Article 28 GDPR
Data Processing Agreement
This agreement governs AI Inbx's processing of personal data on behalf of customers using the email platform.
Last updated: 1 September 2026
- Controller or processor
- The customer identified in the applicable account or order, where it determines the relevant processing purposes or acts for another controller (“Customer”)
- Processor
This DPA is incorporated into the Terms of Service wherever AI Inbx processes personal data on the Customer's behalf. No separate signature is required.
1. Scope, precedence, and roles
This DPA applies where Processor handles personal data on Customer's behalf under the Terms of Service, an order form, or another agreement (together, the “Agreement”). It reflects Article 28 GDPR and equivalent processor requirements under applicable data protection law.
Customer is the controller and AI Inbx is the processor. Where Customer processes data for another controller, Customer is a processor and AI Inbx is its subprocessor. Customer is responsible for the lawfulness, transparency, accuracy, and content of its instructions and for all controller obligations. AI Inbx remains a separate controller for its own account, security, billing, and relationship data as described in the Privacy Policy.
These roles follow the parties' actual activities, not whether Customer is a Consumer or Business Customer under contract law. This DPA does not apply to processing for which AI Inbx determines the purposes and means, or to a Customer activity outside the scope of applicable data-protection law.
If this DPA conflicts with the rest of the Agreement on personal-data processing, this DPA prevails. Applicable EU Standard Contractual Clauses separately executed for a relevant transfer prevail where they conflict.
2. Documented instructions
Processor will process personal data only on Customer's documented instructions, including to provide, secure, support, and maintain the contracted Service; follow Customer's configuration and API requests; and comply with applicable law. The Agreement, Customer's use of the Service, and its authorized support requests are documented instructions.
Processor will inform Customer before processing required by Union or Member State law unless that law prohibits notice. If Processor believes an instruction infringes applicable data protection law, it will inform Customer and may suspend that instruction until resolved.
3. Processor obligations
Processor will:
- ensure authorized persons are bound by confidentiality and access personal data only as necessary;
- maintain measures appropriate to the risk under Article 32 GDPR and Annex 2;
- taking into account the nature of processing, assist Customer with data-subject requests and Articles 32–36 GDPR obligations;
- notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data and provide reasonably available information needed for Customer's duties;
- maintain records and provide information reasonably necessary to demonstrate compliance with this DPA; and
- not sell Customer Data or use it for targeted advertising.
4. Security of processing
Processor will maintain the technical and organizational measures in Annex 2. Customer acknowledges that security is shared and will configure roles, credentials, domains, webhooks, connected mailboxes, retention, regions, and tracking appropriately; protect its endpoints and credentials; and promptly revoke compromised access.
Processor may update the measures to reflect technical progress, provided the overall level of protection is not materially reduced.
5. Subprocessors
Customer gives general authorization for the subprocessors below. AI Inbx will impose materially equivalent data-protection obligations and remains responsible for their performance to the extent required by Article 28 GDPR.
| Provider | Purpose | Location / transfer |
|---|---|---|
| Vercel Inc. | Application hosting, delivery, and technical logs | EU and US; DPF and/or SCCs |
| PlanetScale Inc. | Managed PostgreSQL database | Switzerland (EU Central); adequacy decision |
| Amazon Web Services EMEA SARL / affiliates | Email transport, object storage, notifications, and queues | Customer-selected Frankfurt (EU) or N. Virginia (US); DPA, DPF and/or SCCs |
| OpenAI Ireland Ltd. / affiliates | Email classification and smart threading | EU and US; DPA, DPF and/or SCCs |
| Upstash Inc. / affiliates | Semantic search, cache, pacing, and job queues | Configured cloud regions; DPA and SCCs where required |
AI Inbx will notify Customer by email, dashboard notice, or another contractual communication and update this list at least 15 days before a new subprocessor begins processing Customer Data where reasonably possible. Customer may object on substantiated data-protection grounds during that period. The parties will seek a reasonable solution. If none is available, Customer may terminate the affected Service before the new subprocessor begins processing.
6. International transfers
Customer instructs AI Inbx to transfer Customer Data as needed to the authorized subprocessors and regions above. Where AI Inbx engages a subprocessor in a country without an adequacy decision, AI Inbx will execute the applicable module of the European Commission's 2021 Standard Contractual Clauses with that subprocessor and complete the required transfer assessment and supplementary measures.
Processor will rely on an adequacy decision, the EU–U.S. Data Privacy Framework for certified recipients, SCCs, and supplementary measures as applicable.
7. Requests, assessments, and audits
Customer is responsible for responding to data subjects and authorities. Processor will forward requests received directly where Customer can be identified and will not respond on Customer's behalf unless instructed or legally required. Material assistance beyond the standard Service may be charged at agreed reasonable rates, unless needed because Processor breached this DPA.
Processor will first satisfy audit requests through current security documentation, summaries, and questionnaire responses. If insufficient, Customer may conduct one audit per year, plus audits following a relevant breach or regulator request, on at least 30 days' notice. Audits must avoid disruption, protect other customers, and be performed by an independent auditor bound by confidentiality.
8. Return and deletion
During the term, Customer can retrieve Customer Data through available product and API functionality. At the end of the Service, Processor will delete or, where agreed and technically available, return Customer Data in accordance with Customer's choice, unless law requires retention. Data in backups, provider logs, or asynchronous deletion systems is isolated from ordinary use and removed through the applicable secure rotation cycle.
Processor may retain data necessary to establish, exercise, or defend legal claims or meet statutory duties, with processing limited to that purpose. Customer should export needed data before deleting a workspace or ending the Service.
9. Liability, term, and governing law
This DPA remains effective while Processor processes personal data on Customer's behalf. Liability is governed by the Agreement, without limiting data subjects' rights or liability that cannot legally be limited. The Agreement's law and venue apply, subject to mandatory data-protection law and the SCCs.
Annex 1 — Details of processing
Subject matter and purpose. Programmable email sending and receipt, mailbox synchronization, storage, threading, classification, search, scheduling, pacing, suppression, delivery and engagement reporting, webhooks, security, support, and related functionality.
Duration. The term of the Agreement, plus the limited deletion, backup, security, and legal-retention periods above.
Nature of processing. Collection, receipt, transmission, organization, storage, retrieval, consultation, analysis, classification, semantic indexing, matching, disclosure to intended recipients and subprocessors, restriction, and deletion.
Data subjects. Customer's users, personnel, contractors, contacts, prospects, clients, mailbox owners, email senders and recipients, people named or described in messages or attachments, and users of connected systems.
Personal data. Names, email addresses, identity data; message bodies, subjects, headers, signatures, attachments and thread relationships; domain and mailbox data; OAuth identifiers and encrypted tokens; IP addresses, user agents, timestamps, URLs, device and request data; delivery, bounce, complaint, open, click, opt-out and suppression data; workspace roles, settings, API and webhook metadata; and classification and threading outputs.
Sensitive data. The Service does not require special-category or criminal-conviction data, but email content may incidentally contain it. Customer must minimize such data and ensure an appropriate Article 9 or 10 GDPR condition and safeguards.
Frequency. Continuous or as initiated by Customer and its correspondents through the Service.
Annex 2 — Technical and organizational measures
- Access control: authenticated accounts, role-based workspace access, scoped API credentials, least-privilege production access, and revocation processes.
- Tenant separation: organization-scoped database queries, storage references, credentials, search namespaces, and API authorization checks.
- Encryption: TLS in transit, provider-supported encryption at rest, hashed passwords and API keys, and encrypted mailbox and signing credentials.
- Application security: managed cloud controls, input validation, webhook authentication, private-IP protections for webhook targets, dependency maintenance, and monitoring.
- Resilience: managed database and object-storage durability, queues and retries, regional infrastructure, backups, and recovery procedures proportionate to the Service.
- Data lifecycle: workspace deletion, limited raw message retention, suppression controls, provider rotation, and secure deletion procedures.
- Incident management: logging, investigation, containment, remediation, and Customer notification procedures.
- Vendor management and confidentiality: subprocessor review, data-processing terms, transfer safeguards, purpose-limited access, and confidentiality commitments.