This site is currently invite-only. Enter the access password to continue.
© 2024 Squish. All rights reserved.
Version 1.0 · Effective: August 18, 2026 · Questions? legal@squish.co or
This Data Processing Agreement (“DPA”) is entered into between Squish (“Processor”) and the customer identified in the account (“Controller”, “you”).
For personal data you upload, transmit, or otherwise process through the Services — your website content, your mailboxes, your own customers’ details — you are the controller and Squish is the processor. You decide why and how that data is processed; we act on your instructions.
For the account data we hold to run our own business — your billing details, your support history, the identity of the person who signed up — Squish is the controller. That processing is governed by the Privacy Policy, not by this DPA.
This DPA applies for as long as Squish processes personal data on your behalf, and survives termination for as long as we retain any of that data.
Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA governs. Where this DPA and the Standard Contractual Clauses conflict, the Clauses govern.
Squish processes personal data only on your documented instructions, including for international transfers, unless required otherwise by law we are subject to. Where the law requires processing without your instruction, we will tell you before processing unless that law forbids it.
Your instructions are: the Terms of Service, this DPA, your configuration of the Services, and any further written instruction you give us. Using the Services as documented is an instruction — you do not have to itemise ordinary operation.
If we believe an instruction infringes the GDPR or other applicable data-protection law, we will tell you and may pause that processing rather than carry it out.
We do not sell personal data, and we do not use your data to train AI models — ours or anyone else’s. Where a Service sends content to an AI sub-processor to produce a result for you, that is processing on your instruction and for your benefit only.
Squish ensures that every person authorised to process personal data is bound by an obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to deliver the Services or to comply with law.
Squish implements appropriate technical and organisational measures to protect personal data, having regard to the state of the art, cost of implementation, and the nature and risk of the processing. The measures in force are described in Annex II and on the Trust page, which is kept current.
Measures may change as the platform evolves. We will not reduce the overall level of security of the Services during your subscription.
Taking into account the nature of the processing, Squish assists you by appropriate technical and organisational measures — insofar as possible — in fulfilling your obligation to respond to requests to exercise rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection).
In practice: the Services let you access, export, correct and delete customer data yourself. Where a request cannot be satisfied through the product, email privacy@squish.co or and we will help.
If a data subject contacts us directly about data we process on your behalf, we will not respond to the substance ourselves. We will forward the request to you promptly, because it is yours to answer.
Squish assists you in ensuring compliance with the obligations in Articles 32 to 36 of the GDPR — security of processing, breach notification, data protection impact assessments, and prior consultation — taking into account the nature of the processing and the information available to us.
Squish notifies you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf.
The notification will describe, to the extent known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the full picture is not available at once, we will provide it in phases as it becomes available rather than delaying the first notification.
You grant Squish general authorisation to engage sub-processors, subject to this section.
The current list of sub-processors — vendor, purpose, region, and their own compliance programme — is maintained on the Trust page and forms Annex III to this DPA. It is deliberately kept in one place rather than duplicated here, so that it cannot drift out of step with the list you can actually see.
Squish imposes on each sub-processor, by written contract, data-protection obligations no less protective than those in this DPA. Squish remains fully liable to you for a sub-processor’s performance.
We will give you at least 30 days’ notice before adding or replacing a sub-processor, by email to the account’s administrative contact. If you reasonably object on data-protection grounds within that period, we will work with you in good faith to find a solution; if none is available, you may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees.
Squish is established in the United States. Where you are established in the EEA, the United Kingdom, or Switzerland, personal data you send us is transferred out of your jurisdiction.
For those transfers, the parties adopt the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, which are incorporated into this DPA by reference with the following selections:
For UK transfers, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies to the Clauses, with the UK as the governing law and the courts of England and Wales. For Swiss transfers, the Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner as the supervisory authority, and “data subject” extended to legal entities while Swiss law so provides.
At the end of the provision of Services, Squish deletes or returns all personal data processed on your behalf, at your choice, and deletes existing copies unless law requires storage.
Operationally: you may export your data at any time during the subscription. After termination, account data is deleted within 30 days, except billing records, which are retained for 7 years as US tax and accounting law requires. Operational logs age out on the published windows in the Trust page retention table, which are enforced automatically rather than by hand.
Backups are the exception worth stating plainly: data deleted from live systems may persist in encrypted backups until those backups age out on their own schedule. It is not restored to live systems, and it expires without intervention.
Squish makes available to you the information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we will satisfy this by providing our security documentation, completing a security questionnaire (CAIQ-Lite, SIG-Lite, or your own format), and answering reasonable written questions. Where that is genuinely insufficient for your compliance obligations, you may request an audit on 30 days’ written notice, no more than once in any 12-month period unless a regulator requires otherwise or there has been a personal data breach. Audits are conducted during business hours, subject to confidentiality, and in a manner that does not disrupt the Services or the data of other customers.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.
Nothing in this DPA limits either party’s liability to a data subject under the Standard Contractual Clauses, or any liability that cannot be limited under applicable law.
Data exporter: the Controller identified in the account. Data importer: Squish, providing the Services described in the Terms of Service.
Categories of data subjects
Your own customers and end users; visitors to websites you host with us; recipients and senders of email you send or receive through mailboxes we provide; your staff who use the Services; registrant contacts for domains you register.
Categories of personal data
| Website content | Whatever personal data your site stores or collects — form submissions, comments, customer records held by your application |
| Email content | Message bodies, subjects, attachments, sender and recipient addresses, mailbox metadata |
| Domain registration | Registrant name, postal address, email address and telephone number, as ICANN requires |
| Technical data | IP addresses, request metadata, user agents and server logs generated by visitors to your services |
| Support content | Whatever personal data appears in tickets, chat messages and correspondence you send us |
Special categories
The Services are not designed for special-category data under Article 9, and we ask you not to send it to support channels. If your application stores it, that remains your decision and your lawful basis; we process it as any other content, under the same measures.
Nature, purpose, frequency and duration
Hosting, storing, transmitting, backing up and serving the data as needed to provide web hosting, email, domain registration, migration and related support. Processing is continuous for the duration of the subscription, plus the retention windows in §11.
The measures below are in force. The Trust page carries the current detail and is the version to check.
| Encryption in transit | TLS 1.3 (TLS 1.2 minimum) end-to-end, HSTS enforced on every customer-facing domain |
| Encryption at rest | AES-256 on the primary datastore; card data is held by Stripe under PCI DSS Level 1 controls and never by us |
| Access control | Internal surfaces sit behind Cloudflare Zero Trust with SSO; per-route role gates; every staff "act as customer" session is audit-logged with reason and timestamps, and destructive actions are blocked during it |
| Audit logging | Append-only logs of authentication failures, authorisation denials, impersonation sessions, billing actions, outbound email and scheduled-job runs |
| Resilience | Point-in-time recovery with a 7-day window, plus daily managed backups retained 14 days |
| Data minimisation | Operational logs expire automatically on published retention windows, enforced by database-level policy rather than by hand |
| Secure development | Automated checks on every change, including a gate that fails the build if response security headers drift from their intended values |
| Vendor management | Sub-processors are contracted with equivalent obligations and listed publicly; the list is re-verified on a monthly schedule |
The authorised sub-processor list is maintained on the Trust page and forms part of this DPA. It records, for each vendor, the purpose of processing, the region, and that vendor’s own compliance programme.
It lives there rather than being restated here on purpose: a list copied into three documents becomes three different lists. Changes are notified under §9.
Need a countersigned copy of this Agreement? Email legal@squish.co or — a case gives you a number to chase.