This Data Processing Addendum (“DPA”) forms part of the Terms between the customer (“Controller”) and SupaMail (“Processor”) when SupaMail processes personal data in Customer Content on the Controller's behalf. It applies automatically from the effective date of the Terms and takes priority over conflicting provisions about that processing.
1. Processing details
- Subject and duration: hosted mailbox synchronization, storage, search, access, sending, support, and deletion for the term of the service plus the deletion period.
- Nature and purpose: collecting from connected mail systems; encrypting credentials; copying, structuring, indexing, retrieving, transmitting, and deleting mail data; operating APIs, MCP, webhooks, and support.
- Personal data: account identifiers; mailbox addresses and credentials; message bodies, headers, participants, folders, flags, attachments and metadata; logs and identifiers. Content may incidentally include any category of personal data chosen or received by Controller.
- Data subjects: Controller's users, personnel, customers, suppliers, correspondents, and anyone represented in connected mail.
2. Controller obligations and instructions
Controller determines the lawfulness of its instructions, provides required notices, and has all rights and lawful bases needed for the processing. The Terms, product configuration, API calls, and documented support requests are Controller's instructions. Processor will process personal data only on those instructions unless law requires otherwise, in which case Processor will notify Controller unless prohibited by law. Processor will promptly inform Controller if it believes an instruction violates applicable data-protection law.
3. Confidentiality and security
Processor will ensure authorized personnel are bound by confidentiality and limit access to what they need. Processor will maintain measures appropriate to the risk, including tenant isolation and row-level access controls, encryption in transit, encryption of stored credentials and stored message bodies, private content storage, access controls, secret-management practices, security logging, and tested recovery and deletion paths appropriate to the service.
4. Subprocessors
Controller gives general written authorization for the subprocessors listed in the Privacy Notice. Processor will impose materially equivalent data-protection obligations and remains responsible for their performance. Processor will give reasonable advance notice of a new subprocessor that will process Customer Content. Controller may object on reasonable data-protection grounds; the parties will try to resolve the objection, and Controller may terminate the affected service if they cannot.
5. Assistance
Taking account of the nature of processing and information available, Processor will reasonably assist Controller with data-subject requests, security, breach notification, data-protection impact assessments, and regulator consultations. Controller is responsible for responding to requests. Processor may charge reasonable costs for assistance beyond standard product functionality unless the assistance is required because Processor breached this DPA.
6. Personal-data breaches
Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting Customer Content and provide available information reasonably needed for Controller's notification duties. Notification is not an admission of fault. Controller is responsible for notices to authorities and data subjects unless law assigns that duty to Processor.
7. Return and deletion
On termination or written request, Processor will delete or return Customer Content as reasonably available, unless law requires retention. Deletion may take time to propagate through backups and provider systems. Data retained for legal, security, or backup purposes remains protected by this DPA and will not be used for another purpose.
8. Information and audits
Processor will provide information reasonably necessary to demonstrate compliance with this DPA. No more than once annually, Controller may request a remote audit on reasonable notice, subject to confidentiality, security, and protection of other customers. On-site or third-party audits are available only where a regulator requires them or documentation is insufficient, and Controller bears reasonable costs unless the audit finds material breach.
9. International transfers
Where a restricted transfer requires safeguards, the applicable 2021 European Commission Standard Contractual Clauses are incorporated by reference using Module 2 (controller to processor) or Module 3 (processor to processor), as applicable. The optional docking clause applies; for those SCCs only, Clause 17 selects Irish law and Clause 18 selects the courts of Ireland; and the competent supervisory authority is determined under Clause 13. This DPA and the Privacy Notice supply the Annex I processing details, subprocessor list, and Annex II security description. The Terms remain governed by California law. If those SCCs do not lawfully cover a transfer, the parties will use another valid mechanism.
10. General
“Personal data,” “controller,” “processor,” “process,” and “personal-data breach” have the meanings in applicable data-protection law. The liability provisions of the Terms apply to this DPA to the extent permitted by law and without limiting data subjects' rights under the SCCs. This DPA ends when Processor has deleted all covered personal data.
