01 Parties & scope
This data processing agreement ("DPA") is between:
- Inbox Harbour of Suite RA01, 195-197 Wood Street, London, E17 3NU ("Processor", "we", "us"); and
- the business identified as the customer in the terms of service or order form referencing this DPA ("Controller", "you").
It applies whenever we process personal data on your behalf in connection with the Inbox Harbour email triage service (the "Service"), and is incorporated into and forms part of our terms & conditions. Where this DPA and those terms conflict on anything concerning the processing of personal data, this DPA takes precedence.
In plain English
You own the data in your mailbox and decide what happens to it. We only touch it to do the job you've asked us to do — tagging and filing — and this document is our written promise about how we handle it, who else is involved, and what happens when things go wrong.
02 Definitions
"Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Personal Data Breach" and "Special Category Data" have the meanings given to them in UK GDPR (the UK General Data Protection Regulation, as defined in the Data Protection Act 2018).
"Sub-processor" means any processor we engage to carry out specific processing activities on your behalf.
03 Subject matter & duration
The subject matter, nature, purpose, data types and data subjects are set out in Schedule 1.
This DPA remains in effect for as long as we process personal data on your behalf, and survives termination of our agreement to the extent needed to give effect to section 10 (deletion & return).
04 Our obligations as processor
05 Your obligations as controller
You confirm that you have a lawful basis for the personal data you authorise us to process, and that your instructions to us comply with UK GDPR.
You are responsible for the accuracy, quality and legality of the personal data in your mailbox and for the means by which you obtained it — including, where required, telling your own customers and contractors that their correspondence is processed in this way.
06 International transfers
We will not transfer personal data outside the UK except to a country or organisation covered by UK adequacy regulations, or subject to appropriate safeguards — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another valid mechanism under UK GDPR.
Current Sub-processor locations and the mechanism relied on for each are set out in Schedule 2.
07 Personal data breach notification
Why 48 hours
You have 72 hours to report a reportable breach to the ICO from the moment you become aware of it. Notifying you inside 48 hours is designed to leave you time to assess and report within your own deadline.
08 Special category data
The Service is not designed to seek out or specifically process special category data (such as health, religious or similar sensitive information). Where such data appears incidentally within email content, it is processed only as part of the ordinary triage function — tagging and filing — and is not used for any separate purpose.
You are responsible for assessing whether your own use of the Service in relation to such data requires a data protection impact assessment.
09 Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in our terms & conditions, except that nothing in this DPA or those terms limits either party's liability for infringements of UK GDPR to the extent that such a limitation is not permitted by law.
10 Deletion & return of data
On termination or expiry of the Service, we will — at your written election, made within [30 days] of termination — either delete or return all personal data processed on your behalf, and delete existing copies.
The exception is where UK law requires us to retain some of it (for example, billing records kept for tax purposes). In that case we isolate and protect that data from further processing, and delete it once the retention requirement ends.
Your emails and folders remain in your own mailbox throughout, exactly as they are — deletion here concerns our own systems, not your Microsoft account.
11 General
S1 Schedule 1 — Details of processing
S2 Schedule 2 — Authorised sub-processors
By accepting this DPA you give general authorisation for us to engage the following Sub-processors:
We will notify you of any change to this list in accordance with clause 4.4.
S3 Schedule 3 — Technical & organisational measures
- Authentication to your mailbox uses Microsoft OAuth 2.0 — we never receive or store your Microsoft password.
- Access tokens are encrypted at rest, and all connections are encrypted in transit using TLS.
- We request only the minimum Microsoft Graph permissions needed to read, tag and move messages. We do not request permission to send mail as you.
- Access to production systems and customer data is restricted to those who need it to operate the Service.
- Email content is never treated as instructions — message content is processed strictly as data to be classified, never as commands to act on.
- Backups of our infrastructure and data are taken according to our hosting provider's standard practices. Access to production systems and personal data is logged and restricted to personnel who need it to operate the Service, and those personnel are bound by confidentiality obligations.
S4 Acceptance & signature
This DPA is incorporated into our terms & conditions and takes effect when you accept those terms — no separate signature is needed.
If your organisation requires a countersigned copy naming your business specifically, email [email protected] and we'll send one over.
For signed copies
For and on behalf of Inbox Harbour
Questions about this agreement?
Email [email protected] and a real person will get back to you.