← Back to context

Comment by buzer

3 days ago

According to https://superhuman.com/legal/dpa they claim that their role is processor. Processor is only allowed to use personal data they obtained from controller under controller's documented instructions. Unless those included authorization to send such an email to controller's users it's quite likely that they exceeded those. GDPR-wise (and likely that DPA-wise) that is a breach on it's own.