01 Who we are
Inbox Harbour ("we", "us", "our") provides an automated email triage service for small businesses. We tag and file emails inside your own mailbox so your inbox stays organised.
For the purposes of UK GDPR, when we process the contents of your mailbox we act as a data processor on your behalf — you remain the data controller for your own customers' and contractors' data. For the account information you give us directly (your name, email, billing details), we act as a data controller.
Trading name: Inbox Harbour
Address: Suite RA01, 195-197 Wood Street, London, E17 3NU
Company number: 17382265
ICO registration: ZC223444
Contact: [email protected]
02 What data we process
03 Your email content — the important bit
This is the part most people want to know about, so we'll be direct.
- Your emails stay in your mailbox. Tagging and filing happen inside your own Microsoft 365 account. We don't copy your mail into a separate archive.
- We never see your password. You sign in on Microsoft's own page. We only receive a secure access token, which you can revoke at any time from your Microsoft account.
- Content is processed transiently. To decide whether an email is urgent, awaiting payment, or belongs to a particular job, its content is read at the moment of processing and is not retained afterwards.
- We request least-privilege access. We only ask for the permissions needed to read, tag and file mail. We do not request permission to send email as you.
04 Why we process it, and our lawful basis
We do not sell your data, and we do not use the contents of your mailbox for advertising or to train AI models.
05 How we protect your data
- Authentication uses Microsoft OAuth 2.0 — we never handle or store passwords.
- Access tokens are encrypted at rest using AES-256-GCM encryption.
- All connections between your mailbox, our systems and your browser are encrypted in transit (TLS).
- Our infrastructure sits behind access controls, with administrative endpoints restricted and protected.
- Access to production systems is limited to those who need it to operate the service.
No system can promise perfect security, but if a breach affects your rights we will notify you and, where required, the ICO within 72 hours of becoming aware of it.
07 How long we keep it
When you disconnect, you can also revoke our access directly from your Microsoft account at any time — you don't need to ask us first.
08 Your rights
Under UK GDPR you have the right to:
- Be told what personal data we hold about you, and get a copy of it
- Have inaccurate data corrected
- Have your data erased
- Restrict or object to how we process it
- Receive your data in a portable format
- Withdraw consent, where consent is the basis we rely on
To exercise any of these, email [email protected]. We'll respond within one month.
If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
10 Changes to this policy
We may update this policy as the service develops. The "last updated" date at the top will always reflect the current version, and we'll email active customers about anything significant before it takes effect.
11 Contact us
Questions about your data, or want to exercise your rights?
Email: [email protected]
Post: Suite RA01, 195-197 Wood Street, London, E17 3NU
A real person will get back to you — usually within a couple of working days.