Legal
Data Processing Addendum
Processor terms between InboxDays (Processor) and enterprise customers (Controller) under GDPR Article 28.
This Data Processing Addendum (“DPA”) forms part of the agreement between InboxDays (“Processor”) and the enterprise customer (“Controller”) that executes an order form or otherwise accepts this DPA. It governs Processor’s processing of Customer Personal Data in providing the Service.
Self-serve customers may request a countersigned PDF by emailing legal@inboxdays.com. Until a signed order form states otherwise, this public DPA describes our standard processor commitments.
1. Roles
- Controller determines the purposes and means of processing Customer Personal Data in connected mailboxes and workspaces.
- Processor processes Customer Personal Data only on documented instructions from Controller, unless required by law.
2. Nature and purpose of processing
Processing includes hosting, transmission, indexing, display, AI inference (when enabled by users), retention/TTL deletion per Controller configuration, security monitoring, and support. Categories of data subjects typically include Controller’s employees, contractors, and correspondents. Types of data include account metadata and application email content as described in the Privacy Policy.
3. Duration
Processing continues for the term of the Service agreement and any post-termination retention required to delete or return data, subject to TTL rules and legal holds.
4. Security measures
Processor implements appropriate technical and organizational measures as outlined in the Security Policy, including encryption in transit, access controls, logging, and isolation of production systems.
5. Subprocessors
Controller authorizes Processor to engage subprocessors listed in the Subprocessor Directory. Processor will impose data protection terms on subprocessors no less protective than this DPA. Processor remains responsible for subprocessor performance regarding Customer Personal Data.
6. International transfers
Where Customer Personal Data is transferred from the EEA/UK to a third country lacking an adequacy decision, Processor will ensure an appropriate transfer mechanism, including the European Commission Standard Contractual Clauses (SCCs) and UK addendum/IDTA as applicable, supplemented by transfer impact assessments where required.
7. Assistance with data subject rights
Taking into account the nature of processing, Processor will assist Controller with DSARs, security incidents, DPIAs, and consultations with supervisory authorities, as reasonably requested and as required by GDPR Articles 28, 32–36.
8. Breach notification
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Controller meet its notification obligations.
9. Return or deletion
Upon termination, Processor will delete or return Customer Personal Data at Controller’s choice, except where retention is required by law or where zero-knowledge ciphertext cannot be reconstructed without Controller keys (see Zero-Knowledge Disclaimer).
10. Audits
Upon reasonable written request, Processor will make available information necessary to demonstrate compliance with this DPA and allow audits (including via third-party reports such as SOC 2 when available) under confidentiality and scheduling conditions that protect other customers and Service security.
11. Order of precedence
For conflicts on data-protection terms, this DPA prevails over the Terms for processing of Customer Personal Data. Commercial terms remain governed by the Terms / order form.