking of sample sends and follow-ups.
4. Categories of Data Subjects
Retail buyers, boutique owners, and store contacts whose details are entered by the Customer.
5. Categories of Personal Data
Name, contact name, email address, business address/location, website or social handle, and notes entered by the Customer.
6. Processor Obligations
Process only on documented instructions, ensure confidentiality, implement security measures, inform of sub-processor changes, assist with data subject requests, notify breaches within 72 hours where possible, and delete or return data at termination.
7. Sub-processors
Listed on our Subprocessors page. Material changes are communicated with at least 14 days' notice.
8. Security Measures
Row-level security in Supabase (PostgreSQL), HTTPS/TLS in transit, authentication via Supabase Auth, workspace-level access controls, EU-region hosting (eu-central-1).
9. Data Subject Requests
If a buyer contacts SampleRelay directly, we direct them to the relevant Customer and assist where technically possible.
10. Deletion at Termination
Upon account deletion or written request, we delete the Customer's personal data within 30 days, except where retention is legally required.
11. International Transfers
Where data is processed outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions.