Skip to content

Legal

Data Processing Agreement

Last updated 22 August 2026

This summarises the Data Processing Agreement that forms part of every customer contract. The signed version governs. Ask [email protected] for a countersigned copy.

Subject matter

Processing of communications data from the messaging accounts the customer connects, for the purpose of providing indexing, retrieval, classification, drafting, export and API access.

Duration

For the term of the subscription, plus a thirty day export window, after which data is deleted unless a legal hold applies.

Categories of data subject

Customer personnel, and the counterparties who communicate with them. Because messaging archives are inherently two-sided, the second group is usually the larger one, and customers should account for that in their own notices.

Our obligations

  • Process only on documented instructions.
  • Bind everyone with access to confidentiality.
  • Apply the technical and organisational measures described in the security overview.
  • Engage subprocessors only under equivalent terms, with notice of change and a right to object.
  • Assist with data subject requests, impact assessments and regulator enquiries.
  • Delete or return data at the end of the term, at the customer's choice.
  • Make available the information needed to demonstrate compliance, and allow audits.

Subprocessors

The current list is published on the subprocessors page. Customers can subscribe to change notifications and have thirty days to object to an addition.

Security measures

Encryption in transit and at rest, tenant isolation, role and scope based access control including scoped credentials for automated agents, immutable audit logging of every read and export, least privilege staff access with time-bound elevation, and tested restore procedures.

Transfers

Standard Contractual Clauses where a transfer leaves the EEA, with a transfer impact assessment on file.