Data Processing Agreement (DPA)

SendFaxFast · pursuant to Art. 28 GDPR · Version 1.1 · Last updated: October 2026

This Agreement applies to every fax order placed via sendfaxfast.com where the user acts as a data controller within the meaning of Art. 4(7) GDPR. It is concluded electronically upon submission of the order (Art. 28(9) GDPR). The applicable version, date, and timestamp of conclusion are logged server-side.

1. Parties

Data Processor:
[OPERATOR NAME, ADDRESS]
Email: support@sendfaxfast.com

Data Controller:
The respective user who places the fax order via sendfaxfast.com and thereby transmits personal data of third parties.

2. Subject Matter and Duration of Processing

The subject matter is the technical transmission of documents by fax on behalf of the controller. Processing begins with the upload of the document and ends with the final completion of the transmission process (successful or failed). Uploaded documents are irrevocably deleted no later than 24 hours after completion of the process.

3. Nature and Purpose of Processing

The processor processes personal data solely for the purpose of transmitting the document uploaded by the controller to the recipient fax number specified by the controller. No further use, disclosure, or analysis of document content takes place.

4. Type of Personal Data and Categories of Data Subjects

The personal data processed depends on the content of the uploaded document and is determined by the controller. Depending on the document content, the following may be affected:

Data subjects are generally third parties whose data is contained in the transmitted document. The controller is responsible for ensuring that they are authorized to transmit such data.

5. Instructions

The processor processes personal data solely on documented instructions from the controller. The instructions arise from the fax order placed. No processing for other purposes takes place. If the processor considers an instruction to be in violation of data protection law, it will notify the controller immediately.

6. Confidentiality

The processor ensures that all persons authorized to process data are bound by confidentiality obligations. Document content is neither inspected nor stored beyond what is strictly necessary for technical transmission.

7. Technical and Organizational Measures (Art. 32 GDPR)

The processor implements appropriate technical and organizational measures to protect the data processed, in particular:

8. Sub-processors

The processor engages the following sub-processors who may have access to personal data in the course of providing the service:

Provider Purpose Location Transfer Basis
Telnyx LLC
311 W Superior St, Suite 504, Chicago, IL 60654, USA
Fax infrastructure and transmission USA EU Standard Contractual Clauses (SCCs) + EU-U.S. Data Privacy Framework (DPF)
[HOSTING PROVIDER]
[HOSTING PROVIDER ADDRESS]
Web hosting and server infrastructure [HOSTING LOCATION] [TRANSFER BASIS]

The controller consents to the engagement of these sub-processors by concluding this Agreement. Any changes to the list of sub-processors will be communicated to the controller by updating this page.

9. Assistance to the Controller

The processor shall assist the controller, to the extent possible, in fulfilling data subject rights (Art. 15–22 GDPR) and the obligations pursuant to Art. 32–36 GDPR (security, breach notification, data protection impact assessment). Requests should be directed to: support@sendfaxfast.com

10. Deletion and Return After Completion

After the transmission process is complete, uploaded documents are automatically and irrevocably deleted within 24 hours. Return of data to the controller is not technically provided; the controller is responsible for retaining their own copies.

11. Controller's Audit Rights

The controller is entitled to verify compliance with this Agreement. Audit requests may be submitted in writing to support@sendfaxfast.com. The processor shall provide all information necessary to demonstrate compliance.

12. Scope and Governing Law

This Agreement applies to every fax order placed via sendfaxfast.com where the user acts as a data controller under data protection law. For purely private use within the meaning of Art. 2(2)(c) GDPR (household exemption), a DPA is not legally required. German law applies.