InboxDays
Log inStart free

Legal

Data Processing Addendum

Processor terms between InboxDays (Processor) and enterprise customers (Controller) under GDPR Article 28.

Last updated: 3 August 2026 · All policies · In-app legal center

Source: content/legal/dpa.md

This Data Processing Addendum (“DPA”) forms part of the agreement between InboxDays (“Processor”) and the enterprise customer (“Controller”) that executes an order form or otherwise accepts this DPA. It governs Processor’s processing of Customer Personal Data in providing the Service.

Self-serve customers may request a countersigned PDF by emailing legal@inboxdays.com. Until a signed order form states otherwise, this public DPA describes our standard processor commitments.

1. Roles

  • Controller determines the purposes and means of processing Customer Personal Data in connected mailboxes and workspaces.
  • Processor processes Customer Personal Data only on documented instructions from Controller, unless required by law.

2. Nature and purpose of processing

Processing includes hosting, transmission, indexing, display, AI inference (when enabled by users), retention/TTL deletion per Controller configuration, security monitoring, and support. Categories of data subjects typically include Controller’s employees, contractors, and correspondents. Types of data include account metadata and application email content as described in the Privacy Policy.

3. Duration

Processing continues for the term of the Service agreement and any post-termination retention required to delete or return data, subject to TTL rules and legal holds.

4. Security measures

Processor implements appropriate technical and organizational measures as outlined in the Security Policy, including encryption in transit, access controls, logging, and isolation of production systems.

5. Subprocessors

Controller authorizes Processor to engage subprocessors listed in the Subprocessor Directory. Processor will impose data protection terms on subprocessors no less protective than this DPA. Processor remains responsible for subprocessor performance regarding Customer Personal Data.

6. International transfers

Where Customer Personal Data is transferred from the EEA/UK to a third country lacking an adequacy decision, Processor will ensure an appropriate transfer mechanism, including the European Commission Standard Contractual Clauses (SCCs) and UK addendum/IDTA as applicable, supplemented by transfer impact assessments where required.

7. Assistance with data subject rights

Taking into account the nature of processing, Processor will assist Controller with DSARs, security incidents, DPIAs, and consultations with supervisory authorities, as reasonably requested and as required by GDPR Articles 28, 32–36.

8. Breach notification

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Controller meet its notification obligations.

9. Return or deletion

Upon termination, Processor will delete or return Customer Personal Data at Controller’s choice, except where retention is required by law or where zero-knowledge ciphertext cannot be reconstructed without Controller keys (see Zero-Knowledge Disclaimer).

10. Audits

Upon reasonable written request, Processor will make available information necessary to demonstrate compliance with this DPA and allow audits (including via third-party reports such as SOC 2 when available) under confidentiality and scheduling conditions that protect other customers and Service security.

11. Order of precedence

For conflicts on data-protection terms, this DPA prevails over the Terms for processing of Customer Personal Data. Commercial terms remain governed by the Terms / order form.

© 2026 InboxDays

Trust-first email for people and teams who live in their inbox.

Product

FeaturesHow it worksHelpInstall & downloadPricingSign upLog in

Legal & trust

PrivacyTermsBeta TermsCookiesSecuritySubprocessorsAll policies

Enterprise

Data Processing AddendumAI privacyZero-knowledge disclaimerAcceptable useCancel & refunds