Legal

Data processing agreement

When we triage your mailbox, we handle personal data belonging to your customers and contractors. This agreement sets out our obligations to you when we do — as required by Article 28 of the UK GDPR. It forms part of our terms & conditions.

Version: 24/08/2026

01 Parties & scope

This data processing agreement ("DPA") is between:

  • Inbox Harbour of Suite RA01, 195-197 Wood Street, London, E17 3NU ("Processor", "we", "us"); and
  • the business identified as the customer in the terms of service or order form referencing this DPA ("Controller", "you").

It applies whenever we process personal data on your behalf in connection with the Inbox Harbour email triage service (the "Service"), and is incorporated into and forms part of our terms & conditions. Where this DPA and those terms conflict on anything concerning the processing of personal data, this DPA takes precedence.

In plain English

You own the data in your mailbox and decide what happens to it. We only touch it to do the job you've asked us to do — tagging and filing — and this document is our written promise about how we handle it, who else is involved, and what happens when things go wrong.

02 Definitions

"Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Personal Data Breach" and "Special Category Data" have the meanings given to them in UK GDPR (the UK General Data Protection Regulation, as defined in the Data Protection Act 2018).

"Sub-processor" means any processor we engage to carry out specific processing activities on your behalf.

03 Subject matter & duration

The subject matter, nature, purpose, data types and data subjects are set out in Schedule 1.

This DPA remains in effect for as long as we process personal data on your behalf, and survives termination of our agreement to the extent needed to give effect to section 10 (deletion & return).

04 Our obligations as processor

4.1We process personal data only on your documented instructions, including in relation to transfers outside the UK, unless UK law requires otherwise — in which case we will tell you about that legal requirement before processing, unless the law prohibits us from doing so.
4.2We ensure that anyone authorised to process your personal data is bound by a duty of confidentiality.
4.3We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Schedule 3.
4.4We will not engage a Sub-processor without your prior authorisation. Schedule 2 lists those you authorise generally by accepting this DPA. We will tell you before adding or replacing a Sub-processor, and you may object on reasonable grounds within [14 days]. Any Sub-processor we engage is bound by the same obligations set out here, and we remain fully liable to you for their performance.
4.5Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as reasonably possible, in responding to requests from data subjects exercising their rights.
4.6We will assist you in meeting your obligations around security of processing, breach notification, data protection impact assessments and prior consultation with the ICO, taking into account the information available to us.
4.7On termination of the Service, we will delete or return all personal data as set out in section 10.
4.8We will make available to you all information reasonably necessary to demonstrate compliance with this section, and allow for and contribute to audits or inspections by you or an auditor you mandate — on reasonable notice, subject to confidentiality, and no more than [once per 12 months] unless a Personal Data Breach has occurred.

05 Your obligations as controller

You confirm that you have a lawful basis for the personal data you authorise us to process, and that your instructions to us comply with UK GDPR.

You are responsible for the accuracy, quality and legality of the personal data in your mailbox and for the means by which you obtained it — including, where required, telling your own customers and contractors that their correspondence is processed in this way.

06 International transfers

We will not transfer personal data outside the UK except to a country or organisation covered by UK adequacy regulations, or subject to appropriate safeguards — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another valid mechanism under UK GDPR.

Current Sub-processor locations and the mechanism relied on for each are set out in Schedule 2.

07 Personal data breach notification

7.1We will notify you without undue delay, and in any event within [48 hours] of becoming aware, of any Personal Data Breach affecting your personal data.
7.2That notification will, so far as reasonably possible, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
7.3We will provide reasonable assistance to help you meet your own obligations to notify the ICO and affected individuals where required.

Why 48 hours

You have 72 hours to report a reportable breach to the ICO from the moment you become aware of it. Notifying you inside 48 hours is designed to leave you time to assess and report within your own deadline.

08 Special category data

The Service is not designed to seek out or specifically process special category data (such as health, religious or similar sensitive information). Where such data appears incidentally within email content, it is processed only as part of the ordinary triage function — tagging and filing — and is not used for any separate purpose.

You are responsible for assessing whether your own use of the Service in relation to such data requires a data protection impact assessment.

09 Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in our terms & conditions, except that nothing in this DPA or those terms limits either party's liability for infringements of UK GDPR to the extent that such a limitation is not permitted by law.

10 Deletion & return of data

On termination or expiry of the Service, we will — at your written election, made within [30 days] of termination — either delete or return all personal data processed on your behalf, and delete existing copies.

The exception is where UK law requires us to retain some of it (for example, billing records kept for tax purposes). In that case we isolate and protect that data from further processing, and delete it once the retention requirement ends.

Your emails and folders remain in your own mailbox throughout, exactly as they are — deletion here concerns our own systems, not your Microsoft account.

11 General

11.1This DPA is governed by the laws of England and Wales and subject to the same jurisdiction provisions as our terms & conditions.
11.2If any provision is found unenforceable, the rest continues in full force.
11.3We may update this DPA to reflect changes to Sub-processors, security measures or applicable law. Material changes are notified in the same way as changes to our terms & conditions.

S1 Schedule 1 — Details of processing

Item
Details
Subject matter
Provision of an automated email triage service that reads, tags and files messages within your connected mailbox.
Duration
For the term of our agreement, and thereafter only as needed to comply with section 10.
Nature & purpose
Automated classification (tagging) and filing of email messages, including limited automated decision-making to determine tags and folder placement. The Service does not send, reply to, forward or delete email.
Categories of personal data
Sender and recipient names and email addresses; subject lines and message body content; timestamps and folder locations; and, incidentally, any personal data your correspondents include within message content.
Categories of data subjects
Your customers, contractors, suppliers and other correspondents who email your connected mailbox; and your own personnel who use the Service.
Special category data
Not intentionally processed; may appear incidentally within message content, as described in section 08.

S2 Schedule 2 — Authorised sub-processors

By accepting this DPA you give general authorisation for us to engage the following Sub-processors:

Sub-processor
Purpose
Location & safeguard
Microsoft
Hosts and provides access to your mailbox (Microsoft 365 / Microsoft Graph). All mailbox access happens through Microsoft's authenticated APIs.
UK/Europe
Anthropic
Reads message content to determine the correct tag and folder for each message.
United States — Anthropic's Data Processing Addendum incorporating UK-approved transfer safeguards
DigitalOcean
Hosts our backend infrastructure and database, including workflow orchestration and the encrypted token store.
London (LON1), United Kingdom — no international transfer
Cloudflare
Network routing and security in front of our infrastructure.
United States — Cloudflare's Data Processing Addendum incorporating UK-approved transfer safeguards
Stripe Payments UK, Ltd.
Processes subscription payments. Does not process your mailbox data.
United Kingdom

We will notify you of any change to this list in accordance with clause 4.4.

S3 Schedule 3 — Technical & organisational measures

  • Authentication to your mailbox uses Microsoft OAuth 2.0 — we never receive or store your Microsoft password.
  • Access tokens are encrypted at rest, and all connections are encrypted in transit using TLS.
  • We request only the minimum Microsoft Graph permissions needed to read, tag and move messages. We do not request permission to send mail as you.
  • Access to production systems and customer data is restricted to those who need it to operate the Service.
  • Email content is never treated as instructions — message content is processed strictly as data to be classified, never as commands to act on.
  • Backups of our infrastructure and data are taken according to our hosting provider's standard practices. Access to production systems and personal data is logged and restricted to personnel who need it to operate the Service, and those personnel are bound by confidentiality obligations.

S4 Acceptance & signature

This DPA is incorporated into our terms & conditions and takes effect when you accept those terms — no separate signature is needed.

If your organisation requires a countersigned copy naming your business specifically, email [email protected] and we'll send one over.

For signed copies

Controller — name
Position
Signature
Date

For and on behalf of Inbox Harbour

Name
Position
Signature
Date

Questions about this agreement?

Email [email protected] and a real person will get back to you.