Legal & trust
Data Processing Agreement
Last updated: August 8, 2026 · In force since: 8 August 2026
1. Roles, and which data each covers
This agreement applies where Brand My Inbox processes personal data on your instructions. It supplements the Terms of Use and the Privacy Policy, and where they conflict on processing, this agreement governs.
Brand My Inbox acts as CONTROLLER for its own account administration, billing, security and service operations: who holds an account, what they bought, what they were told. That processing is described in the Privacy Policy and is not covered by this agreement.
Brand My Inbox acts as PROCESSOR for the data you direct through the service: your domains and DNS configuration, your inbound addresses and their destinations, mail received on those addresses including its content and attachments, contacts and campaign data in EmailPro, and, where you switch it on, the record of who in your organisation opened which received message.
That last one is the clearest case and is stated separately for that reason. Where you enable message access logging, you decide that it happens, you owe notice to the people it covers, and you are responsible for having a lawful basis for it. We hold the records on your instructions, disclose them to nobody, delete them after 90 days, and never use them for our own purposes.
2. Our instructions, and when we would refuse one
We process personal data only on your documented instructions, which are given by your use of the service, by its settings, and by any written instruction you send us. Operating the service as you have configured it is itself an instruction.
We will tell you if an instruction appears to us to breach applicable data protection law, and we may decline to act on it. We do not process your data for our own purposes, do not sell it, and do not use it to train any model.
Where law requires us to process without your instruction, we will tell you before doing so unless that same law forbids telling you.
3. Confidentiality and access
Everyone we authorise to process your data is bound by confidentiality and has access only where their role requires it. Access is role-based, isolated per workspace, and audited.
Two categories our own staff cannot see at all. The content of mail you send, because it is never stored — it passes through the relay in memory. And the message access log, which is readable only by the owners and managers of your own workspace and is deliberately excluded from our support tooling, so that a support agent answering your ticket cannot read your internal monitoring records.
4. Security measures
Implemented technical and organisational measures: encryption in transit for all service traffic; encryption at rest for stored mail bodies and attachments; role-based access control with row-level isolation between workspaces; credentials stored only as scrypt hashes and compared in constant time; per-domain and per-mailbox scoping of sending credentials, checked before every send; rate limiting and brute-force protection on authentication; a copy of the whole DNS zone taken before any change we make to it, downloadable by you; audit logging of configuration changes; and monitored backups with periodic restore testing.
This is a description of what is in place, not a warranty. No measure listed here makes the service perfectly secure, and none should be read as a guarantee of any outcome.
5. Sub-processors
You give general authorisation for the sub-processors named in the Privacy Policy. At the date of this document they are: Hetzner Online GmbH (hosting, Germany); Oracle Cloud Infrastructure (outbound email delivery, Jerusalem region); Neon (database); Cloudflare (DNS, and storage of received mail in the European Union); SUMIT (payments); Anthropic (only where you use the site builder); Google (only where you connect a Google service yourself); and Amazon Web Services, whose Simple Email Service is retained as a standby sending route and can be enabled without a code change, named here although no customer mail is routed to it at present.
We remain responsible for our sub-processors performing these obligations. We will give you notice before adding or replacing one, and you may object on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected service without penalty for the period you have paid for and not used.
6. International transfers
Personal data is processed in Germany, elsewhere in the European Union, and in Israel. Israel holds a European Commission adequacy decision, so transfers there require no additional mechanism. Where any transfer falls outside an adequacy decision, the Standard Contractual Clauses apply and are incorporated by reference, with this agreement supplying the details they require.
7. Helping you meet your own obligations
We will assist you, taking into account the nature of the processing and the information available to us: in responding to requests from individuals exercising their rights; in carrying out data protection impact assessments; and in consulting a supervisory authority where that is required.
Much of this is self-service by design, which is faster than asking us. You can export your data, read your audit trail, download the copies we take of your DNS before changing it, and read the access log for your own workspace, without contacting us at all.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and in any event within 72 hours where the breach is likely to result in a risk to individuals. The notice will describe what happened, the categories and approximate number of records affected so far as they are known, the likely consequences, and the measures taken or proposed.
We will not delay a notice in order to finish investigating. An incomplete notice sent on time is more useful to you than a complete one sent late, and the missing detail follows as we establish it.
9. Deletion and return
On termination you may export your data through the service. After a documented offboarding period we delete or return personal data processed on your behalf, except where law requires us to keep it.
Retention periods that run on their own clock continue to run. Mail is deleted at the end of the retention period set on its address. Message access records are deleted 90 days after the access they record, on their own clock rather than the message's — so a message deleted early still leaves the record of who read it for the full 90 days. Ending your account does not shorten either period, and switching off access logging does not delete records already taken.
10. Audits
We will make available the information needed to demonstrate compliance with this agreement, and will allow and contribute to audits, including inspections, conducted by you or by an auditor you appoint. We may require reasonable notice, confidentiality undertakings, and that an audit does not compromise the security of another customer's data.
The processing record the service generates is available to you and is the ordinary starting point.
11. Acceptance
This agreement takes effect when you accept the Terms of Use, and continues for as long as we process personal data on your behalf. Organisations requiring a countersigned copy should write to [email protected].